Principal Security Researcher
Posted 12hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Principal Security Researcher securing GitLab’s AI-powered DevSecOps platform. Leading vulnerability research, AI attack analysis, penetration testing, and remediation across GitLab’s codebase.
Responsibilities:
- Conduct and lead security research projects across multiple functional areas
- Identify novel, systemic, and chained vulnerabilities in GitLab
- Validate security vulnerabilities through hands-on testing and develop proof-of-concept exploits
- Assess emerging industry vulnerability classes against the GitLab codebase and drive class-level remediation
- Lead security research into GitLab's AI and agentic surfaces and define security requirements
- Build and direct tooling and automation for security research, including agent-assisted vulnerability discovery
- Research the security posture of open source tools and dependencies integrated with GitLab
- Report findings to maintainers and track mitigation under responsible disclosure guidelines
- Solve technical problems of the highest scope, complexity, and ambiguity
- Help shape the team and sub-department roadmap
- Lead integration of security research results into engineering and business functions
- Teach, mentor, and advise domain experts and individual contributors
- Share knowledge and novel vulnerability types with the security community
- Report to the Senior Manager of Application Security
Requirements:
- 10+ years of experience in security research, penetration testing, or offensive security roles
- Strong ability in discovering and exploiting vulnerabilities in large codebase and complex systems
- Proficiency in two or more of Ruby, Go, Python, TypeScript, or Rust
- Ability to read and analyze code across multiple languages and codebases
- Strong knowledge of AI frameworks
- Strong understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation
- At ease in establishing and driving complex remediation initiatives involving cross-functional teams
- Excellent written communication skills with an ability to articulate complex topics in a clear and concise manner
- Ability to translate complex technical findings into clear risk assessments and remediation recommendations
- Strong analytical and problem-solving skills with creative thinking about attack scenarios
- Nice to Have: Published security research or conference presentations; background in software engineering with distributed systems expertise; experience with GitLab or similar DevSecOps platforms
Benefits:
- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave



















