Principal Security ResearcherActive$275K

The opportunity

Security Researchers are a part of our Application Security team, who address complex security challenges facing GitLab and its customers to enable GitLab to be the most secure software factory platform on the market. We focus on systemic product security risks and work…

What you'll do

  • Conduct and lead security research projects across multiple functional areas.

  • Identify novel, systemic, and chained vulnerabilities in GitLab, where: individual weaknesses combine for outsized impact.

  • Validate security vulnerabilities through hands-on testing, developing: proof-of-concept exploits that demonstrate real-world attack scenarios.

  • Assess emerging industry vulnerability classes against the GitLab codebase,: and drive remediation of the class rather than the instance.

  • Lead security research into GitLab's AI and agentic surfaces, and define the: security requirements that engineering teams build against.

  • Build and direct the tooling and automation that scales security research,: including agent-assisted vulnerability discovery across our codebase.

What they're looking for

  • Research the security posture of open source tools and dependencies: integrated with GitLab, report findings to their maintainers, and track mitigation following our responsible disclosure guidelines .
  • Solve technical problems of the highest scope, complexity, and ambiguity.
  • Help shape the team and sub-department roadmap.
  • Lead the integration of security research results into the engineering and: business functions that need to act on them.