Staff Security Researcher

Posted 11hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Staff Security Researcher conducting vulnerability research and penetration testing for GitLab’s AI-powered DevSecOps platform. Developing attack methodologies, tooling, and security improvements.

Responsibilities:

  • Conduct security research in two or more specialty areas
  • Identify novel, systemic, and chained vulnerabilities in GitLab
  • Validate vulnerabilities through hands-on testing and proof-of-concept exploits
  • Assess emerging vulnerability classes against the GitLab codebase and drive remediation
  • Research GitLab's AI and agentic surfaces and help define security requirements
  • Build tooling and automation for scalable security research, including agent-assisted vulnerability discovery
  • Research the security posture of open source tools and dependencies, report findings to maintainers, and track mitigation
  • Solve technical problems of high scope, complexity, and ambiguity
  • Define and implement security technical and process improvements
  • Contribute to the team roadmap
  • Provide actionable feedback to engineering teams
  • Mentor and advise individual contributors
  • Share knowledge and novel vulnerability types with the security community
  • Report to the Senior Manager of Application Security

Requirements:

  • 7+ years of experience in security research, penetration testing, or offensive security roles
  • Hands-on experience discovering and exploiting vulnerabilities
  • Subject matter expertise in at least two technical areas impacting product security
  • Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust
  • Ability to read and analyze code across multiple languages and codebases
  • Understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation
  • Experience leading technical objectives in cross-functional teams
  • Excellent written communication skills with ability to articulate complex topics clearly and concisely
  • Ability to translate complex technical findings into clear risk assessments and remediation recommendations
  • Strong analytical and problem-solving skills with creative thinking about attack scenarios
  • Published security research or conference presentations (nice to have)
  • Background in software engineering with distributed systems expertise (nice to have)
  • Security certifications such as OSCP, OSCE, GPEN, or similar (nice to have)
  • Experience with GitLab or similar DevSecOps platforms (nice to have)

Benefits:

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave