Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
AWS @ 7
Agentic AI
GCP @ 7
LLM
Ruby @ 7
Ruby on Rails
SEO
Security @ 4
Software Development @ 7
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
GitLab is seeking a Senior Software Security Engineer to engineer security improvements to the GitLab product and build and maintain tools that detect and prevent abuse on its SaaS platforms. The role requires a strong software engineering background with experience in large Ruby/Rails codebases. Formal security engineering experience is not required.
As part of the global Trust and Safety team, you will identify abuse patterns and trends and build anomaly detection and prevention systems to mitigate abusive users and activities. The team uses automation, LLM-aided anomaly detection, and user behavior analysis to proactively detect and prevent abuse on GitLab.com.
Responsibilities
- Maintain core abuse prevention systems and build new abuse detection rules for evolving platform abuse, including spam, AI/token abuse, SEO optimization and redirects, and other financially motivated abuse campaigns.
- Become a core maintainer of the in-house abuse platform, a Ruby on Rails monolith, and support and build new platform features.
- Improve and expand agentic AI capabilities in abuse mitigation tools, including multi-agent reasoning decision patterns, with the goal of reducing human-in-the-loop operational load.
- Lead collaboration with peer engineering teams to deliver safety improvements for the GitLab product.
- Resolve automation gaps and create efficient, automated processes.
- Create and maintain documentation, including runbooks and procedures.
- Collaborate with Security Incident Response, Signals Engineering, Threat Intelligence, and Red Team teams.
Requirements
- Strong software development skills with experience in Ruby and Rails.
- Experience working on distributed applications with large codebases deployed in cloud environments is strongly preferred.
- Passion or desire to proactively develop security engineering skills.
- Comfortable working in an all-remote environment where results and impact matter more than hours worked.
- Strong experience with cloud-native development using Google Cloud Platform (GCP) and/or AWS.
- Interest in thinking like a hacker and defending against attacks with an automation-first mindset.
- Interest in handling trust and safety security incidents and collaborating with engineering teams to harden platform defenses against abuse campaigns.
- Experience working on an AI-native development team, maintaining teams of agents, acting as a code reviewer, and abstracting the engineer's role away from writing code in most cases.
Benefits
- Benefits supporting health, finances, and well-being.
- Flexible paid time off.
- Team member resource groups.
- Equity compensation and employee stock purchase plan.
- Growth and development fund.
- Parental leave.
Salary
The United States base salary range is $139,200–$196,000 USD per year. The range applies to United States residents and excludes bonuses, equity, and benefits. Salary is determined based on factors including grade level, education, experience, knowledge, skills, abilities, equity with other team members, market data, and geographic location.
GitLab states that all roles are remote, although some roles may have location-based eligibility requirements.