Principal Security Researcher

GitLab
Canada, Israel, United Kingdom, United States
Workplace: RemoteFull timeUSD 203,200 - 275,000 annuallyFunction: Research & Scientific (R&D)Experience: 10+ yearsSkills: ["Written communication","Analytical thinking","Problem-solving","Creative thinking"]

Lead security research within the Application Security team to strengthen GitLab’s AI-powered DevSecOps capabilities. Conduct cutting-edge research, uncover and validate systemic and chained vulnerabilities with hands-on penetration testing, and develop proof-of-concept exploits. Assess emerging vulnerability classes across the GitLab codebase, define security requirements for AI and agentic surfaces, and build automation tooling to scale research while translating findings into actionable remediation.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GitLab
GitLab
3 days ago

Principal Security Researcher

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 23 minutes agoStatus: Live

Job Summary

Lead security research within the Application Security team to strengthen GitLab’s AI-powered DevSecOps capabilities. Conduct cutting-edge research, uncover and validate systemic and chained vulnerabilities with hands-on penetration testing, and develop proof-of-concept exploits. Assess emerging vulnerability classes across the GitLab codebase, define security requirements for AI and agentic surfaces, and build automation tooling to scale research while translating findings into actionable remediation.
Location: Canada, Israel, United Kingdom, United States
Workplace: Remote
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Mid level

Key Responsibilities

  • •Conduct and lead security research projects across multiple functional areas
  • •Identify and validate systemic and chained vulnerabilities using hands-on testing and proof-of-concept exploits
  • •Assess emerging vulnerability classes against the GitLab codebase and drive remediation of vulnerability classes
  • •Lead security research into GitLab’s AI and agentic surfaces and define security requirements for engineering teams
  • •Build tooling and automation to scale security research, including agent-assisted vulnerability discovery

Pay and Benefits

Salary: USD 203,200 - 275,000 annually
Perks:Paid LeaveEquityParental LeaveLearning Budget

Key Requirements

  • •10+ years of experience in security research, penetration testing, or offensive security
  • •Ability to discover and exploit vulnerabilities in large codebases and complex systems
  • •Proficiency in two or more of Ruby, Go, Python, TypeScript, or Rust
  • •Strong knowledge of AI frameworks and AI attack vectors such as prompt injection, agent manipulation, and workflow exploitation
  • •Excellent written communication to articulate technical findings into clear risk assessments and remediation recommendations
Experience:10+ years
Skills:Written communicationAnalytical thinkingProblem-solvingCreative thinking
Tech Stack:RubyGoPythonTypeScriptRustAIPrompt injection

Company Brief

GitLab
Provides a single application for the complete DevSecOps lifecycle, offering source code management, CI/CD, security, and collaboration tools to help teams deliver software faster and more securely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2011
WebsiteLinkedIn