Staff Security Researcher
GitLab · Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States
Posted 11 days ago
or apply directly on GitLab's site. We never take the application ourselves.
Is this posting real?
- This role has been open
- 11 days GitLab's roles stay open a median of 41 days
- Reposted
- No
- Salary listed
- No 0% of GitLab's roles list one
- Ghost-job risk at GitLab
- low 0 stale, 9 reposted of 238 open
- Hiring momentum
- 338 roles opened in the last 90 days ↑ up vs. the prior 90 days
- Last confirmed on the employer's board
- 2026-09-17
Measured from postings appearing on and disappearing from GitLab's own greenhouse board since 2026-08-03. Full hiring picture for GitLab.
About this role
As a Staff Security Research Engineer at GitLab, you will conduct advanced security research focused on the company's AI-powered DevSecOps capabilities. Your responsibilities will include identifying and validating vulnerabilities, developing testing methodologies, and translating emerging threats into actionable security improvements. You will work closely with engineering teams to enhance security practices and contribute to the development of secure software tools.
- benefits
- 3/5
- freshness
- 4/5
- career value
- 5/5
- role clarity
- 5/5
- pay transparency
- 0/5
Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of GitLab as an employer.
What you need
- 7+ years of experience in security research, penetration testing, or offensive security roles
- Hands-on experience discovering and exploiting vulnerabilities
- Be a subject matter expert (SME) of at least two technical areas impacting the security of the product
- Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust
- Ability to read and analyze code across multiple languages and codebases
- Understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation
Nice to have
- Published security research or conference presentations
- Background in software engineering with distributed systems expertise
- Security certifications such as OSCP, OSCE, GPEN, or similar
- Experience with GitLab or similar DevSecOps platforms
What you get
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
Worth weighing
- No salary listed for locations outside the United States
- Role involves cutting-edge security research in AI, which may require continuous learning and adaptation
- Position requires collaboration with engineering teams, which may involve navigating complex technical discussions
Summarised from GitLab's posting. Read the full original.
Listed by GitLab on their greenhouse job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.
More roles at GitLab
- Senior Backend Engineer, UKRemote, United Kingdom
- Senior Backend Engineer, IndiaBangalore, India
- Senior Backend Engineer, AMERRemote, Canada; Remote, United States
- Ecosystem Sales ManagerRemote, United States
- Staff Site Reliability Engineer - Monitoring and Anomaly Detection (Monetization)Bangalore, India
- Strategic Account Executive - SeattleRemote, United States
- Senior Product Manager, Secret Detection and Vulnerability ResearchRemote, United States
- RPA Engineer, UiPathBangalore, India