Senior Software Engineer, Security Factory: Code Security
Remote
- Posted 3h ago
- From GitLab’s careers page
- Work mode
- Remote
- Level
- Senior
- Department
- Software Development
Opens the listing on job-boards.greenhouse.io
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
An overview of this role:
As a Senior Backend Engineer on GitLab's Security Factory: Code Security team, you help developers find and fix security issues. Those issues live in the code they write and in the open source components they depend on.
Your work spans complementary parts of a complete security analysis. On the dependency analysis side, you teach the analysis engine what a project depends on. You parse dependency manifests, lockfiles, and SBOMs so the engine knows which libraries and frameworks are in play and how the code uses them. You also extend the service that turns security advisories into automated merge requests that update vulnerable dependencies. On the vulnerability detection side, you grow GitLab's security analysis engine with hybrid analyzers that blend rule-based detection and AI reasoning. You build and apply the tooling that develops, evaluates, and ships those analyzers, and you measure how well they find real problems. That work also expands coverage of the libraries, frameworks, and AI agent tooling that real-world applications are built on.
These threads reinforce each other. What a project depends on, and how its code uses those dependencies, are parts of one picture, and this team works across all of it. We make thoughtful use of AI-assisted development tools in our daily work. We expect you to use them effectively and with good judgment.
What you do:
- Act as the directly responsible individual (DRI) for team initiatives from design through delivery, shipping with minimal guidance in partnership with the technical lead
- Bring systems built by one engineer to team ownership through documentation, tests, and shared review
- Design and ship analyzers that pair deterministic analysis capabilities with AI-driven analysis, and build the evaluation harnesses that measure their false positives and missed findings against benchmark applications with known vulnerabilities, raising the bar for what counts as a trustworthy result. That includes detection rules mapped to CWE and the test fixtures that prove they work.
- Package those analyzers for every place GitLab runs them, including CI jobs, AI agent workflows, and command-line tools, with findings reported in GitLab's standard security report formats
- Design and ship the manifest, lockfile, and SBOM parsing that tells the static analysis engine what a project depends on, and extend it to new ecosystems and formats
- Ship features across the automated remediation service that turns security advisories into dependency update merge requests, from sandboxed updates to merge request creation
- Solve technical problems of high scope and complexity, actively seek out difficult impediments affecting the whole team, and advocate for improvements to quality, security, and performance with Product Management, Engineering stakeholders such as Frontend and UX, and partner teams such as Code Scanning and Composition Analysis
- Mentor Intermediate engineers through code review and pairing, and maintain our internal standards for style, maintainability, and best practices through review
- Participate in on-call rotations to assist troubleshooting product operations, security operations, and urgent engineering issues
What you bring:
- Experience building your own LLM tooling, such as a harness, an agent pipeline, or evaluations, with the judgment to know when output is trustworthy and when it isn't
- Substantial professional experience writing and testing production code in a systems language, particularly Go and/or Rust, with depth in at least one. We use both, plus Ruby on the remediation side and Python for some analyzers, and value willingness to work across them.
- Familiarity with package managers and dependency management in one or more language ecosystems, such as npm, Maven, pip, Bundler, or Cargo. Experience building tooling around them is better still.
- Demonstrated application security experience, such as vulnerability research, secure code review, or writing detection rules, and fluency with vulnerability classes (OWASP Top 10, CWE) and the software supply chain
- A track record of taking ownership of ambiguous problems and shipping with minimal guidance, with the self-motivation and organizational skills suited to a remote, largely asynchronous environment
- Demonstrated capacity to communicate clearly and concisely about technical problems, and to write design proposals that bring a team to a decision
Helpful experience:
- Experience evaluating AI-driven detection against labeled data, including measuring false positives and missed findings
- Experience with performance optimization at scale
- Hands-on program analysis experience, such as parsing, ASTs, or data-flow analysis
- Familiarity with popular web or mobile application frameworks and how they handle input, data, and configuration
- Experience with containerized workflows and CI/CD (we use Docker heavily)
About the team:
The Security Factory: Code Security team builds GitLab's code-level security scanning capabilities, spanning static application security testing and dependency scanning. We help developers find and fix security issues in both the code they write and the open source components they depend on, as early as possible.
We work closely with the Static Analysis team on GitLab's SAST engines, with Composition Analysis on the broader software supply chain, and with other groups across the Sec Section. We rely heavily on asynchronous work across time zones.
United States Salary Range:
$139,200 - $235,200 USD. The base salary range for this role's listed level is currently for residents of the United States only. The range does not include bonuses, equity, or benefits.
How GitLab Supports Full-Time Employees:
- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. If you're excited about this role, please apply and allow our recruiters to assess your application.
Country Hiring Guidelines:
GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.
Equal Opportunity:
GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab's policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex, national origin, age, citizenship, marital status, disability, genetic information, veteran status, or any other basis protected by law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.
Skills they ask for
Pick one to see other roles that ask for it.
About GitLab
One platform for software development and deliveryGitLab provides a software development platform covering source control, CI/CD, security, and AI-assisted software workflows.
See all 94 roles at GitLabMore roles at GitLab
See all 94- People Systems EngineerBengaluru · RemoteInformation Technology · RemoteBengaluru, India7h
- People Technology Analyst - WorkdayUnited States · RemoteHuman Resources · RemoteUnited States7h
- Lead Legal Counsel, CorporateUnited States · Lead · RemoteLegal and Compliance · Lead · RemoteUnited States8h
- Benefits AnalystBengaluru · HybridHuman Resources · HybridBengaluru, India13h
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.