Staff Security Researcher

Posted 16 hours ago

This is a fully remote position, open to applicants in United States, +2 more countries.

📋 Description

• Perform security research across two or more specialized domains.

• Discover innovative, systemic, and interconnected vulnerabilities within GitLab.

• Confirm vulnerabilities via practical testing and proof-of-concept exploits.

• Evaluate emerging vulnerability types within the GitLab codebase and spearhead remediation efforts.

• Investigate GitLab's AI and agent-based surfaces to help establish security requirements.

• Create tools and automation to enhance scalable security research, including agent-assisted vulnerability detection.

• Analyze the security posture of open-source tools and dependencies, communicate findings to maintainers, and monitor mitigation efforts.

• Address technical challenges of significant scope, complexity, and ambiguity.

• Define and execute improvements in security techniques and processes.

• Contribute to the overall team roadmap.

• Provide constructive feedback to engineering teams.

• Mentor and guide individual contributors.

• Share insights and new vulnerability types with the security community.

• Report directly to the Senior Manager of Application Security.


⛳️ Requirements

• Over 7 years of experience in security research, penetration testing, or offensive security positions.

• Practical experience in identifying and exploiting vulnerabilities.

• Expertise in at least two technical areas that affect product security.

• Proficiency in one or more programming languages, including Ruby, Go, Python, TypeScript, or Rust.

• Capability to read and analyze code in various languages and across different codebases.

• Understanding of AI attack vectors such as prompt injection, agent manipulation, and workflow exploitation.

• Experience leading technical initiatives within cross-functional teams.

• Outstanding written communication skills, with the ability to convey complex topics clearly and succinctly.

• Ability to translate intricate technical findings into straightforward risk assessments and remediation strategies.

• Strong analytical and problem-solving abilities, with creative thinking regarding attack scenarios.

• Published security research or presentations at conferences (preferred).

• Background in software engineering, particularly with distributed systems (preferred).

• Relevant security certifications such as OSCP, OSCE, GPEN, or equivalents (preferred).

• Familiarity with GitLab or similar DevSecOps platforms (preferred).


🏝️ Benefits

• Benefits designed to support your health, finances, and overall well-being.

• Flexible Paid Time Off policy.

• Access to Team Member Resource Groups.

• Equity Compensation and Employee Stock Purchase Plan.

• Growth and Development Fund.

• Parental Leave.

People also viewed

GitLab16 hours ago

Principal Security Researcher

US flagUnited States, +2 more countriesFull-timeCybersecurity / Security Engineer$203.2k – $275k/year
ApplyView job
Cisco16 hours ago

Software Security Lead

US flagNorth Carolina OnlyFull-timeCybersecurity / Security Engineer$151.6k – $222.4k/year
ApplyView job
Lovesac16 hours ago

Senior Engineer, Information Security Architect

US flagConnecticut OnlyFull-timeCybersecurity / Security Engineer$95k – $125k/year
ApplyView job
General Dynamics Information Technology23 hours ago

Cybersecurity Architect

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$149.5k – $184k/year
ApplyView job
PGTEK1 day ago

Senior Security Agent / AI Red Team Engineer

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Cisco1 day ago

Software Security Lead

US flagNorth Carolina OnlyFull-timeCybersecurity / Security Engineer$139.3k – $203.6k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers