Staff Security Researcher
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.
About the job
Responsibilities
- Conduct security research across at least two specialty areas.
- Identify novel, systemic, and chained vulnerabilities in GitLab.
- Validate vulnerabilities through hands-on testing and proof-of-concept exploits.
- Assess emerging vulnerability classes against the GitLab codebase and drive class-level remediation.
- Research security risks in GitLab’s AI and agentic surfaces and help define security requirements.
- Build tooling and automation for scalable security research, including agent-assisted vulnerability discovery.
- Research the security posture of open-source tools and dependencies, report findings to maintainers, and track mitigation.
- Solve high-scope, complex, and ambiguous technical problems.
- Define and implement security and process improvements.
- Contribute to the team roadmap and provide actionable feedback to engineering teams.
- Mentor and advise individual contributors.
- Share knowledge and novel vulnerability types with the security community.
Requirements
- 7+ years of experience in security research, penetration testing, or offensive security.
- Hands-on experience discovering and exploiting vulnerabilities.
- Subject matter expertise in at least two technical areas affecting product security.
- Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust.
- Ability to read and analyze code across multiple languages and codebases.
- Understanding of AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation.
- Experience leading technical objectives in cross-functional teams.
- Excellent written communication and ability to explain complex topics clearly.
- Ability to translate technical findings into risk assessments and remediation recommendations.
- Strong analytical, problem-solving, and creative attack-scenario skills.
Nice to Have
- Published security research or conference presentations.
- Software engineering background with distributed-systems expertise.
- Security certifications such as OSCP, OSCE, or GPEN.
- Experience with GitLab or similar DevSecOps platforms.
- Experience with AI frameworks.
Compensation and Benefits
- United States base salary: $168,000–$238,000 USD.
- Benefits include flexible paid time off, team member resource groups, equity compensation and employee stock purchase plan, growth and development funding, and parental leave.
Skills
Ruby, Go, Python, TypeScript, Rust, Ai Frameworks, Prompt Injection, Penetration Testing, Vulnerability Research, Distributed Systems, Oscp, Osce, Gpen, DevSecOps
Similar jobs
Security Engineering jobsStaff-level security engineer leading enterprise IAM, cloud identity, AI platform access, and non-human identity governance. The role requires deep Okta, infrastructure-as-code, Python, GCP or AWS, and regulated-environment experience.
Leads corporate endpoint security architecture and automation, with emphasis on macOS, Terraform, GitOps, and scalable controls across device platforms. The role partners across security and IT, improves detection and auditability, and mentors engineers.
Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.
Leads vulnerability disclosure operations at scale, including novel vulnerability measurement, CVE assignment, embargo coordination, and industry collaboration. The Staff individual contributor provides technical leadership and requires extensive software security or open source experience.
Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.