跳到主要内容
OOfficialJobs
菜单
官方来源官方来源职位

首席安全研究员

机器翻译
查看雇主原标题Principal Security Researcher

GitLab · Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, 美国 · base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary ra

职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。

为什么值得关注?

发现指数 54/100,仅依据与该职位一起存储的证据计算。

54/100 发现指数
  • 新的雇主官方职位
  • 远程职位

分数构成

  • 时效性 (随职位发布时间变化)+18
  • 雇主官方来源+15
  • 远程职位+8
  • 稀有职位+5
  • 公司来源健康度+8

该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。

这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。

职位描述

机器翻译

GitLab 是面向 DevSecOps 的智能编排平台。GitLab 帮助组织提升开发者生产力、改善运营效率、降低安全与合规风险,并加速数字化转型。超过 5000 万注册用户以及超过 50% 的《财富》100 强*企业信赖 GitLab,以更快交付更优质、更安全的软件。

我们产品中内置的相同原则也体现在我们团队的工作方式中:我们将 AI 视为核心生产力倍增器,所有团队成员都应把 AI 融入日常工作流程,以推动效率、创新和影响力。GitLab 是职业加速发展、创新蓬勃生长、每一个声音都被重视的地方。我们的高绩效文化由我们的价值观和持续的知识交流驱动,使我们的团队成员能够充分发挥潜力,同时与行业领袖协作解决复杂问题。与我们一起共创未来,打造改变世界软件开发方式的技术。

* Fortune 500® 是 Fortune Media IP Limited 的注册商标,经许可使用。该声明基于 GitLab 数据。Fortune 100 指 2025 年 6 月发布的 2025 年 Fortune 500 榜单中排名前 20% 的公司。Fortune 和 Fortune Media IP Limited 与 GitLab 无关联,也不为 GitLab 的产品或服务背书。

职位概述

我们正在寻找一位首席安全研究员加入我们的应用安全团队,针对 GitLab 由 AI 驱动的 DevSecOps 能力开展前沿安全研究。随着 GitLab 通过开发者和专用 AI 代理之间的智能协作来变革软件开发,我们需要能够在漏洞影响我们的平台或客户之前主动识别并验证漏洞的安全研究员。

在这个职位上,你将站在安全研究的前沿,与我们的 GitLab DevSecOps 平台、Duo Agent Platform、GitLab Duo Chat 以及代表人机协作开发未来的 AI 工作流打交道。你将开发新颖的测试方法(包括针对 AI 代理安全的方法),开展实操渗透测试,并将新兴威胁转化为可执行的安全改进。你的研究将直接影响我们如何构建并保护下一代 AI 驱动的 DevSecOps 工具,确保 GitLab 始终是市场上最安全的软件工厂平台。

该职位提供独特的机会,让你在全球最大的 DevSecOps 平台之一中塑造安全和 AI 安全实践,并与正在推动 AI 辅助软件开发边界的工程团队合作。你将能够使用前沿 AI 系统,并拥有探索创造性攻击场景的自由,同时为全球数百万开发者的安全作出贡献。

该职位向应用安全高级经理汇报。

岗位职责

• 开展并领导跨多个职能领域的安全研究项目。

• 识别 GitLab 中新颖的、系统性的和链式漏洞,即单个弱点组合后产生超常影响的情况。

• 通过实操测试验证安全漏洞,开发概念验证漏洞利用,以展示真实世界的攻击场景。

• 针对 GitLab 代码库评估新兴行业漏洞类别,并推动修复整个类别,而非单个实例。

• 领导针对 GitLab 的 AI 和代理界面的安全研究,并定义工程团队据此构建的安全要求。

• 构建并指导可扩展安全研究的工具和自动化,包括在我们的代码库中进行代理辅助的漏洞发现。

• 研究与 GitLab 集成的开源工具和依赖项的安全态势,按照我们的负责任披露指南向其维护者报告发现,并跟踪缓解情况。

• 解决最高范围、复杂性和模糊性的技术问题。

• 帮助塑造团队和子部门路线图。

• 领导将安全研究成果整合到需要据此采取行动的工程和业务职能中。

• 教导、指导并建议其他领域专家以及多个团队中的个人贡献者。

• 与安全社区分享知识和新型漏洞类型。

你将带来

• 10 年以上安全研究、渗透测试或进攻性安全岗位经验

• 在大型代码库和复杂系统中发现并利用漏洞的强大能力

• 熟练掌握 Ruby、Go、Python、TypeScript 或 Rust 中的两种或更多。

• 能够阅读并分析多种语言和代码库中的代码

• 对 AI 框架有深入了解

• 对 AI 攻击向量有深入理解,包括提示注入、代理操纵和工作流利用

• 能够自如地建立并推动涉及跨职能团队的复杂修复计划

• 出色的书面沟通能力,能够清晰简洁地阐述复杂主题。

• 能够将复杂的技术发现转化为清晰的风险评估和修复建议

• 强大的分析和问题解决能力,并能创造性地思考攻击场景

• 加分项:已发表的安全研究或会议演讲;具备软件工程背景并拥有分布式系统专业知识;有 GitLab 或类似 DevSecOps 平台经验

福利待遇

• 灵活带薪休假

• 团队成员资源小组

• 股权薪酬与员工购股计划

• 成长与发展基金

• 育儿假

请注意,我们欢迎具有不同经验水平的候选人表达兴趣;许多成功候选人并不满足每一项要求。此外,研究表明,来自代表性不足群体的人除非满足每一项资格要求,否则不太可能申请工作。如果你对这个职位感到兴奋,请申请,并让我们的招聘人员评估你的申请。

国家招聘指南:GitLab 在世界各国招聘新团队成员。我们的所有职位均为远程职位,但某些职位可能有特定的基于地点的资格要求。我们的招聘团队可以在启动招聘流程后帮助回答有关地点的任何问题。

隐私政策:请查看我们的招聘隐私政策。你的隐私对我们很重要。

GitLab 自豪地成为提供平等机会的工作场所,并且是采取平权行动的雇主。GitLab 与招聘、雇佣、职业发展和晋升、升职以及退休相关的政策和实践完全基于绩效,不论种族、肤色、宗教、血统、性别(包括怀孕、哺乳、性取向、性别认同或性别表达)、民族出身、年龄、公民身份、婚姻状况、精神或身体残疾、遗传信息(包括家族病史)、退伍状态、受保护退伍军人身份(包括残疾退伍军人、近期退伍军人、战时或战役徽章现役退伍军人以及武装部队服务奖章退伍军人),或任何其他受法律保护的基础。GitLab 不会容忍基于任何这些特征的歧视或骚扰。另请参阅 GitLab 的 EEO 政策以及 EEO is the Law。如果你有残疾或特殊需要而需要便利安排,请在招聘流程中告知我们。

以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。

查看雇主原文

职位描述

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.

The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software.

* Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.

An overview of the role

We are seeking a Principal Security Researcher to join our Application Security Team to conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities. As GitLab transforms software development through intelligent collaboration between developers and specialized AI agents, we need security researchers who can proactively identify and validate vulnerabilities before they impact our platform or customers.

In this role, you'll be at the forefront of security research, working with our GitLab DevSecOps platform, Duo Agent Platform, GitLab Duo Chat, and AI workflows that represent the future of human/AI collaborative development. You'll develop novel testing methodologies (including for AI agent security), conduct hands-on penetration testing, and translate emerging threats into actionable security improvements. Your research will directly influence how we build and secure the next generation of AI-powered DevSecOps tools, ensuring GitLab remains the most secure software factory platform on the market.

This position offers the unique opportunity to shape security and AI security practices in one of the world's largest DevSecOps platforms, working with engineering teams who are pushing the boundaries of what's possible with AI-assisted software development. You'll have access to cutting-edge AI systems and the freedom to explore creative attack scenarios while contributing to the security of millions of developers worldwide.

This role reports to the Senior Manager of Application Security.

岗位职责

• Conduct and lead security research projects across multiple functional areas.

• Identify novel, systemic, and chained vulnerabilities in GitLab, where individual weaknesses combine for outsized impact.

• Validate security vulnerabilities through hands-on testing, developing proof-of-concept exploits that demonstrate real-world attack scenarios.

• Assess emerging industry vulnerability classes against the GitLab codebase, and drive remediation of the class rather than the instance.

• Lead security research into GitLab's AI and agentic surfaces, and define the security requirements that engineering teams build against.

• Build and direct the tooling and automation that scales security research, including agent-assisted vulnerability discovery across our codebase.

• Research the security posture of open source tools and dependencies integrated with GitLab, report findings to their maintainers, and track mitigation following our responsible disclosure guidelines .

• Solve technical problems of the highest scope, complexity, and ambiguity.

• Help shape the team and sub-department roadmap.

• Lead the integration of security research results into the engineering and business functions that need to act on them.

• Teach, mentor, and advise other domain experts and individual contributors across several teams.

• Share knowledge and novel vulnerability types with the security community.

What you'll bring

• 10+ years of experience in security research, penetration testing, or offensive security roles

• Strong ability in discovering and exploiting vulnerabilities in large codebase and complex systems

• Proficiency in two or more of Ruby, Go, Python, TypeScript, or Rust.

• Ability to read and analyze code across multiple languages and codebases

• Strong knowledge of AI frameworks

• Strong understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation

• At ease in establishing and driving complex remediation initiatives involving cross-functional teams

• Excellent written communication skills with an ability to articulate complex topics in a clear and concise manner.

• Ability to translate complex technical findings into clear risk assessments and remediation recommendations

• Strong analytical and problem-solving skills with creative thinking about attack scenarios

• Nice to Have: Published security research or conference presentations; background in software engineering with distributed systems expertise; experience with GitLab or similar DevSecOps platforms

福利待遇

• Flexible Paid Time Off

• Team Member Resource Groups

• Equity Compensation & Employee Stock Purchase Plan

• Growth and Development Fund

• Parental Leave

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.

Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.

Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us.

GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law . If you have a disability or special need that requires accommodation , please let us know during the recruiting process .

GitLab 的更多职位

公司主页
远程远程全职未披露薪资
英文原文

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, a…

未出现在监控的职位板上
首次发现于8小时前
已核实19分钟前
官方来源最新
Remote, 日本远程全职未披露薪资
英文原文

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, a…

未出现在监控的职位板上
首次发现于8小时前
已核实19分钟前

中级技术项目经理

GitLab · Office of the CTO

官方来源最新
Bangalore, 印度全职未披露薪资
英文原文

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, a…

未出现在监控的职位板上
首次发现于8小时前
已核实19分钟前
官方来源最新
Remote, Canada; Remote, 美国远程合同制未披露薪资
英文原文

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, a…

未出现在监控的职位板上
首次发现于8小时前
已核实19分钟前

其他公司的相似职位

搜索这类职位
Mexico - Mexico City全职未披露薪资
英文原文

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts. Job Category Sales Job Details About Sal…

官方来源职位
首次发现于15分钟前
已核实15分钟前

Principal Customer Engineer, Majors原文

Cloudflare · Solution Engineering

官方来源最新
Distributed全职€148k – €204k
英文原文

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet propertie…

官方来源职位
首次发现于18分钟前
已核实18分钟前
官方来源最新
Distributed全职€148k – €204k
英文原文

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet propertie…

官方来源职位
首次发现于18分钟前
已核实18分钟前
Long Beach, CA全职Base salary is just one component of our total rewards package at Rocket Lab. Employees may also receive company equity and access to a robust benefits package
英文原文

ABOUT ROCKET LAB Rocket Lab is the end-to-end space company building rockets, spacecraft, and critical subsystems that keep the world connected, protected, expand humanity’s reach to the Moon, Mar…

未出现在监控的职位板上
首次发现于前天
已核实17分钟前