4 дня назад
Staff Security Researcher (AI Security)
168 000 - 238 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Security Researcher (AI Security): Conducting vulnerability research and penetration testing across GitLab's AI-powered DevSecOps platform, Duo Agent Platform, and AI workflows with an accent on agent security, systemic vulnerabilities, and scalable research automation. Focus on developing proof-of-concept exploits, analyzing prompt injection and workflow exploitation, and translating complex findings into remediation improvements.
Location: Remote in Canada, Israel, the United Kingdom, or the United States
Salary: $168,000–$238,000 USD annually for US residents
Company
provides an intelligent orchestration platform for DevSecOps, helping organizations develop, secure, and deliver software.
What you will do
- Conduct security research and hands-on penetration testing across 's DevSecOps platform, AI capabilities, agentic workflows, and integrated open-source dependencies.
- Identify novel, systemic, and chained vulnerabilities and develop proof-of-concept exploits demonstrating real-world attack scenarios.
- Research AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation, and help define security requirements for engineering teams.
- Build tooling and automation for scalable security research, including agent-assisted vulnerability discovery.
- Drive remediation of vulnerability classes, provide actionable risk assessments, and improve security processes.
- Mentor security researchers, contribute to the team roadmap, and share findings with engineering teams and the wider security community.
Requirements
- 7+ years of experience in security research, penetration testing, or offensive security.
- Hands-on experience discovering and exploiting vulnerabilities, with subject-matter expertise in at least two product security areas.
- Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust, plus the ability to analyze code across multiple languages and codebases.
- Understanding of AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation.
- Experience leading technical objectives in cross-functional teams and communicating complex findings clearly.
- Strong analytical, problem-solving, and creative attack-scenario development skills.
Nice to have
- Published security research or conference presentations.
- Software engineering background with distributed systems expertise.
- Security certifications such as OSCP, OSCE, or GPEN.
- Experience with or similar DevSecOps platforms.
- Experience with AI frameworks.
Culture & Benefits
- Fully remote work with location-based eligibility requirements.
- Health, financial, and well-being benefits.
- Flexible paid time off and parental leave.
- Equity compensation and an employee stock purchase plan.
- Growth and development funding and team member resource groups.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Staff Application Security Engineer (Web3)
168 000 - 240 000$
Apollo.io
8 дней назад
Senior Application Security Engineer (AI)
190 000 - 273 000$
Writer
5 дней назад
Security Engineer, Applications (AI Security)
Raft Digital Solutions
4 дня назад
AI Security Researcher
6 дней назад
Staff Application Security Engineer (AI)
189 000 - 303 000$
4 дня назад
Senior Application Security Engineer (Crypto)
140 000 - 200 000$