Search Remote Jobs

Principal Security Researcher

Job not on LinkedIn

šŸ”„ 7 minutes ago

🌐 United States, Canada, +2 more countries – Remote

infoinfo

šŸ’µ $203.2k - $275k / year

ā° Full Time

šŸ”“ Lead

šŸ‘®ā€ā™‚ļø Cybersecurity / Security Engineer

šŸ‘» Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

šŸ“Š Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GitLab

GitLab

1001 - 5000 employees

Founded 2014

šŸ’¼ Consulting

šŸ“£ Marketing

šŸ¤– Artificial Intelligence

šŸ’° Secondary Market on 2020-11

Consulting • Marketing • Artificial Intelligence

GitLab is the most comprehensive AI-powered DevSecOps platform, offering tools for automated software delivery, security, and compliance throughout the software development lifecycle. It provides solutions across areas such as AI-assisted development, continuous integration/continuous deployment (CI/CD), source code management, and vulnerability management. GitLab aims to simplify and accelerate software delivery by uniting development, security, and operations on a unified platform. It is particularly recognized for its AI code assistants and has been named a leader in the Gartner Magic Quadrantā„¢ for DevOps Platforms, making it a preferred choice for many enterprises.

šŸ“‹ Description

• Conduct and lead security research projects across multiple functional areas • Identify novel, systemic, and chained vulnerabilities in GitLab • Validate security vulnerabilities through hands-on testing and develop proof-of-concept exploits • Assess emerging industry vulnerability classes against the GitLab codebase and drive class-level remediation • Lead security research into GitLab's AI and agentic surfaces and define security requirements • Build and direct tooling and automation for security research, including agent-assisted vulnerability discovery • Research the security posture of open source tools and dependencies integrated with GitLab • Report findings to maintainers and track mitigation under responsible disclosure guidelines • Solve technical problems of the highest scope, complexity, and ambiguity • Help shape the team and sub-department roadmap • Lead integration of security research results into engineering and business functions • Teach, mentor, and advise domain experts and individual contributors • Share knowledge and novel vulnerability types with the security community • Report to the Senior Manager of Application Security

šŸŽÆ Requirements

• 10+ years of experience in security research, penetration testing, or offensive security roles • Strong ability in discovering and exploiting vulnerabilities in large codebase and complex systems • Proficiency in two or more of Ruby, Go, Python, TypeScript, or Rust • Ability to read and analyze code across multiple languages and codebases • Strong knowledge of AI frameworks • Strong understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation • At ease in establishing and driving complex remediation initiatives involving cross-functional teams • Excellent written communication skills with an ability to articulate complex topics in a clear and concise manner • Ability to translate complex technical findings into clear risk assessments and remediation recommendations • Strong analytical and problem-solving skills with creative thinking about attack scenarios • Nice to Have: Published security research or conference presentations; background in software engineering with distributed systems expertise; experience with GitLab or similar DevSecOps platforms

šŸ–ļø Benefits

• Benefits to support your health, finances, and well-being • Flexible Paid Time Off • Team Member Resource Groups • Equity Compensation & Employee Stock Purchase Plan • Growth and Development Fund • Parental Leave

Apply Now

Similar Jobs

šŸ”„ 17 hours ago

Frontera

201 - 500

šŸ„ Healthcare

šŸ’¼ Consulting

šŸ“¦ Logistics

Head of Information Security/Compliance owning AWS security and SOC 2 audits at Frontera, a pediatric behavioral healthcare technology company. Building compliance infrastructure and representing security to enterprise customers and boards.

šŸ”„ 20 hours ago

Cotiviti

5001 - 10000

šŸ„ Healthcare

šŸ’¼ Consulting

šŸ“¦ Logistics

Principal security architect governing identity, privileged access, and secrets across Cotiviti’s hybrid and multi-cloud enterprise. Leading Delinea PAM, Agentic Identity standards, and compliance controls.

šŸ”„ 22 hours ago

Samsara

1001 - 5000

šŸ“¦ Logistics

šŸ—ļø Construction

šŸ„ Healthcare

Staff Offensive Security Engineer leading vulnerability management and application security for Samsara’s Connected Operations Cloud. Building automation across cloud, firmware, IoT, and corporate systems.

šŸ”„ 22 hours ago

Samsara

1001 - 5000

šŸ“¦ Logistics

šŸ—ļø Construction

šŸ„ Healthcare

Staff Offensive Security Engineer leading vulnerability management for Samsara's Connected Operations Cloud. Automating security across cloud, firmware, IoT, and corporate systems.

šŸ”„ 22 hours ago

Zero Hash

51 - 200

šŸ’³ Fintech

₿ Crypto

🌐 Web 3

Security Architect securing zerohash’s crypto and stablecoin infrastructure platform. Designing cloud, blockchain, and application security across global financial services systems.