
Staff Software Engineer, Security Factory – Static Analysis
Posted 15 hours ago

Posted 15 hours ago
This is a fully remote position, open to applicants in United States, +2 more countries.
• Serve as the primary individual responsible for the team's most significant initiatives from design to delivery.
• Deliver substantial features with minimal supervision and influence the team's long-term objectives.
• Transition systems developed by individual engineers to team ownership through thorough documentation, testing, and collaborative review.
• Establish the technical direction for AI-assisted tools that implement, assess, and validate changes and findings in the engine.
• Create validations for changes made by agents and their generated outcomes, measuring detection quality against benchmark applications with known vulnerabilities.
• Oversee the architecture of the program model, which includes parsing, symbol resolution, intermediate representations, call graphs, taint analysis, and data-flow analysis.
• Manage the pipeline that converts source code into findings and outline its expansion to accommodate new languages and frameworks.
• Address high-level technical challenges and advocate for enhancements in quality, security, and performance.
• Collaborate with teams in Product Management, UX, Code Security, Composition Analysis, and other partner teams.
• Guide engineers through code reviews and pairing, eliminate obstacles, and enhance internal standards.
• Engage in on-call rotations for product operations, security operations, and urgent engineering matters.
• Create architecture and specification documents and lead implementation efforts by AI agents and engineers.
• Develop and sustain harnesses, agent instructions, agentic skills, coding and reviewing agents, independent review panels, and performance, API, and dependency gates.
• Stay informed about program analysis and security research, conduct AI-assisted research and exploratory projects, and translate findings into prototypes, proposals, and contributions to upstream projects.
• Advance GitLab's SAST capabilities for customer software repositories.
• Experience in developing your own LLM tooling, such as a harness, an agent pipeline, or evaluations, with the discernment to assess the trustworthiness of outputs.
• Significant professional experience in writing, testing, and reviewing production code in Rust, Go, or a comparable systems language, with expertise in at least one.
• Openness to working with Rust, Go, and Ruby.
• Background in performance optimization, containerized workflows, and CI/CD processes, including Docker.
• Extensive knowledge in program analysis and static analysis, encompassing parsing and ASTs, intermediate representations, SSA, control-flow and call graphs, taint and data-flow analysis, type inference, incremental and fixpoint computation, or detection rules.
• Capability to read, analyze, and implement research literature.
• Profound experience in application security, including vulnerability research, secure code reviews, or crafting detection rules.
• Familiarity with OWASP Top 10 and CWE vulnerability classifications.
• Skill in communicating complex technical, architectural, and organizational issues clearly and succinctly.
• Proficiency in writing architecture and design specifications that facilitate team decision-making.
• Proven history of managing ambiguous, team-wide challenges and delivering from concept to production with minimal guidance.
• Experience in defining overarching architecture, assigning component specifications to engineers and AI agents, and ensuring reliable implementation.
• Demonstrated success in mentoring engineers, elevating technical standards, and shaping technical direction through consensus-building.
• Familiarity with widely-used web or mobile application frameworks (beneficial).
• Experience in designing safeguards for agent-generated code, such as mutation testing, fuzzing, and CI gates (beneficial).
• Engagement with the research community through publications, tool papers, or contributions to upstream open source projects (beneficial).
• Comprehensive benefits to enhance your health, financial stability, and overall well-being.
• Flexible Paid Time Off.
• Access to Team Member Resource Groups.
• Equity Compensation & Employee Stock Purchase Plan.
• Growth and Development Fund.
• Parental Leave.
Cummins Inc.
Tangible
Tevora
Delinea
Get handpicked remote jobs straight to your inbox weekly.