GitLab

Staff Security Researcher

GitLab · Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States

Posted 11 days ago

or apply directly on GitLab's site. We never take the application ourselves.

Is this posting real?

This role has been open
11 days
GitLab's roles stay open a median of 41 days
Reposted
No
Salary listed
No
0% of GitLab's roles list one
Ghost-job risk at GitLab
low
0 stale, 9 reposted of 238 open
Hiring momentum
338 roles opened in the last 90 days
↑ up vs. the prior 90 days
Last confirmed on the employer's board
2026-09-17

Measured from postings appearing on and disappearing from GitLab's own greenhouse board since 2026-08-03. Full hiring picture for GitLab.

About this role

As a Staff Security Research Engineer at GitLab, you will conduct advanced security research focused on the company's AI-powered DevSecOps capabilities. Your responsibilities will include identifying and validating vulnerabilities, developing testing methodologies, and translating emerging threats into actionable security improvements. You will work closely with engineering teams to enhance security practices and contribute to the development of secure software tools.

Our read on this posting3.4out of 5
benefits
3/5
freshness
4/5
career value
5/5
role clarity
5/5
pay transparency
0/5

Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of GitLab as an employer.

What you need

  • 7+ years of experience in security research, penetration testing, or offensive security roles
  • Hands-on experience discovering and exploiting vulnerabilities
  • Be a subject matter expert (SME) of at least two technical areas impacting the security of the product
  • Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust
  • Ability to read and analyze code across multiple languages and codebases
  • Understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation

Nice to have

  • Published security research or conference presentations
  • Background in software engineering with distributed systems expertise
  • Security certifications such as OSCP, OSCE, GPEN, or similar
  • Experience with GitLab or similar DevSecOps platforms

What you get

  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Worth weighing

  • No salary listed for locations outside the United States
  • Role involves cutting-edge security research in AI, which may require continuous learning and adaptation
  • Position requires collaboration with engineering teams, which may involve navigating complex technical discussions

Summarised from GitLab's posting. Read the full original.

Listed by GitLab on their greenhouse job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.

More roles at GitLab

All 238 open roles at GitLab