A live role

Staff Software Engineer, Security Factory: Static Analysis

from GitLab · read the original and apply on their site

Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States

Our take: The real work here is owning the architecture of a static analysis security engine and the tooling that proves it finds real vulnerabilities, while directing engineers and AI agents to build it.

If you light up at the hard problems in program analysis, parsing source into call graphs, tracking tainted data across files, and proving your engine actually catches real vulnerabilities, this is the deep end you have wanted. You will set the technical direction for a static analysis engine, write the specifications a team builds against, and direct AI agents to implement them under your judgment about what counts as trustworthy. It rewards rigour, long thinking, and the quiet satisfaction of making every engineer around you better.

Needs

  • static analysis architecture
  • building security tooling
  • evaluating detection quality
  • setting technical direction
  • writing specifications
  • mentoring engineers

Rewards

  • deep security research
  • protecting real developers
  • shaping team strategy
  • prototyping new ideas
  • growing other engineers

Demands

  • owning ambiguous problems
  • async across time zones
  • on-call rotations
  • building consensus
  • delegating to agents

Grows

  • learning program analysis
  • directing ai agents
  • solving hard problems

Values

  • rigour and trust
  • craftsmanship
  • learning culture
  • async transparency
  • long-term thinking

Drains

  • writing test fixtures
  • on-call troubleshooting
  • maintaining review gates

Would you love this work?

See how what you love doing lines up with this role - it takes about ten minutes to find out.

Find what I'd love to do next