Principal Security Researcher

at GitLab
USD 203,200-275,000 per year
SENIOR
✅ Remote

Tech Stack

AI @ 7 Communication @ 6 Distributed Systems Go @ 6 Python @ 6 Ruby @ 6 Rust @ 6 Security @ 4 TypeScript @ 6

Details

GitLab is seeking a Principal Security Researcher to join its Application Security team and conduct security research on GitLab's AI-powered DevSecOps capabilities. The role focuses on proactively identifying and validating vulnerabilities across the GitLab DevSecOps platform, Duo Agent Platform, GitLab Duo Chat, and AI workflows.

The researcher will develop novel testing methodologies for AI agent security, conduct hands-on penetration testing, and translate emerging threats into actionable security improvements. This role reports to the Senior Manager of Application Security.

Responsibilities

  • Conduct and lead security research projects across multiple functional areas.
  • Identify novel, systemic, and chained vulnerabilities in GitLab.
  • Validate vulnerabilities through hands-on testing and proof-of-concept exploits demonstrating real-world attack scenarios.
  • Assess emerging vulnerability classes against the GitLab codebase and drive remediation of the class rather than the individual instance.
  • Lead security research into GitLab's AI and agentic surfaces and define security requirements for engineering teams.
  • Build and direct tooling and automation to scale security research, including agent-assisted vulnerability discovery across the codebase.
  • Research the security posture of open-source tools and dependencies integrated with GitLab, report findings to maintainers, and track mitigation under GitLab's responsible disclosure guidelines.
  • Solve technical problems involving high scope, complexity, and ambiguity.
  • Help shape the team and sub-department roadmap.
  • Lead integration of security research results into engineering and business functions.
  • Teach, mentor, and advise domain experts and individual contributors across multiple teams.
  • Share knowledge and novel vulnerability types with the security community.

Requirements

  • 10+ years of experience in security research, penetration testing, or offensive security roles.
  • Strong ability to discover and exploit vulnerabilities in large codebases and complex systems.
  • Proficiency in at least two of Ruby, Go, Python, TypeScript, or Rust.
  • Ability to read and analyze code across multiple languages and codebases.
  • Strong knowledge of AI frameworks.
  • Strong understanding of AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation.
  • Ability to establish and drive complex remediation initiatives involving cross-functional teams.
  • Excellent written communication skills and the ability to articulate complex topics clearly and concisely.
  • Ability to translate complex technical findings into clear risk assessments and remediation recommendations.
  • Strong analytical and problem-solving skills, with creative thinking about attack scenarios.

Nice to Have

  • Published security research or conference presentations.
  • Software engineering background with distributed systems expertise.
  • Experience with GitLab or similar DevSecOps platforms.

Team

Security Researchers are part of GitLab's Application Security team, which addresses complex security challenges facing GitLab and its customers. The team focuses on systemic product security risks and works cross-functionally to mitigate them while maintaining engineering development velocity.

Benefits

  • Benefits supporting health, finances, and well-being.
  • Flexible paid time off.
  • Team member resource groups.
  • Equity compensation and employee stock purchase plan.
  • Growth and development fund.
  • Parental leave.

GitLab roles are remote, with location-based eligibility requirements for some positions.

More jobs at GitLab

Similar jobs