Skip to content
GitLabGitLab

Principal Security Researcher

Leads offensive security research across GitLab’s codebase and AI-powered agentic surfaces, identifying systemic vulnerabilities, developing exploit proofs of concept, and driving remediation. Requires 10+ years of security research or penetration-testing experience and proficiency in multiple programming languages.

About the job

Responsibilities

  • Conduct and lead security research projects across multiple functional areas.
  • Identify novel, systemic, and chained vulnerabilities in GitLab and validate them through hands-on testing.
  • Develop proof-of-concept exploits demonstrating real-world attack scenarios.
  • Assess emerging vulnerability classes against the GitLab codebase and drive systemic remediation.
  • Lead security research into AI and agentic surfaces, defining security requirements for engineering teams.
  • Build and direct tooling and automation for scalable security research, including agent-assisted vulnerability discovery.
  • Research the security posture of open-source tools and dependencies, report findings to maintainers, and track mitigation.
  • Solve highly complex, ambiguous technical problems and help shape team and sub-department roadmaps.
  • Integrate security research findings into engineering and business functions.
  • Teach, mentor, and advise security and engineering contributors.
  • Share knowledge and novel vulnerability types with the security community.

Requirements

  • 10+ years of experience in security research, penetration testing, or offensive security.
  • Strong ability to discover and exploit vulnerabilities in large codebases and complex systems.
  • Proficiency in at least two of Ruby, Go, Python, TypeScript, or Rust.
  • Ability to read and analyze code across multiple languages and codebases.
  • Strong knowledge of AI frameworks and AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation.
  • Ability to establish and drive complex, cross-functional remediation initiatives.
  • Excellent written communication and ability to explain complex topics clearly.
  • Ability to translate technical findings into risk assessments and remediation recommendations.
  • Strong analytical, problem-solving, and creative attack-scenario development skills.

Nice to Have

  • Published security research or conference presentations.
  • Software engineering background with distributed-systems expertise.
  • Experience with GitLab or similar DevSecOps platforms.

Compensation and Benefits

  • United States base salary: $203,200–$275,000 USD.
  • Base salary excludes bonuses, equity, and benefits.
  • Benefits include flexible paid time off, team member resource groups, equity compensation and employee stock purchase plan, growth and development funding, and parental leave.

Skills

Application Security, Penetration Testing, Security Research, Offensive Security, Ruby, Go, Python, TypeScript, Rust, Ai Frameworks, Prompt Injection, Distributed Systems, DevSecOps

GitLab

GitLab

United States
Principal Security Awareness & Human Risk Engineer
$203k+/yrRemote10+ YOESecurity Engineering

Own GitLab’s global security awareness and human-risk program, leading phishing simulations, behavior-change initiatives, training platforms, vendor strategy, and audit support. Requires 10+ years scaling enterprise awareness programs and strong stakeholder influence in a distributed organization.

Wrapbook

Wrapbook

United States
GRC Principal - Data Privacy and Security
$143k+/yrRemote10+ YOESecurity Engineering

Leads security, privacy, audit, vendor-risk, and AI governance programs while setting long-term GRC strategy and executing cross-functional controls. Requires 10+ years of GRC, information security, and privacy compliance experience, with deep SOC 2, privacy, and emerging AI governance expertise.

Lob

Lob

United States

Staff Security Engineer, Cloud and Product Security
$198k+/yrRemote8+ YOESecurity Engineering

Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.

Upside

Upside

Washington, DC
Staff Application Security Engineer
$210k+/yrRemote6+ YOESecurity Engineering

Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.

Illumio

Illumio

Sunnyvale, CA

Staff Engineer - Container Security
$194k+/yrOn-site8+ YOESecurity Engineering

Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.