GitLab logo
GitLabΒ·Verified

Senior Software Engineer, Security Factory: Code Security - GitLab

Fully remoteFull-timeSenior$139K - $235KUTC-8–-4AsyncAmericas#Go#Rust#securityEquityESPPPTOParental leaveLearningCommissionWellness

About GitLab

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100 trust GitLab to ship better, more secure software faster.

We embrace AI as a core productivity multiplier, with team members incorporating AI into daily workflows to drive efficiency, innovation, and impact. GitLab offers a high-performance culture driven by our values and continuous knowledge exchange.

Overview of the Role

As a Senior Backend Engineer on GitLab's Security Factory: Code Security team, you help developers find and fix security issues within their code and open source dependencies.

Your work covers complementary parts of comprehensive security analysis:

  • Dependency Analysis: Teach the analysis engine project dependencies by parsing manifests, lockfiles, and SBOMs. Extend the service converting security advisories into automated merge requests that update vulnerable dependencies.
  • Vulnerability Detection: Expand GitLab's security analysis engine with hybrid analyzers combining rule-based detection and AI reasoning. Build and apply tooling to develop, evaluate, and ship analyzers, measuring efficacy against benchmark applications with known vulnerabilities.

What You'll Do

  • Act as the directly responsible individual (DRI) for team initiatives from design through delivery, shipping with minimal guidance.
  • Transition systems built by individual engineers into team ownership through documentation, tests, and shared reviews.
  • Design and ship analyzers pairing deterministic analysis with AI-driven analysis, building evaluation harnesses to measure false positives and missed findings mapped to CWE.
  • Package analyzers for execution in CI jobs, AI agent workflows, and command-line tools using standard GitLab security report formats.
  • Design and ship manifest, lockfile, and SBOM parsing to expand static analysis engine support across ecosystems.
  • Implement features across automated remediation services converting advisories into dependency update merge requests.
  • Solve complex technical problems, advocate for quality and security improvements, and collaborate with Product Management, Frontend, UX, Code Scanning, and Composition Analysis teams.
  • Mentor Intermediate engineers through code review and pairing.
  • Participate in on-call rotations for product operations, security operations, and urgent engineering issues.

What You Bring

  • Experience building custom LLM tooling (such as harnesses, agent pipelines, or evaluation frameworks) with sound judgment on output reliability.
  • Substantial professional experience writing and testing production systems code, particularly in Go and/or Rust, with depth in at least one. Willingness to work across Ruby and Python as needed.
  • Familiarity with package managers and dependency ecosystems (such as npm, Maven, pip, Bundler, or Cargo); tooling experience is a plus.
  • Demonstrated application security experience (vulnerability research, secure code review, rule writing) and fluency with OWASP Top 10, CWE, and software supply chain security.
  • Proven track record of taking ownership of ambiguous problems and shipping in an asynchronous remote environment.
  • Clear, concise technical communication and experience writing design proposals.

Helpful Experience

  • Evaluating AI-driven detection against labeled datasets.
  • Large-scale performance optimization.
  • Program analysis fundamentals (parsing, ASTs, data-flow analysis).
  • Popular web or mobile framework security models.
  • Containerized workflows and CI/CD (Docker).

Benefits & Compensation

  • Equity Compensation & Employee Stock Purchase Plan (ESPP)
  • Flexible Paid Time Off
  • Parental Leave
  • Growth and Development Fund
  • Comprehensive health and financial benefits

Timezone overlap

UTC-8–-4

Culture

Async-friendly

Open to

NA

Sign in to track applications and earn points.

More roles at GitLab

Similar remote roles