SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Security Researcher

GitLab - Remote - Remote - posted 2026-09-05

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

GitLab is seeking a Staff Security Researcher to join the Application Security Team and conduct cutting-edge security research on GitLab's AI-powered DevSecOps platform. You'll work at the forefront of security research, focusing on GitLab's DevSecOps platform, Duo Agent Platform, GitLab Duo Chat, and AI workflows that represent the future of human/AI collaborative development. Key responsibilities include conducting security research in two or more specialty areas; identifying novel, systemic, and chained vulnerabilities where individual weaknesses combine for outsized impact; validating vulnerabilities through hands-on penetration testing and proof-of-concept exploits; assessing emerging vulnerability classes against the GitLab codebase and driving class-level remediation; conducting security research into GitLab's AI and agentic surfaces; building tooling and automation that scales security research including agent-assisted vulnerability discovery; researching the security posture of open source tools and dependencies integrated with GitLab; solving technical problems of high scope, complexity, and ambiguity; defining and implementing security technical and process improvements; contributing to team roadmap; providing actionable feedback to engineering teams; mentoring other individual contributors; and sharing knowledge with the security community. You'll need 7+ years of experience in security research, penetration testing, or offensive security roles; hands-on experience discovering and exploiting vulnerabilities; subject matter expertise in at least two technical areas impacting product security; proficiency in Ruby, Go, Python, TypeScript, or Rust (AI framework experience is a plus); ability to read and analyze code across multiple languages and codebases; and understanding of AI attack surfaces. This role reports to the Senior Manager of Application Security and offers the opportunity to shape security practices in one of the world's largest DevSecOps platforms, working with millions of developers worldwide.

Similar roles