Staff Software Engineer, Security Factory – Static Analysis

🔥 12 hours ago

🌐 United States, Canada, +2 more countries – Remote

infoinfo

💵 $152.8k - $259.2k / year

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GitLab

GitLab

1001 - 5000 employees

Founded 2014

💼 Consulting

📣 Marketing

🤖 Artificial Intelligence

💰 Secondary Market on 2020-11

Consulting • Marketing • Artificial Intelligence

GitLab is the most comprehensive AI-powered DevSecOps platform, offering tools for automated software delivery, security, and compliance throughout the software development lifecycle. It provides solutions across areas such as AI-assisted development, continuous integration/continuous deployment (CI/CD), source code management, and vulnerability management. GitLab aims to simplify and accelerate software delivery by uniting development, security, and operations on a unified platform. It is particularly recognized for its AI code assistants and has been named a leader in the Gartner Magic Quadrant™ for DevOps Platforms, making it a preferred choice for many enterprises.

📋 Description

• Act as the directly responsible individual for the team's highest-scope initiatives from design through delivery • Ship large features with minimal guidance and shape the team's long-range goals • Bring systems built by one engineer to team ownership through documentation, tests, and shared review • Set technical direction for AI-assisted tooling that implements, reviews, and validates engine changes and findings • Design checks for agent-written changes and generated results, and measure detection quality against benchmark applications with known vulnerabilities • Own the architecture of the program model, including parsing, symbol resolution, intermediate representations, call graphs, taint analysis, and data-flow analysis • Own the pipeline that turns source code into findings and define its extension to new languages and frameworks • Solve high-scope technical problems and advocate for quality, security, and performance improvements • Collaborate with Product Management, UX, Code Security, Composition Analysis, and other partner teams • Mentor engineers through code review and pairing, remove blockers, and improve internal standards • Participate in on-call rotations for product operations, security operations, and urgent engineering issues • Define architecture and specification documents and drive implementation by AI agents and engineers • Build and maintain harnesses, agent instructions, agentic skills, coding and reviewing agents, independent review panels, and performance, API, and dependency gates • Stay current with program analysis and security research, run AI-assisted research and spikes, and turn findings into prototypes, proposals, and upstream contributions • Develop GitLab's SAST capabilities for customer software repositories

🎯 Requirements

• Experience building your own LLM tooling, such as a harness, an agent pipeline, or evaluations, with the judgment to know when output is trustworthy • Extensive professional experience writing, testing, and reviewing production code in Rust, Go, or a comparable systems language, with depth in at least one • Willingness to work across Rust, Go, and Ruby • Experience with performance optimization and containerized workflows and CI/CD, including Docker • Deep program analysis and static analysis background, including parsing and ASTs, intermediate representations, SSA, control-flow and call graphs, taint and data-flow analysis, type inference, incremental and fixpoint computation, or detection rules • Ability to read, evaluate, and apply research literature • Deep application security experience, including vulnerability research, secure code review, or writing detection rules • Fluency with OWASP Top 10 and CWE vulnerability classes • Ability to communicate clearly and concisely about complex technical, architectural, and organizational problems • Ability to write architecture and design specifications that bring a team to a decision • Track record of owning ambiguous, team-wide problems and shipping from concept to production with minimal guidance • Experience defining overarching architecture, delegating component specifications to engineers and AI agents, and getting them implemented reliably • Track record of mentoring engineers, raising technical standards, and influencing technical direction by achieving consensus • Familiarity with popular web or mobile application frameworks (helpful) • Experience designing guardrails for agent-written code, such as mutation testing, fuzzing, and CI gates (helpful) • Research community engagement through publications, tool papers, or upstream open source contributions (helpful)

🏖️ Benefits

• Benefits to support your health, finances, and well-being • Flexible Paid Time Off • Team Member Resource Groups • Equity Compensation & Employee Stock Purchase Plan • Growth and Development Fund • Parental Leave

Apply Now

Similar Jobs

🔥 14 hours ago

Delinea

1001 - 5000

🔒 Cybersecurity

☁️ SaaS

🏢 Enterprise

Staff Security Engineer leading product security for Delinea’s cloud-native identity security platform. Driving threat modeling, secure architecture, cloud standards, and S-SDLC maturity.

🇺🇸 United States – Remote

💵 $170k - $200k / year

💰 Private Equity Round on 2021-03

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🔥 17 hours ago

Eli Lilly and Company

10,000+ employees

💊 Pharmaceuticals

🏥 Healthcare

🧬 Biotechnology

Enterprise AI Security Advisor securing Lilly’s AI agents, models, and infrastructure. Setting cybersecurity strategy and controls for a global pharmaceutical company.

🇺🇸 United States – Remote

💵 $129k - $253k / year

💰 $6.5M Post-IPO Debt - Eli Lilly on 2024-02

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🔥 21 hours ago

Eli Lilly and Company

10,000+ employees

💊 Pharmaceuticals

🏥 Healthcare

🧬 Biotechnology

Enterprise AI Security Advisor securing AI agents, models, and infrastructure at pharmaceutical company Eli Lilly. Defining enterprise controls, threat models, guardrails, and security roadmaps.

🇺🇸 United States – Remote

💵 $129k - $253k / year

💰 $6.5M Post-IPO Debt - Eli Lilly on 2024-02

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🔥 21 hours ago

General Dynamics Information Technology

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

SIEM Security Architect designing Splunk-based cybersecurity solutions for GDIT, a government and defense technology services company. Integrating SOAR, SIEM, EDR, network visibility, and compliance controls.

🔥 21 hours ago

Peraton

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Security Manager leading cybersecurity governance, compliance, incident response, and threat management for Peraton’s government IT environments. Overseeing TX-RAMP, FedRAMP, CJIS, SOC 2, and zero-trust security programs.