Base Salary
$168k - $238k/yr
Responsibilities
- Conduct security research across at least two specialty areas and identify novel, systemic, and chained vulnerabilities.
- Validate vulnerabilities through hands-on testing and proof-of-concept exploit development.
- Research AI and agentic security surfaces, including attack scenarios involving GitLab AI workflows.
- Build tooling and automation for scalable security research and agent-assisted vulnerability discovery.
- Assess the security posture of open-source tools and dependencies, report findings, and track mitigation.
- Define security and process improvements, contribute to the team roadmap, and provide actionable feedback to engineering teams.
- Mentor and advise individual contributors and share vulnerability research with the security community.
Requirements
- 7+ years of experience in security research, penetration testing, or offensive security roles.
- Hands-on experience discovering and exploiting vulnerabilities.
- Subject matter expertise in at least two technical areas affecting product security.
- Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust.
- Ability to read and analyze code across multiple languages and codebases.
- Understanding of AI attack vectors such as prompt injection, agent manipulation, and workflow exploitation.
- Experience leading technical objectives in cross-functional teams.
- Strong written communication, analytical, problem-solving, and technical risk-assessment skills.
- Preferred qualifications include published security research or conference presentations, distributed-systems software engineering experience, OSCP, OSCE, GPEN, or similar certifications, and experience with GitLab or similar DevSecOps platforms.
Benefits
- Fully remote work arrangement.
- Benefits supporting health, finances, and well-being.
- Flexible paid time off.
- Team Member Resource Groups.
- Equity compensation and Employee Stock Purchase Plan.
- Growth and Development Fund.
- Parental leave.
Tech Stack
Categories
About GitLab
GitLab is the Intelligent Orchestration Platform where software teams and their AI agents stay in flow to amplify their capacity for innovation. Together, they automate repetitive tasks to plan, build, secure, test, deploy and maintain software. With GitLab, software teams spend less time on coordination overhead and more time on the next big idea. GitLab Duo Agent Platform provides AI agents that automate tasks across the software lifecycle. Agents handle code generation, security analysis, code review, CI/CD troubleshooting, and custom workflows — while teams maintain control through enterprise governance. Build what's next with us. Explore open roles and join our talent community: https://about.gitlab.com/jobs/
