New The Skills of Tomorrow: how AI-exposed is every skill in 2026? See the data →
GitLab

Staff Security Researcher

GitLab
Apply →
remote staff full-time $168,000-$238,000 USD Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States

First indexed 6 Sept 2026

Description

GitLab is seeking a Staff Security Research Engineer to join its Application Security Team. The successful candidate will conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities.

Responsibilities:

  • Conduct security research in two or more specialty areas
  • Identify novel, systemic, and chained vulnerabilities in GitLab
  • Validate security vulnerabilities through hands-on testing and develop proof-of-concept exploits
  • Assess emerging industry vulnerability classes against the GitLab codebase
  • Conduct security research into GitLab's AI and agentic surfaces
  • Build tooling and automation that scales security research
  • Research the security posture of open source tools and dependencies integrated with GitLab
  • Solve technical problems of high scope, complexity, and ambiguity
  • Define and implement security technical and process improvements
  • Contribute to the team roadmap
  • Provide actionable and constructive feedback to engineering teams
  • Mentor and advise other individual contributors
  • Share knowledge and novel vulnerability types with the security community

Requirements:

  • 7+ years of experience in security research, penetration testing, or offensive security roles
  • Hands-on experience discovering and exploiting vulnerabilities
  • Subject matter expert (SME) of at least two technical areas impacting the security of the product
  • Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust
  • Ability to read and analyze code across multiple languages and codebases
  • Understanding of AI attack vectors
  • Experience leading technical objectives in cross-functional teams
  • Excellent written communication skills
  • Ability to translate complex technical findings into clear risk assessments and remediation recommendations

Nice to have:

  • Published security research or conference presentations
  • Background in software engineering with distributed systems expertise
  • Security certifications such as OSCP, OSCE, GPEN, or similar
  • Experience with GitLab or similar DevSecOps platforms
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting: https://job-boards.greenhouse.io/gitlab/jobs/8782153002