Principal Security Researcher

Principal Security Researcher

Full-Time 80100 - 97900 £ / year (est.) Remote
G

At a Glance

  • Tasks: Lead cutting-edge security research and identify vulnerabilities in GitLab's AI-powered DevSecOps platform.
  • Company: Join GitLab, a trusted leader in software development with over 50 million users.
  • Benefits: Enjoy flexible paid time off, equity compensation, and a growth fund for your professional development.
  • Other info: Collaborate with industry leaders in a remote-first environment that values every voice.
  • Why this job: Shape the future of security in AI-driven software development and make a real impact.
  • Qualifications: 10+ years in security research, strong coding skills, and knowledge of AI attack vectors.

The predicted salary is between 80100 - 97900 £ per year.

Git Lab is the intelligent orchestration platform for Dev Sec Ops.

Git Lab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation.

More than 50 million registered users and more than 50% of the Fortune 100* trust Git Lab to ship better, more secure software faster.

The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact.

Git Lab is where careers accelerate, innovation flourishes, and every voice is valued.

Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems.

Co-create the future with us as we build technology that transforms how the world develops software.

  • Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license.

Claim based on Git Lab data.

Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025.

Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of Git Lab.

An Overview Of The Role

We are seeking a Principal Security Researcher to join our Application Security Team to conduct cutting-edge security research on Git Lab's AI-powered Dev Sec Ops capabilities.

As Git Lab transforms software development through intelligent collaboration between developers and specialized AI agents, we need security researchers who can proactively identify and validate vulnerabilities before they impact our platform or customers.

In this role, you'll be at the forefront of security research, working with our Git Lab Dev Sec Ops platform, Duo Agent Platform, Git Lab Duo Chat, and AI workflows that represent the future of human/AI collaborative development.

You'll develop novel testing methodologies (including for AI agent security), conduct hands-on penetration testing, and translate emerging threats into actionable security improvements.

Your research will directly influence how we build and secure the next generation of AI-powered Dev Sec Ops tools, ensuring Git Lab remains the most secure software factory platform on the market.

This position offers the unique opportunity to shape security and AI security practices in one of the world's largest Dev Sec Ops platforms, working with engineering teams who are pushing the boundaries of what's possible with AI-assisted software development.

You'll have access to cutting-edge AI systems and the freedom to explore creative attack scenarios while contributing to the security of millions of developers worldwide.

This role reports to the Senior Manager of Application Security.

What You'll Do

  • Conduct and lead security research projects across multiple functional areas.
  • Identify novel, systemic, and chained vulnerabilities in Git Lab, where individual weaknesses combine for outsized impact.
  • Validate security vulnerabilities through hands-on testing, developing proof-of-concept exploits that demonstrate real-world attack scenarios.
  • Assess emerging industry vulnerability classes against the Git Lab codebase, and drive remediation of the class rather than the instance.
  • Lead security research into Git Lab's AI and agentic surfaces, and define the security requirements that engineering teams build against.
  • Build and direct the tooling and automation that scales security research, including agent-assisted vulnerability discovery across our codebase.
  • Research the security posture of open source tools and dependencies integrated with Git Lab, report findings to their maintainers, and track mitigation following our responsible disclosure guidelines.
  • Solve technical problems of the highest scope, complexity, and ambiguity.
  • Help shape the team and sub-department roadmap.
  • Lead the integration of security research results into the engineering and business functions that need to act on them.
  • Teach, mentor, and advise other domain experts and individual contributors across several teams.
  • Share knowledge and novel vulnerability types with the security community.
  • What You'll Bring
  • 10+ years of experience in security research, penetration testing, or offensive security roles
  • Strong ability in discovering and exploiting vulnerabilities in large codebase and complex systems
  • Proficiency in two or more of Ruby, Go, Python, Type Script, or Rust.
  • Ability to read and analyze code across multiple languages and codebases
  • Strong knowledge of AI frameworks
  • Strong understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation
  • At ease in establishing and driving complex remediation initiatives involving cross‑functional teams
  • Excellent written communication skills with an ability to articulate complex topics in a clear and concise manner.
  • Ability to translate complex technical findings into clear risk assessments and remediation recommendations
  • Strong analytical and problem‑solving skills with creative thinking about attack scenarios
  • Nice to

Have: Published security research or conference presentations; background in software engineering with distributed systems expertise; experience with Git Lab or similar Dev Sec Ops platforms

About The Team

Security Researchers are a part of our Application Security team, who address complex security challenges facing Git Lab and its customers to enable Git Lab to be the most secure software factory platform on the market.

We focus on systemic product security risks and work cross‑functionally to mitigate them while maintaining Engineering's development velocity.

The base salary range for this role's listed level is currently for residents of the United States only.

This range is intended to reflect the role's base salary rate in locations throughout the US.

Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location.

The base salary range does not include any bonuses, equity, or benefits.

See more information on our benefits and equity.

Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.

  • United States Salary Range
  • How Git Lab Supports Full-Time Employees
  • Benefits to support your health, finances, and well‑being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Country Hiring Guidelines

Git Lab hires new team members in countries around the world.

All of our roles are remote, however some roles may carry specific location-based eligibility requirements.

Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.

Privacy Policy

Please review our Recruitment Privacy Policy. Your privacy is important to us.

Git Lab is proud to be an equal opportunity workplace and is an affirmative action employer.

Git Lab's policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law.

Git Lab will not tolerate discrimination or harassment based on any of these characteristics.

See also Git Lab's EEO Policy and EEO is the Law.

If you have a disability or special need that requires accommodation, please let us know during the recruiting process.

#J-18808-Ljbffr

Principal Security Researcher employer: GitLab

GitLab is an exceptional employer that fosters a high-performance culture where innovation thrives and every team member's voice is valued. With a commitment to employee growth through flexible paid time off, equity compensation, and a dedicated development fund, GitLab empowers its employees to reach their full potential while working remotely in a collaborative environment. Join us in shaping the future of software security and enjoy the unique advantage of being part of a company trusted by over 50% of the Fortune 100.

G

Contact Details:

GitLab Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Principal Security Researcher

✨Join Local Tech Meetups

Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at GitLab or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!

✨Contribute to Open Source Projects

Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to GitLab.

✨Tap into Online Developer Communities

Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like GitLab.

✨Explore Job Boards Specifically for Tech Roles

Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like GitLab that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!

We think you need these skills to ace Principal Security Researcher

Security Research
Penetration Testing
Vulnerability Discovery
Ruby
Go
Python
TypeScript

Some tips for your application 🫡

Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.

Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at GitLab.

Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at GitLab and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!

Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!

How to prepare for a job interview at GitLab

✨Brush Up on Your Coding Skills

For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.

✨Know Your Tools and Frameworks

Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If GitLab uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.

✨Showcase Your Projects

Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.

✨Prepare for Behavioural Questions

While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.