GitLab

Staff Software Engineer, Security Factory: Static Analysis

GitLab
Apply
4 hours ago
Remote, United States +3 moreStaff+

Base Salary

$153k - $259k/yr

Responsibilities

  • Act as the directly responsible individual for high-scope initiatives from design through delivery and shape the team’s long-range technical goals.
  • Own the architecture of the static analysis program model and source-to-findings pipeline, including parsing, symbol resolution, intermediate representations, call graphs, taint analysis, and data-flow analysis.
  • Design and maintain AI-assisted coding, review, evaluation, and validation tooling with independent agents, guardrails, performance gates, API gates, dependency gates, and human review escalation.
  • Build and apply evaluation harnesses, benchmark applications, SAST rules mapped to CWE and OWASP, and test fixtures to measure detection quality.
  • Define architecture and component specifications, delegate implementation to engineers and AI agents, and drive reliable phased delivery.
  • Mentor engineers, conduct code reviews and pairing, remove blockers, and improve internal engineering standards.
  • Collaborate with Product Management, UX, Code Security, Composition Analysis, and other partner teams on quality, security, and performance.
  • Participate in on-call rotations supporting product operations, security operations, and urgent engineering issues.
  • Stay current with program analysis and security research and turn findings into prototypes, proposals, and upstream contributions.

Requirements

  • Extensive professional experience writing, testing, and reviewing production code in Rust, Go, or a comparable systems language, with depth in at least one.
  • Experience building LLM tooling such as agent harnesses, agent pipelines, or evaluation systems and judging when generated output is trustworthy.
  • Experience with performance optimization, containerized workflows, Docker, and CI/CD.
  • Deep program analysis or static analysis experience involving parsing, ASTs, intermediate representations, SSA, control-flow and call graphs, taint and data-flow analysis, type inference, incremental or fixpoint computation, detection rules, and relevant research literature.
  • Deep application security experience in areas such as vulnerability research, secure code review, or detection-rule development, with fluency in OWASP Top 10 and CWE.
  • Experience defining overarching system architecture, delegating component specifications, and getting implementations delivered reliably by engineers and AI agents.
  • Strong communication and technical writing skills for complex technical, architectural, and organizational topics.
  • Track record of owning ambiguous team-wide problems, shipping from concept to production with minimal guidance, mentoring engineers, raising technical standards, and influencing technical direction.
  • Helpful experience includes familiarity with web or mobile application frameworks, agent-code guardrails such as mutation testing and fuzzing, research-community engagement, publications, tool papers, or open source contributions in program analysis or security.

Benefits

  • Remote-global work arrangement with location-based eligibility requirements that may vary by role.
  • Benefits supporting health, finances, and well-being.
  • Flexible paid time off.
  • Team Member Resource Groups.
  • Equity compensation and Employee Stock Purchase Plan.
  • Growth and Development Fund.
  • Parental leave.

Tech Stack

Categories

GitLab

About GitLab

1,001-5,000 employees

GitLab builds a DevSecOps platform that unifies source code management, CI/CD, and security with AI-assisted workflows for software teams and enterprises. It sells cloud-hosted and self-managed subscriptions, plus enterprise features and support. Founded in 2014 and headquartered in San Francisco, GitLab is a public company listed on NASDAQ and is widely used by large enterprises, including many in the Fortune 100.

Contact me