Staff Software Engineer, Security Factory – Static Analysis

Posted 15 hours ago

This is a fully remote position, open to applicants in United States, +2 more countries.

📋 Description

• Serve as the primary individual responsible for the team's most significant initiatives from design to delivery.

• Deliver substantial features with minimal supervision and influence the team's long-term objectives.

• Transition systems developed by individual engineers to team ownership through thorough documentation, testing, and collaborative review.

• Establish the technical direction for AI-assisted tools that implement, assess, and validate changes and findings in the engine.

• Create validations for changes made by agents and their generated outcomes, measuring detection quality against benchmark applications with known vulnerabilities.

• Oversee the architecture of the program model, which includes parsing, symbol resolution, intermediate representations, call graphs, taint analysis, and data-flow analysis.

• Manage the pipeline that converts source code into findings and outline its expansion to accommodate new languages and frameworks.

• Address high-level technical challenges and advocate for enhancements in quality, security, and performance.

• Collaborate with teams in Product Management, UX, Code Security, Composition Analysis, and other partner teams.

• Guide engineers through code reviews and pairing, eliminate obstacles, and enhance internal standards.

• Engage in on-call rotations for product operations, security operations, and urgent engineering matters.

• Create architecture and specification documents and lead implementation efforts by AI agents and engineers.

• Develop and sustain harnesses, agent instructions, agentic skills, coding and reviewing agents, independent review panels, and performance, API, and dependency gates.

• Stay informed about program analysis and security research, conduct AI-assisted research and exploratory projects, and translate findings into prototypes, proposals, and contributions to upstream projects.

• Advance GitLab's SAST capabilities for customer software repositories.


⛳️ Requirements

• Experience in developing your own LLM tooling, such as a harness, an agent pipeline, or evaluations, with the discernment to assess the trustworthiness of outputs.

• Significant professional experience in writing, testing, and reviewing production code in Rust, Go, or a comparable systems language, with expertise in at least one.

• Openness to working with Rust, Go, and Ruby.

• Background in performance optimization, containerized workflows, and CI/CD processes, including Docker.

• Extensive knowledge in program analysis and static analysis, encompassing parsing and ASTs, intermediate representations, SSA, control-flow and call graphs, taint and data-flow analysis, type inference, incremental and fixpoint computation, or detection rules.

• Capability to read, analyze, and implement research literature.

• Profound experience in application security, including vulnerability research, secure code reviews, or crafting detection rules.

• Familiarity with OWASP Top 10 and CWE vulnerability classifications.

• Skill in communicating complex technical, architectural, and organizational issues clearly and succinctly.

• Proficiency in writing architecture and design specifications that facilitate team decision-making.

• Proven history of managing ambiguous, team-wide challenges and delivering from concept to production with minimal guidance.

• Experience in defining overarching architecture, assigning component specifications to engineers and AI agents, and ensuring reliable implementation.

• Demonstrated success in mentoring engineers, elevating technical standards, and shaping technical direction through consensus-building.

• Familiarity with widely-used web or mobile application frameworks (beneficial).

• Experience in designing safeguards for agent-generated code, such as mutation testing, fuzzing, and CI gates (beneficial).

• Engagement with the research community through publications, tool papers, or contributions to upstream open source projects (beneficial).


🏝️ Benefits

• Comprehensive benefits to enhance your health, financial stability, and overall well-being.

• Flexible Paid Time Off.

• Access to Team Member Resource Groups.

• Equity Compensation & Employee Stock Purchase Plan.

• Growth and Development Fund.

• Parental Leave.

People also viewed

Cummins Inc.15 hours ago

Cybersecurity Director

US flagAlabama, +45 more statesFull-timeCybersecurity / Security Engineer$180.6k – $265k/year
ApplyView job
Tangible15 hours ago

Information Security Engineer – CISO Track

GB flagUnited Kingdom OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Tevora15 hours ago

Senior Director – Cybersecurity Transformation, AI Security

US flagCalifornia, +1 more stateFull-timeCybersecurity / Security Engineer$190k – $225k/year
ApplyView job
Delinea17 hours ago

Staff Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$170k – $200k/year
ApplyView job
OptiMantra17 hours ago

Lead Cybersecurity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
BibliU17 hours ago

Senior Security Engineer

GB flagUnited Kingdom OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers