
Staff Security Researcher
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States, +2 more countries.
• Perform security research across two or more specialized domains.
• Discover innovative, systemic, and interconnected vulnerabilities within GitLab.
• Confirm vulnerabilities via practical testing and proof-of-concept exploits.
• Evaluate emerging vulnerability types within the GitLab codebase and spearhead remediation efforts.
• Investigate GitLab's AI and agent-based surfaces to help establish security requirements.
• Create tools and automation to enhance scalable security research, including agent-assisted vulnerability detection.
• Analyze the security posture of open-source tools and dependencies, communicate findings to maintainers, and monitor mitigation efforts.
• Address technical challenges of significant scope, complexity, and ambiguity.
• Define and execute improvements in security techniques and processes.
• Contribute to the overall team roadmap.
• Provide constructive feedback to engineering teams.
• Mentor and guide individual contributors.
• Share insights and new vulnerability types with the security community.
• Report directly to the Senior Manager of Application Security.
• Over 7 years of experience in security research, penetration testing, or offensive security positions.
• Practical experience in identifying and exploiting vulnerabilities.
• Expertise in at least two technical areas that affect product security.
• Proficiency in one or more programming languages, including Ruby, Go, Python, TypeScript, or Rust.
• Capability to read and analyze code in various languages and across different codebases.
• Understanding of AI attack vectors such as prompt injection, agent manipulation, and workflow exploitation.
• Experience leading technical initiatives within cross-functional teams.
• Outstanding written communication skills, with the ability to convey complex topics clearly and succinctly.
• Ability to translate intricate technical findings into straightforward risk assessments and remediation strategies.
• Strong analytical and problem-solving abilities, with creative thinking regarding attack scenarios.
• Published security research or presentations at conferences (preferred).
• Background in software engineering, particularly with distributed systems (preferred).
• Relevant security certifications such as OSCP, OSCE, GPEN, or equivalents (preferred).
• Familiarity with GitLab or similar DevSecOps platforms (preferred).
• Benefits designed to support your health, finances, and overall well-being.
• Flexible Paid Time Off policy.
• Access to Team Member Resource Groups.
• Equity Compensation and Employee Stock Purchase Plan.
• Growth and Development Fund.
• Parental Leave.
GitLab
Cisco
Lovesac
General Dynamics Information Technology
Get handpicked remote jobs straight to your inbox weekly.