4 hours ago
Remote, United States or Remote, CanadaSenior
Base Salary
$139k - $235k/yr
Responsibilities
- Own team initiatives from design through delivery with minimal guidance.
- Design and ship hybrid security analyzers and evaluation harnesses that measure false positives and missed findings against vulnerable benchmark applications.
- Develop detection rules mapped to CWE and test fixtures that validate analyzer behavior.
- Package analyzers for CI jobs, AI agent workflows, and command-line tools with findings reported in GitLab security report formats.
- Build manifest, lockfile, and SBOM parsing for dependency analysis across new ecosystems and formats.
- Extend the automated remediation service from sandboxed dependency updates through merge request creation.
- Improve systems for quality, security, performance, and maintainability while addressing complex team-wide technical problems.
- Mentor intermediate engineers through code review and pairing and maintain internal engineering standards.
- Participate in on-call rotations for product operations, security operations, and urgent engineering issues.
Requirements
- Experience building LLM tooling such as harnesses, agent pipelines, or evaluation systems.
- Substantial professional experience writing and testing production code in a systems language, with depth in Go and/or Rust.
- Familiarity with package managers and dependency management in ecosystems such as npm, Maven, pip, Bundler, or Cargo.
- Application security experience including vulnerability research, secure code review, or writing detection rules.
- Fluency with vulnerability classes including the OWASP Top 10 and CWE and with the software supply chain.
- Track record of owning ambiguous problems and shipping with minimal guidance in a remote, largely asynchronous environment.
- Clear technical communication skills and experience writing design proposals that drive team decisions.
- Helpful experience includes evaluating AI-driven detection against labeled data, performance optimization at scale, program analysis, application frameworks, and containerized workflows or CI/CD.
- Experience with Ruby, Python, or Docker is useful because these technologies are used in the team’s systems and workflows.
Benefits
- Remote-global work arrangement with largely asynchronous collaboration.
- Benefits supporting health, finances, and well-being.
- Flexible paid time off.
- Team Member Resource Groups.
- Equity compensation and Employee Stock Purchase Plan.
- Growth and Development Fund.
- Parental leave.
About GitLab
GitLab builds a DevSecOps platform that unifies source code management, CI/CD, and security with AI-assisted workflows for software teams and enterprises. It sells cloud-hosted and self-managed subscriptions, plus enterprise features and support. Founded in 2014 and headquartered in San Francisco, GitLab is a public company listed on NASDAQ and is widely used by large enterprises, including many in the Fortune 100.
