Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
Communication @ 6
Distributed Systems @ 6
Go @ 6
Python @ 6
Ruby @ 6
Rust @ 6
Security @ 4
TypeScript @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
GitLab is seeking a Staff Security Research Engineer to join its Application Security Team and conduct security research on GitLab's AI-powered DevSecOps capabilities. The role focuses on proactively identifying and validating vulnerabilities across the GitLab DevSecOps platform, Duo Agent Platform, GitLab Duo Chat, and AI workflows.
The position involves developing novel testing methodologies for AI agent security, conducting hands-on penetration testing, researching emerging threats, and translating findings into actionable security improvements. The role reports to the Senior Manager of Application Security.
Responsibilities
- Conduct security research in two or more specialty areas.
- Identify novel, systemic, and chained vulnerabilities in GitLab.
- Validate vulnerabilities through hands-on testing and proof-of-concept exploits.
- Assess emerging vulnerability classes against the GitLab codebase and drive remediation of systemic issues.
- Research GitLab's AI and agentic surfaces, including security requirements for engineering teams.
- Build tooling and automation to scale security research, including agent-assisted vulnerability discovery.
- Research the security posture of open-source tools and dependencies integrated with GitLab, report findings to maintainers, and track mitigation according to responsible disclosure guidelines.
- Solve technical problems with high scope, complexity, and ambiguity.
- Define and implement security technical and process improvements.
- Contribute to the team roadmap.
- Provide actionable feedback to engineering teams on security findings.
- Mentor and advise individual contributors within and outside the team.
- Share knowledge and novel vulnerability types with the security community.
Requirements
- 7+ years of experience in security research, penetration testing, or offensive security roles.
- Hands-on experience discovering and exploiting vulnerabilities.
- Subject matter expertise in at least two technical areas affecting product security.
- Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust.
- Ability to read and analyze code across multiple languages and codebases.
- Understanding of AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation.
- Experience leading technical objectives in cross-functional teams.
- Excellent written communication skills and the ability to explain complex topics clearly and concisely.
- Ability to translate technical findings into clear risk assessments and remediation recommendations.
- Strong analytical and problem-solving skills, with creative thinking about attack scenarios.
- Experience with AI frameworks is an asset.
- Published security research or conference presentations are nice to have.
- A background in software engineering with distributed systems expertise is nice to have.
- Security certifications such as OSCP, OSCE, GPEN, or similar are nice to have.
- Experience with GitLab or similar DevSecOps platforms is nice to have.
About the Team
Security Researchers are part of GitLab's Application Security team. The team addresses complex security challenges affecting GitLab and its customers, focuses on systemic product security risks, and works cross-functionally to mitigate them while maintaining engineering velocity.
Compensation
The United States base salary range for this role is $168,000–$238,000 USD per year. The range applies to United States residents and excludes bonuses, equity, and benefits.
Benefits
- Benefits supporting health, finances, and well-being.
- Flexible paid time off.
- Team member resource groups.
- Equity compensation and employee stock purchase plan.
- Growth and development fund.
- Parental leave.
GitLab hires remotely in countries around the world, although some roles may have location-based eligibility requirements. GitLab is an equal opportunity workplace and an affirmative action employer.