[Hiring] Staff Security Researcher REMOTE USA

Position: Staff Security Researcher

Date Posted: September 6, 2026

Industry: Cybersecurity | Software Engineering | Artificial Intelligence

Employment Type: Full Time

Experience: 7+ years of experience in security research, penetration testing, or offensive security roles

Qualification: Not Specified

Salary: $168,000 – $238,000 per year

Location: REMOTE, United States

Company: GitLab

Description:

GitLab is seeking a Staff Security Researcher to join its Application Security Team and conduct advanced security research across GitLab’s AI-powered DevSecOps platform. This role focuses on identifying vulnerabilities, improving security practices, and protecting next-generation AI-driven software development tools.

The successful candidate will work on security research, penetration testing, AI security challenges, and vulnerability discovery while collaborating with engineering teams. This position offers the opportunity to influence security strategies for a platform trusted by millions of developers worldwide.

Key Responsibilities:

• Conduct security research across multiple technical specialty areas.

• Identify complex vulnerabilities and chained security issues within GitLab products.

• Validate vulnerabilities through hands-on testing and proof-of-concept exploit development.

• Research emerging vulnerability classes and drive effective remediation strategies.

• Conduct security research on AI systems, agent platforms, and AI-powered workflows.

• Build security research tools and automation for vulnerability discovery.

• Assess security risks in open-source tools and dependencies integrated with GitLab.

• Solve complex technical security challenges and improve security processes.

• Provide actionable security feedback to engineering teams.

• Mentor other security professionals and share research knowledge with the security community.

Requirements:

• 7+ years of experience in security research, penetration testing, or offensive security roles.

• Hands-on experience discovering and exploiting vulnerabilities.

• Expertise in at least two technical security areas impacting product security.

• Ability to analyze code across multiple programming languages and codebases.

• Experience leading technical initiatives within cross-functional teams.

• Excellent written communication skills with the ability to explain complex security topics.

• Strong analytical and problem-solving skills with creative attack scenario thinking.

Strong knowledge of:

• Security research, penetration testing, and vulnerability assessment.

• AI security concepts including prompt injection, agent manipulation, and workflow exploitation.

• Programming languages such as Ruby, Go, Python, TypeScript, or Rust.

• AI frameworks, DevSecOps platforms, and application security practices.

• Security certifications such as OSCP, OSCE, GPEN, or similar are an advantage.

Disclaimer: The job details above are structured for clarity and based on publicly available content from recruiters/Company pages. All rights remain with the original source; names may be withheld for confidentiality. We are not involved in the hiring process.