Senior Software Security Engineer
Senior engineer on Trust and Safety team building and maintaining abuse prevention systems, anomaly detection, and agentic AI tools for the GitLab SaaS platform. Requires strong Ruby/Rails software engineering background; security experience preferred but not required.
About the job
What you’ll do
- Maintain core abuse prevention systems and build new abuse detection rules to identify and prevent evolving platform abuse such as spam, AI/token, SEO optimization/redirects and other financially motivated abuse campaigns.
- Become a core maintainer for our in-house abuse platform (Ruby on Rails monolith) and be comfortable supporting and building new features for the platform.
- Improve and expand agentic AI capabilities in our abuse mitigation tools, including improving multi agent reasoning decision patterns with a target to reduce HITL operational load.
- Lead collaboration with peer engineering teams to deliver safety improvements for the GitLab product.
- Resolve automation gaps and create efficient, automated processes.
- Create and maintain documentation such as runbooks and procedures.
What you’ll bring
- Strong software development skills with experience in Ruby/Rails.
- Experience working on distributed applications with large codebases and deployed in cloud environments strongly preferred.
- Passion/desire to proactively develop security engineering skills.
- Comfortable working in an all remote environment where results and impact matter above hours worked.
- Strong experience with cloud native development (Google Cloud Platform (GCP) and/or AWS).
- Interest in “thinking like a hacker” and defending against attacks with an “automation first” mindset.
- Interest in handling trust and safety security incidents and collaborating with engineering to harden platform defenses to combat abuse campaigns.
- Experience working on an AI native development team maintaining teams of agents and acting as a code reviewer and experience abstracting your role away from writing code for most cases.
Skills
Ruby, Ruby on Rails, GCP, AWS, AI, LLMs
Similar jobs
Security Engineering jobsSenior Security Compliance Engineer supporting public-sector compliance programs, regulated customers, audits, certifications, and FedRAMP continuous monitoring. Requires 5+ years in GRC or cybersecurity, compliance automation experience, cloud familiarity, and U.S. citizenship and residency.
Owns technology compliance and security assurance controls across corporate and business systems, aligning evidence for SOX, SOC 2, ISO, regulatory, and contractual obligations. The role requires 5+ years in compliance, audit, security, or IT, strong control-testing experience, and a bachelor's degree or equivalent.
Senior Security Engineer on the Red Team performing offensive security, adversarial testing, and red team operations against GenAI/LLM systems, deepfake defenses, cloud infrastructure, and SaaS products. Requires 3+ years of hands-on pen testing/red team experience plus demonstrable GenAI attack experience.
Lead technical response to security incidents across Twilio's global cloud infrastructure, including triage, containment, remediation, documentation, and post-incident improvements. Requires 5+ years incident response experience, expertise with SIEM/SOAR, cloud platforms, and AI-driven security tools.
Build detection, threat-hunting, and automated incident-response capabilities for AI infrastructure, including GPU clusters, training pipelines, and model deployments. The role requires substantial security operations experience, strong programming skills, and expertise in distributed systems or AI/ML environments.