The opportunity
Security Researchers are a part of our Application Security team, who address complex security challenges facing GitLab and its customers to enable GitLab to be the most secure software factory platform on the market. We focus on systemic product security risks and work…
What you'll do
Conduct security research in two or more specialty areas.
Identify novel, systemic, and chained vulnerabilities in GitLab, where: individual weaknesses combine for outsized impact.
Validate security vulnerabilities through hands-on testing, developing: proof-of-concept exploits that demonstrate real-world attack scenarios.
Assess emerging industry vulnerability classes against the GitLab codebase in: your areas of expertise, and drive remediation of the class rather than the instance.
Conduct security research into GitLab's AI and agentic surfaces, and: participate in defining the security requirements that engineering teams build against.
Build the tooling and automation that scales security research, including: agent-assisted vulnerability discovery across our codebase.
What they're looking for
- Research the security posture of open source tools and dependencies: integrated with GitLab, report findings to their maintainers, and track mitigation following our responsible disclosure guidelines .
- Solve technical problems of high scope, complexity, and ambiguity.
- Define and implement security technical and process improvements.
- Contribute to the team roadmap.