
Overview
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, reduce security risk, and accelerate digital transformation. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab.
As a Staff Backend Engineer on GitLab's Security Factory: Code Scanning team, you will help developers find and fix security vulnerabilities directly in the code they write, setting the technical direction for the static analysis engine that discovers them.
Your work spans two complementary parts of complete security analysis:
- Engine Side: Shaping how the static analysis toolkit models programs (parsing source into intermediate representations, resolving symbols, building call graphs, and tracking tainted data across files and languages). You define the architecture and delegate specifications to engineers and AI agents.
- Evaluation Side: Building and applying tooling to test, measure, and validate engine findings against benchmark applications with known vulnerabilities.
What You'll Do
- Act as the directly responsible individual (DRI) for high-scope initiatives from design through delivery, shipping major features with minimal guidance.
- Own the architecture of the program model (parsing, symbol resolution, intermediate representations, call graphs, taint and data-flow analysis) and define how it extends to new languages and frameworks.
- Set technical direction for AI-assisted tooling that implements, reviews, and validates engine changes, designing automated checks for agent-written code to ensure merge-readiness.
- Build and maintain the harness, instructions, and agentic workflows that keep AI-generated code trustworthy (coding vs. reviewing agents, CI gates, independent evaluation panels).
- Shepherd systems from single-engineer prototypes to team-wide ownership via thorough documentation, testing, and shared reviews.
- Solve complex technical problems across quality, security, and performance in collaboration with Product Management, UX, and partner teams.
- Mentor engineers through paired programming and code reviews, continuously raising the team's engineering standards.
- Participate in on-call rotations to support product operations and resolve urgent engineering and security issues.
- Keep abreast of academic and industry research in program analysis, driving spikes, prototypes, and upstream contributions.
What You Bring
- Extensive professional experience writing, testing, and reviewing production code in Rust, Go, or comparable systems languages (the engine is built in Rust, analyzer wrappers in Go, and monolith integration in Ruby).
- Deep background in program analysis and static analysis: AST parsing, intermediate representations (SSA, control-flow, call graphs), taint/data-flow analysis, type inference, or detection rule authoring.
- Strong application security foundation: vulnerability research, secure code reviews, and deep familiarity with OWASP Top 10 and CWE.
- Practical experience building custom LLM tooling, agent pipelines, or evaluation harnesses, paired with rigorous judgment on output validity.
- Experience with performance optimization, containerized workflows, and CI/CD pipelines (Docker).
- Proven ability to write clear architectural specifications, lead cross-functional decisions, and guide initiatives to completion asynchronously.
- A history of technical mentorship and raising engineering standards across teams.
Helpful Experience
- Familiarity with modern web or mobile frameworks and how they handle input, state, and configuration.
- Experience designing guardrails for agent-written code (mutation testing, fuzzing, immutable CI checks).
- Engagement with the research community via publications, tool papers, or open-source security analysis tooling.
Timezone overlap
UTC-8β+4
Culture
Async-friendly
Benefits
Equity, ESPP, Health, PTO, Learning, Parental leave, Commission, Wellness
Open to
NA Β· UK Β· MENA
Sign in to track applications and earn points.