
Principal Security Researcher
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States, +2 more countries.
• Lead and conduct security research initiatives across various functional domains.
• Identify innovative, systemic, and interconnected vulnerabilities within GitLab.
• Validate security vulnerabilities using hands-on testing and create proof-of-concept exploits.
• Evaluate emerging industry vulnerability categories against the GitLab codebase and spearhead class-level remediation efforts.
• Direct security research focused on GitLab's AI and agentic surfaces, and establish security requirements.
• Develop and manage tooling and automation for security research, including agent-assisted vulnerability detection.
• Investigate the security posture of open source tools and dependencies that are integrated with GitLab.
• Communicate findings to maintainers and monitor mitigation efforts in line with responsible disclosure guidelines.
• Tackle technical challenges of the highest scope, complexity, and ambiguity.
• Contribute to shaping the team and sub-department roadmap.
• Integrate security research outcomes into engineering and business functions.
• Educate, mentor, and guide domain experts and individual contributors.
• Share insights and emerging vulnerability types with the security community.
• Report directly to the Senior Manager of Application Security.
• Over 10 years of experience in security research, penetration testing, or offensive security roles.
• Proven capability in identifying and exploiting vulnerabilities in large codebases and complex systems.
• Proficient in two or more programming languages: Ruby, Go, Python, TypeScript, or Rust.
• Ability to read and analyze code across various languages and codebases.
• Solid understanding of AI frameworks.
• Comprehensive knowledge of AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation.
• Comfortable in establishing and leading complex remediation initiatives involving cross-functional teams.
• Exceptional written communication skills with the ability to convey complex topics clearly and concisely.
• Capability to translate intricate technical findings into straightforward risk assessments and remediation suggestions.
• Strong analytical and problem-solving abilities with a creative approach to attack scenarios.
• Nice to Have: Published security research or conference presentations; background in software engineering with expertise in distributed systems; experience with GitLab or similar DevSecOps platforms.
• Comprehensive benefits to support your health, finances, and overall well-being.
• Flexible Paid Time Off.
• Team Member Resource Groups.
• Equity Compensation & Employee Stock Purchase Plan.
• Growth and Development Fund.
• Parental Leave.
GitLab
Cisco
Lovesac
General Dynamics Information Technology
Get handpicked remote jobs straight to your inbox weekly.