Principal Security Researcher

Posted 16 hours ago

This is a fully remote position, open to applicants in United States, +2 more countries.

📋 Description

• Lead and conduct security research initiatives across various functional domains.

• Identify innovative, systemic, and interconnected vulnerabilities within GitLab.

• Validate security vulnerabilities using hands-on testing and create proof-of-concept exploits.

• Evaluate emerging industry vulnerability categories against the GitLab codebase and spearhead class-level remediation efforts.

• Direct security research focused on GitLab's AI and agentic surfaces, and establish security requirements.

• Develop and manage tooling and automation for security research, including agent-assisted vulnerability detection.

• Investigate the security posture of open source tools and dependencies that are integrated with GitLab.

• Communicate findings to maintainers and monitor mitigation efforts in line with responsible disclosure guidelines.

• Tackle technical challenges of the highest scope, complexity, and ambiguity.

• Contribute to shaping the team and sub-department roadmap.

• Integrate security research outcomes into engineering and business functions.

• Educate, mentor, and guide domain experts and individual contributors.

• Share insights and emerging vulnerability types with the security community.

• Report directly to the Senior Manager of Application Security.


⛳️ Requirements

• Over 10 years of experience in security research, penetration testing, or offensive security roles.

• Proven capability in identifying and exploiting vulnerabilities in large codebases and complex systems.

• Proficient in two or more programming languages: Ruby, Go, Python, TypeScript, or Rust.

• Ability to read and analyze code across various languages and codebases.

• Solid understanding of AI frameworks.

• Comprehensive knowledge of AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation.

• Comfortable in establishing and leading complex remediation initiatives involving cross-functional teams.

• Exceptional written communication skills with the ability to convey complex topics clearly and concisely.

• Capability to translate intricate technical findings into straightforward risk assessments and remediation suggestions.

• Strong analytical and problem-solving abilities with a creative approach to attack scenarios.

• Nice to Have: Published security research or conference presentations; background in software engineering with expertise in distributed systems; experience with GitLab or similar DevSecOps platforms.


🏝️ Benefits

• Comprehensive benefits to support your health, finances, and overall well-being.

• Flexible Paid Time Off.

• Team Member Resource Groups.

• Equity Compensation & Employee Stock Purchase Plan.

• Growth and Development Fund.

• Parental Leave.

People also viewed

GitLab16 hours ago

Staff Security Researcher

US flagUnited States, +2 more countriesFull-timeCybersecurity / Security Engineer$168k – $238k/year
ApplyView job
Cisco16 hours ago

Software Security Lead

US flagNorth Carolina OnlyFull-timeCybersecurity / Security Engineer$151.6k – $222.4k/year
ApplyView job
Lovesac16 hours ago

Senior Engineer, Information Security Architect

US flagConnecticut OnlyFull-timeCybersecurity / Security Engineer$95k – $125k/year
ApplyView job
General Dynamics Information Technology23 hours ago

Cybersecurity Architect

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$149.5k – $184k/year
ApplyView job
PGTEK1 day ago

Senior Security Agent / AI Red Team Engineer

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Cisco1 day ago

Software Security Lead

US flagNorth Carolina OnlyFull-timeCybersecurity / Security Engineer$139.3k – $203.6k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers