Principal Security Researcher
GitLab · Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States
Posted 11 days ago
or apply directly on GitLab's site. We never take the application ourselves.
Is this posting real?
- This role has been open
- 11 days GitLab's roles stay open a median of 41 days
- Reposted
- No
- Salary listed
- No 0% of GitLab's roles list one
- Ghost-job risk at GitLab
- low 0 stale, 9 reposted of 238 open
- Hiring momentum
- 338 roles opened in the last 90 days ↑ up vs. the prior 90 days
- Last confirmed on the employer's board
- 2026-09-17
Measured from postings appearing on and disappearing from GitLab's own greenhouse board since 2026-08-03. Full hiring picture for GitLab.
About this role
The Principal Security Researcher at GitLab will lead security research projects focused on identifying and validating vulnerabilities in GitLab's AI-powered DevSecOps capabilities. This role involves developing testing methodologies, conducting penetration testing, and translating emerging threats into actionable security improvements. The researcher will also mentor others, shape security practices, and work with engineering teams to enhance the security of GitLab's platform.
- benefits
- 3/5
- freshness
- 4/5
- career value
- 5/5
- role clarity
- 5/5
- pay transparency
- 0/5
Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of GitLab as an employer.
What you need
- 10+ years of experience in security research, penetration testing, or offensive security roles
- Strong ability in discovering and exploiting vulnerabilities in large codebase and complex systems
- Proficiency in two or more of Ruby, Go, Python, TypeScript, or Rust
- Ability to read and analyze code across multiple languages and codebases
- Strong knowledge of AI frameworks
- Strong understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation
Nice to have
- Published security research or conference presentations
- Background in software engineering with distributed systems expertise
- Experience with GitLab or similar DevSecOps platforms
What you get
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
Worth weighing
- No salary listed for locations outside the United States
- The role involves working with cutting-edge AI systems, which may involve a steep learning curve for those unfamiliar with AI security
- The position requires a high level of experience, which may deter less experienced candidates from applying
Summarised from GitLab's posting. Read the full original.
Listed by GitLab on their greenhouse job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.
More roles at GitLab
- Senior Backend Engineer, UKRemote, United Kingdom
- Senior Backend Engineer, IndiaBangalore, India
- Senior Backend Engineer, AMERRemote, Canada; Remote, United States
- Ecosystem Sales ManagerRemote, United States
- Staff Site Reliability Engineer - Monitoring and Anomaly Detection (Monetization)Bangalore, India
- Strategic Account Executive - SeattleRemote, United States
- Senior Product Manager, Secret Detection and Vulnerability ResearchRemote, United States
- RPA Engineer, UiPathBangalore, India