Principal Security Researcher

GitLab

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
CanadaIsraelUnited Kingdom
Salary
$203,200–$275,000 / yr
Posted
36 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $185k
This role $239k
$127k $291k
below market most similar roles pay here above market

This role pays more than 90% of similar roles. Most pay $156,062–$214,500 — the blue band above. At the midpoint, this role pays about $239k versus about $185k for comparable roles.

Based on 240 similar postings.

Employer

About GitLab

GitLab is an all-remote software company that develops an AI-powered DevSecOps platform combining source code management, CI/CD, security scanning, and project planning in a single application.

GitLab currently has 55 open roles on FindRole.

Listed pay typically runs $152,800–$235,600 across 49 roles with salary data.

Most-posted roles

View all roles at GitLab

At a glance

TL;DR · Principal Security Researcher

The Principal Security Researcher joins the Application Security team to conduct cutting-edge research on AI-powered DevSecOps capabilities. This role involves identifying systemic vulnerabilities, developing proof-of-concept exploits, and leading research into AI agentic surfaces. You will build and direct tooling and automation for agent-assisted vulnerability discovery while defining security requirements for engineering teams. The position requires proficiency in at least two of Ruby, Go, Python, TypeScript, or Rust, alongside strong knowledge of AI frameworks and attack vectors like prompt injection and agent manipulation. You will solve complex technical problems, assess open source dependencies, and mentor other domain experts. The work focuses on securing the GitLab DevSecOps platform, Duo Agent Platform, and GitLab Duo Chat to protect human and AI collaborative development workflows.

What you'll do

  • Conduct and lead security research projects across multiple functional areas of the platform.
  • Identify novel, systemic, and chained vulnerabilities within the GitLab codebase.
  • Validate vulnerabilities through hands-on testing and the development of proof-of-concept exploits.
  • Lead security research into AI and agentic surfaces to define engineering security requirements.
  • Build and direct automation tools to scale security research and agent-assisted vulnerability discovery.
  • Research the security posture of integrated open source tools and report findings to maintainers.
  • Integrate security research results into engineering and business functions to drive remediation.
  • Teach, mentor, and advise domain experts and individual contributors across several teams.

What we're looking for

  • 10+ years of experience in security research, penetration testing, or offensive security roles.
  • Strong ability in discovering and exploiting vulnerabilities in large codebases and complex systems.
  • Proficiency in two or more of Ruby, Go, Python, TypeScript, or Rust.
  • Ability to read and analyze code across multiple languages and codebases.
  • Strong knowledge of AI frameworks and AI attack vectors including prompt injection and agent manipulation.
  • Ability to establish and drive complex remediation initiatives involving cross-functional teams.
  • Excellent written communication skills to articulate complex topics and translate technical findings into risk assessments.
  • Published security research or conference presentations; background in software engineering with distributed systems expertise; experience with GitLab or similar DevSecOps platforms (preferred).

More like this

Similar roles

Staff Security Researcher

GitLab

Remote (Canada) +2 36 days ago $168,000–$238,000
DevSecOps Security Research Penetration Testing AI Security Ruby Go Python TypeScript Rust Distributed Systems Prompt Injection OSCP OSCE GPEN GitLab
7+ yrs exp Remote

Principal Security Researcher

Microsoft

Remote 67 days ago $142,800–$274,800
Vulnerability Research AI Agents Large Language Models Fuzzing Static Analysis Dynamic Analysis Reverse Engineering Symbolic Execution Taint Analysis Exploit Development Python C/C++ C# Java JavaScript TypeScript Threat Modeling SARIF Software Composition Analysis Secure Development Lifecycle
6+ yrs exp Remote

Principal Security Research Manager

Microsoft

Remote 67 days ago $165,600–$296,400
Vulnerability Research Application Security Python C/C++ C# Java JavaScript TypeScript Dynamic Analysis Fuzzing Symbolic Execution Taint Analysis Exploit Development AI Agents Threat Modeling Anomaly Detection Cryptography
8+ yrs exp Remote

Security Researcher

Microsoft

9 days ago $102,100–$202,200
Vulnerability Research Offensive Security Exploit Development Reverse Engineering AI Threat Analysis Anomaly Detection Software Development Lifecycle Large-scale Computing Capture The Flag (CTF)
2+ yrs exp Hybrid

Security Researcher

Microsoft

66 days ago $102,100–$202,200
AI Red Teaming Adversarial Machine Learning Generative AI Penetration Testing Python C# C/C++ PowerShell Kali Linux Burpsuite Nmap Nessus Vulnerability Research Anomaly Detection Threat Analysis Software Development Lifecycle Statistics Predictive Analytics
2+ yrs exp Hybrid

Senior Security Researcher

Microsoft

11 days ago $119,800–$234,700
Vulnerability Research Offensive Security Exploit Development Reverse Engineering AI Threat Analysis Anomaly Detection Software Development Lifecycle Cybersecurity Capture The Flag (CTF)
4+ yrs exp Hybrid