SlipstreamJobsFresh Startup & VC-Backed Jobs

Principal Security Researcher

GitLab - Remote - Remote - posted 2026-09-05

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

GitLab is seeking a Principal Security Researcher to join the Application Security Team and conduct cutting-edge security research on GitLab's AI-powered DevSecOps platform. You'll work at the forefront of security research, focusing on GitLab's DevSecOps platform, Duo Agent Platform, GitLab Duo Chat, and AI workflows that represent the future of human/AI collaborative development. Key responsibilities include conducting and leading security research projects across multiple functional areas; identifying novel, systemic, and chained vulnerabilities where individual weaknesses combine for outsized impact; validating security vulnerabilities through hands-on testing and developing proof-of-concept exploits; assessing emerging vulnerability classes against the GitLab codebase and driving class-level remediation; leading security research into GitLab's AI and agentic surfaces; building and directing tooling and automation that scales security research; researching the security posture of open source tools and dependencies; solving technical problems of the highest scope and complexity; helping shape team and sub-department roadmap; leading integration of security research results into engineering and business functions; mentoring and advising domain experts and individual contributors; and sharing knowledge and novel vulnerability types with the security community. You'll need 10+ years of experience in security research, penetration testing, or offensive security roles; strong ability in discovering and exploiting vulnerabilities in large codebases and complex systems; proficiency in two or more of Ruby, Go, Python, TypeScript, or Rust; ability to read and analyze code across multiple languages; strong knowledge of AI frameworks; strong understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation; and ability to establish and drive complex remediation efforts. This role reports to the Senior Manager of Application Security and offers the unique opportunity to shape security and AI security practices in one of the world's largest DevSecOps platforms.

Similar roles