A live role

Principal Security Researcher

from GitLab · read the original and apply on their site

Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States

Our take: The real work here is inventing new ways to break GitLab's AI-powered DevSecOps platform before anyone else can, then driving the fixes across engineering teams.

If you get a thrill from chaining small weaknesses into an outsized exploit and then proving it works, this is your playground. You will lead security research into brand new AI and agentic surfaces, invent your own testing methods, and have real freedom to explore creative attack scenarios that protect millions of developers. Bring a decade of offensive security instinct and a builder's curiosity about how AI systems break.

Needs

  • deep security research
  • hands-on pentesting
  • reading code
  • building research tooling
  • learning ai frameworks
  • seeing hidden patterns

Rewards

  • inventing attacks
  • novel methodologies
  • protecting millions
  • creative freedom
  • mentoring experts

Demands

  • thriving in ambiguity
  • cross-team remediation
  • translating findings clearly
  • writing it down
  • carrying high stakes

Grows

  • ai security mastery
  • synthesising complexity
  • shaping strategy
  • setting requirements
  • fixing the root cause

Values

  • pragmatism with velocity
  • rigour
  • responsible disclosure
  • learning culture

Drains

  • chasing remediation across teams
  • disclosure tracking

Would you love this work?

See how what you love doing lines up with this role - it takes about ten minutes to find out.

Find what I'd love to do next