A live role

Senior Software Engineer, Security Factory: Code Security

from GitLab · read the original and apply on their site

Remote, Canada; Remote, United States

Our take: The real work here is building security analyzers that pair deterministic detection with AI reasoning, proving they work with honest evaluation, and owning them end to end in an async remote team.

If you love building security analysis engines that blend hard deterministic rules with careful AI reasoning, and you insist on proving they actually work, this is your kind of problem. You will own real systems end to end in a remote, async team, teaching an engine what code depends on and hunting the vulnerabilities hiding inside. The people who thrive here write clean systems code, hold a high bar for what counts as a trustworthy result, and enjoy making others better through review and pairing.

Needs

  • systems code in go rust
  • designing analyzers
  • building eval harnesses
  • security analysis
  • parsing dependency manifests
  • llm tooling judgment

Rewards

  • solving complex problems
  • protecting real developers
  • mentoring engineers
  • inventing detection engines

Demands

  • owning ambiguous problems
  • shipping with minimal guidance
  • async remote work
  • cross-team advocacy

Grows

  • new package ecosystems
  • vulnerability classes
  • multiple systems languages

Values

  • rigour and trustworthy results
  • craftsmanship in code
  • ai as a tool
  • honest judgment

Drains

  • on-call rotations
  • writing test fixtures
  • documenting handovers

Would you love this work?

See how what you love doing lines up with this role - it takes about ten minutes to find out.

Find what I'd love to do next