4 hours ago
Remote, United States +3 moreStaff+
Base Salary
$153k - $259k/yr
Responsibilities
- Act as the directly responsible individual for high-scope initiatives from design through delivery and shape the team’s long-range technical goals.
- Own the architecture of the static analysis program model and source-to-findings pipeline, including parsing, symbol resolution, intermediate representations, call graphs, taint analysis, and data-flow analysis.
- Design and maintain AI-assisted coding, review, evaluation, and validation tooling with independent agents, guardrails, performance gates, API gates, dependency gates, and human review escalation.
- Build and apply evaluation harnesses, benchmark applications, SAST rules mapped to CWE and OWASP, and test fixtures to measure detection quality.
- Define architecture and component specifications, delegate implementation to engineers and AI agents, and drive reliable phased delivery.
- Mentor engineers, conduct code reviews and pairing, remove blockers, and improve internal engineering standards.
- Collaborate with Product Management, UX, Code Security, Composition Analysis, and other partner teams on quality, security, and performance.
- Participate in on-call rotations supporting product operations, security operations, and urgent engineering issues.
- Stay current with program analysis and security research and turn findings into prototypes, proposals, and upstream contributions.
Requirements
- Extensive professional experience writing, testing, and reviewing production code in Rust, Go, or a comparable systems language, with depth in at least one.
- Experience building LLM tooling such as agent harnesses, agent pipelines, or evaluation systems and judging when generated output is trustworthy.
- Experience with performance optimization, containerized workflows, Docker, and CI/CD.
- Deep program analysis or static analysis experience involving parsing, ASTs, intermediate representations, SSA, control-flow and call graphs, taint and data-flow analysis, type inference, incremental or fixpoint computation, detection rules, and relevant research literature.
- Deep application security experience in areas such as vulnerability research, secure code review, or detection-rule development, with fluency in OWASP Top 10 and CWE.
- Experience defining overarching system architecture, delegating component specifications, and getting implementations delivered reliably by engineers and AI agents.
- Strong communication and technical writing skills for complex technical, architectural, and organizational topics.
- Track record of owning ambiguous team-wide problems, shipping from concept to production with minimal guidance, mentoring engineers, raising technical standards, and influencing technical direction.
- Helpful experience includes familiarity with web or mobile application frameworks, agent-code guardrails such as mutation testing and fuzzing, research-community engagement, publications, tool papers, or open source contributions in program analysis or security.
Benefits
- Remote-global work arrangement with location-based eligibility requirements that may vary by role.
- Benefits supporting health, finances, and well-being.
- Flexible paid time off.
- Team Member Resource Groups.
- Equity compensation and Employee Stock Purchase Plan.
- Growth and Development Fund.
- Parental leave.
About GitLab
GitLab builds a DevSecOps platform that unifies source code management, CI/CD, and security with AI-assisted workflows for software teams and enterprises. It sells cloud-hosted and self-managed subscriptions, plus enterprise features and support. Founded in 2014 and headquartered in San Francisco, GitLab is a public company listed on NASDAQ and is widely used by large enterprises, including many in the Fortune 100.
