Staff Security Researcher

GitLab

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
CanadaIsraelUnited Kingdom
Salary
$168,000–$238,000 / yr
Posted
36 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $184k
This role $203k
$124k $250k
below market most similar roles pay here above market

This role pays more than 69% of similar roles. Most pay $151,475–$216,065 — the blue band above. At the midpoint, this role pays about $203k versus about $184k for comparable roles.

Based on 240 similar postings.

Employer

About GitLab

GitLab is an all-remote software company that develops an AI-powered DevSecOps platform combining source code management, CI/CD, security scanning, and project planning in a single application.

GitLab currently has 53 open roles on FindRole.

Listed pay typically runs $152,800–$235,600 across 47 roles with salary data.

Most-posted roles

View all roles at GitLab

At a glance

TL;DR · Staff Security Researcher

The Staff Security Researcher joins the Application Security team to conduct cutting-edge security research on AI-powered DevSecOps capabilities. This role involves identifying systemic vulnerabilities, developing proof-of-concept exploits, and creating novel testing methodologies for AI agents. You will perform hands-on penetration testing, assess emerging vulnerability classes, and build automation tools for agent-assisted discovery across the codebase. Key responsibilities include researching AI attack vectors like prompt injection and agent manipulation, auditing open source dependencies, and mentoring other contributors. Candidates must demonstrate proficiency in Ruby, Go, Python, TypeScript, or Rust, with experience in AI frameworks being an asset. The work focuses on securing the GitLab DevSecOps platform, Duo Agent Platform, and GitLab Duo Chat, ensuring the integrity of human and AI collaborative development workflows.

What you'll do

  • Conduct security research in two or more specialty areas to identify novel and systemic vulnerabilities.
  • Validate vulnerabilities through hands-on testing and develop proof-of-concept exploits for real-world attack scenarios.
  • Research AI and agentic surfaces to define security requirements for engineering teams.
  • Build tooling and automation to scale security research and agent-assisted vulnerability discovery.
  • Assess emerging industry vulnerability classes against the codebase and drive systemic remediation.
  • Research the security posture of open source tools and report findings to maintainers.
  • Provide actionable feedback to engineering teams and mentor other individual contributors.
  • Share knowledge and novel vulnerability types with the broader security community.

What we're looking for

  • 7+ years of experience in security research, penetration testing, or offensive security roles.
  • Hands-on experience discovering and exploiting vulnerabilities.
  • Subject matter expertise in at least two technical areas impacting product security.
  • Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust.
  • Ability to read and analyze code across multiple languages and codebases.
  • Understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation.
  • Experience leading technical objectives in cross-functional teams.
  • Excellent written communication skills to articulate complex topics and risk assessments.
  • Published security research or conference presentations (preferred).
  • Background in software engineering with distributed systems expertise (preferred).
  • Security certifications such as OSCP, OSCE, GPEN, or similar (preferred).
  • Experience with GitLab or similar DevSecOps platforms (preferred).

More like this

Similar roles

Principal Security Researcher

GitLab

Remote (Canada) +2 36 days ago $203,200–$275,000
DevSecOps AI Security Penetration Testing Ruby Go Python TypeScript Rust AI Frameworks Distributed Systems GitLab Prompt Injection Agent Manipulation Security Research
10+ yrs exp Remote

Security Researcher

Microsoft

65 days ago $102,100–$202,200
AI Red Teaming Adversarial Machine Learning Generative AI Penetration Testing Python C# C/C++ PowerShell Kali Linux Burpsuite Nmap Nessus Vulnerability Research Anomaly Detection Threat Analysis Software Development Lifecycle Statistics Predictive Analytics
2+ yrs exp Hybrid

Security Researcher

Microsoft

8 days ago $102,100–$202,200
Vulnerability Research Offensive Security Exploit Development Reverse Engineering AI Threat Analysis Anomaly Detection Software Development Lifecycle Large-scale Computing Capture The Flag (CTF)
2+ yrs exp Hybrid

Senior Security Researcher

Microsoft

10 days ago $119,800–$234,700
Vulnerability Research Offensive Security Exploit Development Reverse Engineering AI Threat Analysis Anomaly Detection Software Development Lifecycle Cybersecurity Capture The Flag (CTF)
4+ yrs exp Hybrid

Principal Security Researcher

Microsoft

Remote 67 days ago $142,800–$274,800
Vulnerability Research AI Agents Large Language Models Fuzzing Static Analysis Dynamic Analysis Reverse Engineering Symbolic Execution Taint Analysis Exploit Development Python C/C++ C# Java JavaScript TypeScript Threat Modeling SARIF Software Composition Analysis Secure Development Lifecycle
6+ yrs exp Remote

Staff Security Engineer

Uber

San Francisco, CA +2 17 days ago
Offensive Security Penetration Testing Threat Modeling AI LLMs Microservices APIs Distributed Systems Security Design Review Automation Secure Software Development Lifecycle Device Attestation
7+ yrs exp Hybrid