Staff Security Researcher

GitLab
Canada, Israel, United Kingdom, United States
Workplace: RemoteFull timeUSD 168,000 - 238,000 annuallyFunction: Research & Scientific (R&D)Experience: 7+ yearsSkills: ["Written communication","Analytical thinking","Problem-solving","Creative thinking","Cross-functional collaboration","Mentorship"]

Conduct advanced security research on GitLab’s AI-powered DevSecOps capabilities within the Application Security team. Develop novel testing methodologies (including AI agent security), run hands-on penetration testing, and validate real-world vulnerabilities via proof-of-concept exploits. Translate emerging threats into engineering requirements, build automation to scale research across the codebase, and help remediate systemic vulnerability classes while sharing findings with the wider security community.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GitLab
GitLab
3 days ago

Staff Security Researcher

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Conduct advanced security research on GitLab’s AI-powered DevSecOps capabilities within the Application Security team. Develop novel testing methodologies (including AI agent security), run hands-on penetration testing, and validate real-world vulnerabilities via proof-of-concept exploits. Translate emerging threats into engineering requirements, build automation to scale research across the codebase, and help remediate systemic vulnerability classes while sharing findings with the wider security community.
Location: Canada, Israel, United Kingdom, United States
Workplace: Remote
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Sr. Manager level

Key Responsibilities

  • •Conduct security research in two or more specialty areas, focusing on novel systemic and chained vulnerabilities.
  • •Validate vulnerabilities through hands-on testing and proof-of-concept exploit development.
  • •Assess emerging vulnerability classes against the GitLab codebase and drive remediation of classes rather than instances.
  • •Research GitLab’s AI and agentic surfaces, define security requirements, and help engineering teams act on findings.
  • •Build tooling and automation to scale security research, including agent-assisted vulnerability discovery; mentor others and share knowledge with the security community.

Pay and Benefits

Salary: USD 168,000 - 238,000 annually
Perks:Health InsuranceEquityParental LeavePaid Leave

Key Requirements

  • •7+ years of experience in security research, penetration testing, or offensive security roles.
  • •Hands-on experience discovering and exploiting vulnerabilities.
  • •SME proficiency in at least two technical areas impacting product security.
  • •Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust; AI framework experience is an asset.
  • •Ability to lead technical objectives in cross-functional teams and translate findings into risk assessments and remediation recommendations.
Experience:7+ yearsOffensive securityPenetration testingOpen source
Skills:Written communicationAnalytical thinkingProblem-solvingCreative thinkingCross-functional collaborationMentorship
Certifications:OSCPOSCEGPEN
Tech Stack:RubyGoPythonTypeScriptRustAI frameworksPrompt injectionPenetration testing

Company Brief

GitLab
Provides a single application for the complete DevSecOps lifecycle, offering source code management, CI/CD, security, and collaboration tools to help teams deliver software faster and more securely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2011
WebsiteLinkedIn