跳到主要内容
OOfficialJobs
菜单
官方来源官方来源职位

资深安全研究员

机器翻译
查看雇主原标题Staff Security Researcher

GitLab · Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, 美国 · base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary ra

职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。

为什么值得关注?

发现指数 60/100,仅依据与该职位一起存储的证据计算。

60/100 发现指数
  • 新的雇主官方职位
  • 远程职位
  • 稀有职位匹配

分数构成

  • 时效性 (随职位发布时间变化)+18
  • 雇主官方来源+15
  • 远程职位+8
  • 稀有职位+11
  • 公司来源健康度+8

该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。

这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。

职位描述

机器翻译

GitLab 是面向 DevSecOps 的智能编排平台。GitLab 使组织能够提高开发者生产力、提升运营效率、降低安全与合规风险,并加速数字化转型。超过 5000 万注册用户以及超过 50% 的《财富》100 强*企业信任 GitLab,以更快地交付更好、更安全的软件。

我们产品中内置的相同原则也体现在我们团队的工作方式中:我们将 AI 视为核心生产力倍增器,所有团队成员都应把 AI 融入日常工作流程,以推动效率、创新和影响力。GitLab 是职业加速发展、创新蓬勃生长、每一个声音都被重视的地方。我们的高绩效文化由我们的价值观和持续的知识交流驱动,使我们的团队成员能够充分发挥潜力,同时与行业领导者协作解决复杂问题。与我们共同创造未来,因为我们正在构建改变世界开发软件方式的技术。

* Fortune 500® 是 Fortune Media IP Limited 的注册商标,经许可使用。该声明基于 GitLab 数据。Fortune 100 指 2025 年《财富》500 强榜单中排名前 20% 的公司,该榜单于 2025 年 6 月发布。Fortune 和 Fortune Media IP Limited 与 GitLab 无关联,也不为 GitLab 的产品或服务背书。

职位概述

我们正在寻找一名资深安全研究工程师加入我们的应用安全团队,针对 GitLab 由 AI 驱动的 DevSecOps 能力开展前沿安全研究。随着 GitLab 通过开发者和专用 AI 代理之间的智能协作来变革软件开发,我们需要能够在漏洞影响我们的平台或客户之前主动识别并验证漏洞的安全研究人员。

在这个职位中,你将站在安全研究的前沿,与我们的 GitLab DevSecOps 平台、Duo Agent Platform、GitLab Duo Chat 以及代表人机/AI 协作开发未来的 AI 工作流一起工作。你将开发新颖的测试方法(包括针对 AI 代理安全的方法),开展实操渗透测试,并将新兴威胁转化为可执行的安全改进。你的研究将直接影响我们如何构建并保护下一代 AI 驱动的 DevSecOps 工具,确保 GitLab 保持市场上最安全的软件工厂平台地位。

该职位提供了一个独特机会,帮助塑造全球最大 DevSecOps 平台之一的安全和 AI 安全实践,并与正在推动 AI 辅助软件开发边界的工程团队合作。你将能够接触前沿 AI 系统,并拥有探索创造性攻击场景的自由,同时为全球数百万开发者的安全作出贡献。

该职位汇报给应用安全高级经理

岗位职责

• 在两个或更多专业领域开展安全研究。

• 识别 GitLab 中新颖、系统性以及链式漏洞,其中单个弱点组合后会产生超乎寻常的影响。

• 通过实操测试验证安全漏洞,开发概念验证漏洞利用,以展示真实世界的攻击场景。

• 在你擅长的领域内,评估新兴行业漏洞类别对 GitLab 代码库的影响,并推动修复整个类别,而不是单个实例。

• 对 GitLab 的 AI 和代理界面开展安全研究,并参与定义工程团队据此构建的安全要求。

• 构建可扩展安全研究的工具和自动化,包括跨我们的代码库进行代理辅助漏洞发现。

• 研究集成到 GitLab 的开源工具和依赖项的安全态势,按照我们的负责任披露指南向其维护者报告发现,并跟踪缓解措施。

• 解决高范围、高复杂性和高模糊性的技术问题。

• 定义并实施安全技术和流程改进。

• 为团队路线图作出贡献。

• 向需要根据你的发现采取行动的工程团队提供可执行且建设性的反馈。

• 指导和建议团队内以及其他团队中的其他个人贡献者。

• 与安全社区分享知识和新型漏洞类型。

你将带来什么

• 7 年以上安全研究、渗透测试或进攻性安全岗位经验

• 发现并利用漏洞的实操经验。

• 成为至少两个影响产品安全的技术领域的主体事务专家(SME)。

• 精通 Ruby、Go、Python、TypeScript 或 Rust 中的一种或多种。具备 AI 框架经验者优先。

• 能够阅读并分析多种语言和代码库中的代码。

• 理解 AI 攻击向量,包括提示注入、代理操纵和工作流利用

任职要求

• 出色的书面沟通能力,能够以清晰简洁的方式阐述复杂主题。

• 能够将复杂技术发现转化为清晰的风险评估和修复建议

• 强大的分析和问题解决能力,并能创造性地思考攻击场景

• 加分项:已发表的安全研究或会议演讲;具备分布式系统专长的软件工程背景;OSCP、OSCE、GPEN 或类似安全认证;具备 GitLab 或类似 DevSecOps 平台经验

福利待遇

• 灵活带薪休假

• 团队成员资源小组

• 股权薪酬与员工购股计划

• 成长与发展基金

• 育儿假

请注意,我们欢迎具有不同经验水平的候选人表达兴趣;许多成功候选人并不满足每一项要求。此外,研究表明,来自代表性不足群体的人除非满足每一项资格要求,否则不太可能申请工作。如果你对这个职位感到兴奋,请申请,并让我们的招聘人员评估你的申请。

国家招聘指南:GitLab 在世界各国招聘新团队成员。我们的所有职位均为远程职位,但某些职位可能有特定的基于地点的资格要求。我们的招聘团队可以在开始招聘流程后帮助回答有关地点的任何问题。

隐私政策:请查看我们的招聘隐私政策。你的隐私对我们很重要。

GitLab 自豪地成为提供平等机会的工作场所,并且是采取平权行动的雇主。GitLab 与招聘、雇佣、职业发展和晋升、升职以及退休相关的政策和实践完全基于能力,不论种族、肤色、宗教、血统、性别(包括怀孕、哺乳、性取向、性别认同或性别表达)、国籍、年龄、公民身份、婚姻状况、精神或身体残疾、遗传信息(包括家族病史)、退伍状态、受保护退伍军人身份(包括残疾退伍军人、近期退伍军人、战时或战役徽章现役退伍军人以及武装部队服务奖章退伍军人),或任何其他受法律保护的基础。GitLab 不会容忍基于任何这些特征的歧视或骚扰。另请参阅 GitLab 的 EEO 政策和 EEO is the Law。如果你有残疾或需要便利的特殊需求,请在招聘流程中告知我们。

以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。

查看雇主原文

职位描述

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.

The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software.

* Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.

An overview of the role

We are seeking a Staff Security Research Engineer to join our Application Security Team to conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities. As GitLab transforms software development through intelligent collaboration between developers and specialized AI agents, we need security researchers who can proactively identify and validate vulnerabilities before they impact our platform or customers.

In this role, you'll be at the forefront of security research, working with our GitLab DevSecOps platform, Duo Agent Platform, GitLab Duo Chat, and AI workflows that represent the future of human/AI collaborative development. You'll develop novel testing methodologies (including for AI agent security), conduct hands-on penetration testing, and translate emerging threats into actionable security improvements. Your research will directly influence how we build and secure the next generation of AI-powered DevSecOps tools, ensuring GitLab remains the most secure software factory platform on the market.

This position offers the unique opportunity to help shape security and AI security practices in one of the world's largest DevSecOps platforms, working with engineering teams who are pushing the boundaries of what's possible with AI-assisted software development. You'll have access to cutting-edge AI systems and the freedom to explore creative attack scenarios while contributing to the security of millions of developers worldwide.

This role reports to the Senior Manager of Application Security

岗位职责

• Conduct security research in two or more specialty areas.

• Identify novel, systemic, and chained vulnerabilities in GitLab, where individual weaknesses combine for outsized impact.

• Validate security vulnerabilities through hands-on testing, developing proof-of-concept exploits that demonstrate real-world attack scenarios.

• Assess emerging industry vulnerability classes against the GitLab codebase in your areas of expertise, and drive remediation of the class rather than the instance.

• Conduct security research into GitLab's AI and agentic surfaces, and participate in defining the security requirements that engineering teams build against.

• Build the tooling and automation that scales security research, including agent-assisted vulnerability discovery across our codebase.

• Research the security posture of open source tools and dependencies integrated with GitLab, report findings to their maintainers, and track mitigation following our responsible disclosure guidelines .

• Solve technical problems of high scope, complexity, and ambiguity.

• Define and implement security technical and process improvements.

• Contribute to the team roadmap.

• Provide actionable and constructive feedback to the engineering teams that need to act on your findings.

• Mentor and advise other individual contributors within the team, and sometimes outside of it.

• Share knowledge and novel vulnerability types with the security community.

What you'll bring

• 7+ years of experience in security research, penetration testing, or offensive security roles

• Hands-on experience discovering and exploiting vulnerabilities.

• Be a subject matter expert (SME) of at least two technical areas impacting the security of the product.

• Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust. Experience in AI frameworks is an asset.

• Ability to read and analyze code across multiple languages and codebases.

• Understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation

任职要求

• Excellent written communication skills with an ability to articulate complex topics in a clear and concise manner.

• Ability to translate complex technical findings into clear risk assessments and remediation recommendations

• Strong analytical and problem-solving skills with creative thinking about attack scenarios

• Nice to have: Published security research or conference presentations; Background in software engineering with distributed systems expertise; Security certifications such as OSCP, OSCE, GPEN, or similar; Experience with GitLab or similar DevSecOps platforms

福利待遇

• Flexible Paid Time Off

• Team Member Resource Groups

• Equity Compensation & Employee Stock Purchase Plan

• Growth and Development Fund

• Parental Leave

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.

Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.

Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us.

GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law . If you have a disability or special need that requires accommodation , please let us know during the recruiting process .

GitLab 的更多职位

公司主页
远程远程全职未披露薪资
英文原文

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, a…

未出现在监控的职位板上
首次发现于14小时前
已核实6小时前
官方来源最新
Remote, 日本远程全职未披露薪资
英文原文

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, a…

未出现在监控的职位板上
首次发现于14小时前
已核实6小时前

中级技术项目经理

GitLab · Office of the CTO

官方来源最新
Bangalore, 印度全职未披露薪资
英文原文

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, a…

未出现在监控的职位板上
首次发现于14小时前
已核实6小时前
官方来源最新
Remote, Canada; Remote, 美国远程合同制未披露薪资
英文原文

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, a…

未出现在监控的职位板上
首次发现于14小时前
已核实6小时前