4 дня назад
Principal Security Researcher (AI Security)
203 200 - 275 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Security Researcher (AI Security): Conducting advanced security research and penetration testing across GitLab's AI-powered DevSecOps platform, Duo Agent Platform, and AI workflows with an accent on vulnerability discovery, exploit validation, and systemic remediation. Focus on researching prompt injection, agent manipulation, workflow exploitation, and building automation for agent-assisted vulnerability discovery.
Location: Remote in Canada, Israel, the United Kingdom, or the United States
Salary: $203,200–$275,000 USD per year for United States residents
Company
provides an intelligent orchestration platform for DevSecOps used by organizations to improve developer productivity, operational efficiency, security, and compliance.
What you will do
- Lead security research projects across 's DevSecOps platform, Duo Agent Platform, Duo Chat, and AI workflows.
- Identify systemic and chained vulnerabilities, validate them through hands-on testing, and develop proof-of-concept exploits.
- Research AI and agentic security surfaces, define security requirements, and investigate attack scenarios.
- Build tooling and automation for scalable security research, including agent-assisted vulnerability discovery.
- Assess open-source tools and dependencies, coordinate responsible disclosure, and track mitigation.
- Lead remediation initiatives, shape the security roadmap, and mentor security researchers and engineering teams.
Requirements
- 10+ years of experience in security research, penetration testing, or offensive security.
- Strong ability to discover and exploit vulnerabilities in large codebases and complex systems.
- Proficiency in at least two of Ruby, Go, Python, TypeScript, or Rust, with the ability to analyze multiple programming languages.
- Strong knowledge of AI frameworks and AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation.
- Ability to drive complex cross-functional remediation initiatives and communicate technical risks clearly.
- Remote work eligibility is limited to Canada, Israel, the United Kingdom, or the United States.
Nice to have
- Published security research or conference presentations.
- Software engineering experience with distributed systems expertise.
- Experience with or similar DevSecOps platforms.
Culture & Benefits
- Remote-first work environment with flexible paid time off.
- Health, financial, and well-being benefits.
- Equity compensation and an employee stock purchase plan.
- Growth and development fund.
- Parental leave and team member resource groups.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Staff Application Security Engineer (Web3)
168 000 - 240 000$
7 дней назад
Head of Cyber Safety (AI Security)
230 000 - 280 000$
9 дней назад
Principal Security Engineer (AI)
256 000 - 320 000$
5 дней назад
Sr. Application Security Engineer (AI)
104 300 - 193 700$
6 дней назад
Staff Application Security Engineer (AI)
189 000 - 303 000$
Writer
5 дней назад