Search Remote Jobs

Staff Security Researcher

Job not on LinkedIn

šŸ”„ 8 minutes ago

🌐 United States, Canada, +2 more countries – Remote

infoinfo

šŸ’µ $168k - $238k / year

ā° Full Time

šŸ”“ Lead

šŸ‘®ā€ā™‚ļø Cybersecurity / Security Engineer

šŸ‘» Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

šŸ“Š Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GitLab

GitLab

1001 - 5000 employees

Founded 2014

šŸ’¼ Consulting

šŸ“£ Marketing

šŸ¤– Artificial Intelligence

šŸ’° Secondary Market on 2020-11

Consulting • Marketing • Artificial Intelligence

GitLab is the most comprehensive AI-powered DevSecOps platform, offering tools for automated software delivery, security, and compliance throughout the software development lifecycle. It provides solutions across areas such as AI-assisted development, continuous integration/continuous deployment (CI/CD), source code management, and vulnerability management. GitLab aims to simplify and accelerate software delivery by uniting development, security, and operations on a unified platform. It is particularly recognized for its AI code assistants and has been named a leader in the Gartner Magic Quadrantā„¢ for DevOps Platforms, making it a preferred choice for many enterprises.

šŸ“‹ Description

• Conduct security research in two or more specialty areas • Identify novel, systemic, and chained vulnerabilities in GitLab • Validate vulnerabilities through hands-on testing and proof-of-concept exploits • Assess emerging vulnerability classes against the GitLab codebase and drive remediation • Research GitLab's AI and agentic surfaces and help define security requirements • Build tooling and automation for scalable security research, including agent-assisted vulnerability discovery • Research the security posture of open source tools and dependencies, report findings to maintainers, and track mitigation • Solve technical problems of high scope, complexity, and ambiguity • Define and implement security technical and process improvements • Contribute to the team roadmap • Provide actionable feedback to engineering teams • Mentor and advise individual contributors • Share knowledge and novel vulnerability types with the security community • Report to the Senior Manager of Application Security

šŸŽÆ Requirements

• 7+ years of experience in security research, penetration testing, or offensive security roles • Hands-on experience discovering and exploiting vulnerabilities • Subject matter expertise in at least two technical areas impacting product security • Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust • Ability to read and analyze code across multiple languages and codebases • Understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation • Experience leading technical objectives in cross-functional teams • Excellent written communication skills with ability to articulate complex topics clearly and concisely • Ability to translate complex technical findings into clear risk assessments and remediation recommendations • Strong analytical and problem-solving skills with creative thinking about attack scenarios • Published security research or conference presentations (nice to have) • Background in software engineering with distributed systems expertise (nice to have) • Security certifications such as OSCP, OSCE, GPEN, or similar (nice to have) • Experience with GitLab or similar DevSecOps platforms (nice to have)

šŸ–ļø Benefits

• Benefits to support your health, finances, and well-being • Flexible Paid Time Off • Team Member Resource Groups • Equity Compensation & Employee Stock Purchase Plan • Growth and Development Fund • Parental Leave

Apply Now

Similar Jobs

šŸ”„ 17 hours ago

Frontera

201 - 500

šŸ„ Healthcare

šŸ’¼ Consulting

šŸ“¦ Logistics

Head of Information Security/Compliance owning AWS security and SOC 2 audits at Frontera, a pediatric behavioral healthcare technology company. Building compliance infrastructure and representing security to enterprise customers and boards.

šŸ”„ 21 hours ago

Cotiviti

5001 - 10000

šŸ„ Healthcare

šŸ’¼ Consulting

šŸ“¦ Logistics

Principal security architect governing identity, privileged access, and secrets across Cotiviti’s hybrid and multi-cloud enterprise. Leading Delinea PAM, Agentic Identity standards, and compliance controls.

šŸ”„ 23 hours ago

Samsara

1001 - 5000

šŸ“¦ Logistics

šŸ—ļø Construction

šŸ„ Healthcare

Staff Offensive Security Engineer leading vulnerability management and application security for Samsara’s Connected Operations Cloud. Building automation across cloud, firmware, IoT, and corporate systems.

šŸ”„ 23 hours ago

Samsara

1001 - 5000

šŸ“¦ Logistics

šŸ—ļø Construction

šŸ„ Healthcare

Staff Offensive Security Engineer leading vulnerability management for Samsara's Connected Operations Cloud. Automating security across cloud, firmware, IoT, and corporate systems.

šŸ”„ 23 hours ago

Zero Hash

51 - 200

šŸ’³ Fintech

₿ Crypto

🌐 Web 3

Security Architect securing zerohash’s crypto and stablecoin infrastructure platform. Designing cloud, blockchain, and application security across global financial services systems.