A live role
Principal Security Researcher
from GitLab · read the original and apply on their site
Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States
Our take: The real work here is inventing new ways to break GitLab's AI-powered DevSecOps platform before anyone else can, then driving the fixes across engineering teams.
If you get a thrill from chaining small weaknesses into an outsized exploit and then proving it works, this is your playground. You will lead security research into brand new AI and agentic surfaces, invent your own testing methods, and have real freedom to explore creative attack scenarios that protect millions of developers. Bring a decade of offensive security instinct and a builder's curiosity about how AI systems break.
Needs
- deep security research
- hands-on pentesting
- reading code
- building research tooling
- learning ai frameworks
- seeing hidden patterns
Rewards
- inventing attacks
- novel methodologies
- protecting millions
- creative freedom
- mentoring experts
Demands
- thriving in ambiguity
- cross-team remediation
- translating findings clearly
- writing it down
- carrying high stakes
Grows
- ai security mastery
- synthesising complexity
- shaping strategy
- setting requirements
- fixing the root cause
Values
- pragmatism with velocity
- rigour
- responsible disclosure
- learning culture
Drains
- chasing remediation across teams
- disclosure tracking
Would you love this work?
See how what you love doing lines up with this role - it takes about ten minutes to find out.
Find what I'd love to do next