A live role

Staff Security Researcher

from GitLab · read the original and apply on their site

Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States

Our take: The real work here is hunting novel and chained vulnerabilities across GitLab's AI-powered DevSecOps platform, proving them with hands-on exploits, and turning findings into fixes that harden the platform for millions.

If you get a thrill from chaining small weaknesses into a real exploit and proving it before anyone else can, this is your kind of playground. You will probe brand new AI and agentic surfaces, build the tooling that scales your own research, and turn what you find into fixes that protect millions of developers. It is remote, deep, and creative work for someone who loves both breaking things and making them safer.

Needs

  • hands-on pen testing
  • vulnerability research
  • reading code
  • building tooling
  • synthesising complexity

Rewards

  • real world impact
  • novel invention
  • risk into action
  • sharing with community
  • mentoring others

Demands

  • living with ambiguity
  • cross-team work
  • clear writing
  • translating jargon
  • constructive feedback

Grows

  • root cause thinking
  • ai threat spotting
  • mentoring peers
  • creative experimenting

Values

  • rigour
  • ethics first
  • remote working
  • pragmatism
  • learning culture

Drains

  • disclosure tracking
  • roadmap process work

Would you love this work?

See how what you love doing lines up with this role - it takes about ten minutes to find out.

Find what I'd love to do next