# Staff Security Researcher

**Company:** [GitLab](https://hotfix.jobs/companies/gitlab)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $168k – $238k/yr
**Experience:** 7+ years
**Skills:** Ruby, Go, Python, TypeScript, Rust, Ai Frameworks, Prompt Injection, Penetration Testing, Vulnerability Research, Distributed Systems, Oscp, Osce, Gpen, DevSecOps
**Posted:** 2026-09-05

> Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.

## Job Description

## Responsibilities
- Conduct security research across at least two specialty areas.
- Identify novel, systemic, and chained vulnerabilities in GitLab.
- Validate vulnerabilities through hands-on testing and proof-of-concept exploits.
- Assess emerging vulnerability classes against the GitLab codebase and drive class-level remediation.
- Research security risks in GitLab’s AI and agentic surfaces and help define security requirements.
- Build tooling and automation for scalable security research, including agent-assisted vulnerability discovery.
- Research the security posture of open-source tools and dependencies, report findings to maintainers, and track mitigation.
- Solve high-scope, complex, and ambiguous technical problems.
- Define and implement security and process improvements.
- Contribute to the team roadmap and provide actionable feedback to engineering teams.
- Mentor and advise individual contributors.
- Share knowledge and novel vulnerability types with the security community.

## Requirements
- 7+ years of experience in security research, penetration testing, or offensive security.
- Hands-on experience discovering and exploiting vulnerabilities.
- Subject matter expertise in at least two technical areas affecting product security.
- Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust.
- Ability to read and analyze code across multiple languages and codebases.
- Understanding of AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation.
- Experience leading technical objectives in cross-functional teams.
- Excellent written communication and ability to explain complex topics clearly.
- Ability to translate technical findings into risk assessments and remediation recommendations.
- Strong analytical, problem-solving, and creative attack-scenario skills.

## Nice to Have
- Published security research or conference presentations.
- Software engineering background with distributed-systems expertise.
- Security certifications such as OSCP, OSCE, or GPEN.
- Experience with GitLab or similar DevSecOps platforms.
- Experience with AI frameworks.

## Compensation and Benefits
- United States base salary: $168,000–$238,000 USD.
- Benefits include flexible paid time off, team member resource groups, equity compensation and employee stock purchase plan, growth and development funding, and parental leave.

## Similar jobs

- [Staff Security Engineer, IAM](https://hotfix.jobs/jobs/f79f024d-e0b6-41b0-b434-9f047bfa2630) - GitLab - Remote - $168k – $238k/yr
- [Staff Corporate Security Engineer](https://hotfix.jobs/jobs/f89034fc-b54a-4d06-a7c4-971c896526ac) - GitLab - Remote - $168k – $238k/yr
- [Staff IAM Engineer](https://hotfix.jobs/jobs/7a722d47-b173-4ffc-9981-f10ed9f3ce9c) - Ironclad - San Francisco, CA - $170k – $190k/yr
- [Staff Vulnerability Management Engineer](https://hotfix.jobs/jobs/f6eb93ea-70d6-496f-a251-e679113fd047) - Chainguard - Remote - $170k – $231k/yr
- [Staff Identity Governance and Access Engineer](https://hotfix.jobs/jobs/8fe7fe60-ff7a-48f4-a805-f3f100e1814f) - Okta - Bellevue, WA - $161k – $221k/yr

**Apply:** https://hotfix.jobs/jobs/6b308cd8-be33-459a-b904-08e54567ad7b
**Canonical:** https://hotfix.jobs/jobs/6b308cd8-be33-459a-b904-08e54567ad7b