Staff Software Engineer, Security Factory: Static Analysis

New
G
GitLabApplication security
Location: Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States, We rely heavily on asynchronous work across time zones.Full-TimeStaff
Salary152,800 - 259,200 USD per year
Apply NowOpens the employer's application page

Job Details

Required Skills
DockerRubyGoRustCI/CD

Requirements

  • Experience building LLM tooling, such as a harness, agent pipeline, or evaluations, and judging when its output is trustworthy.
  • Extensive professional experience writing, testing, and reviewing production code in Rust, Go, or a comparable systems language, with depth in at least one.
  • Experience with performance optimization, containerized workflows, and CI/CD; Docker is used heavily.
  • Deep program analysis and static analysis experience, such as parsing and ASTs, intermediate representations, call graphs, taint and data-flow analysis, type inference, incremental and fixpoint computation, or detection rules.
  • Ability to read, evaluate, and apply program analysis and security research literature.
  • Deep application security experience, such as vulnerability research, secure code review, or writing detection rules.
  • Fluency with vulnerability classes including OWASP Top 10 and CWE.
  • Ability to communicate complex technical, architectural, and organizational problems clearly and write architecture and design specifications.
  • Track record of owning ambiguous, team-wide problems and delivering them to production with minimal guidance, with regular async progress updates.
  • Experience defining system architecture, delegating component specifications to engineers and AI agents, and getting them implemented reliably.
  • Track record of mentoring engineers, raising a team's technical bar, and influencing technical direction through consensus.

Responsibilities

  • Act as the directly responsible individual for high-scope initiatives from design through delivery, shipping large features with minimal guidance.
  • Set the technical direction for the static analysis engine and define its long-range goals.
  • Own the architecture of the program model, including parsing, symbol resolution, intermediate representations, call graphs, and taint and data-flow analysis.
  • Define how the engine and its pipeline extend to new languages and frameworks.
  • Build and maintain the harness, agent instructions, agentic skills, and checks that validate agent-written code and generated findings.
  • Measure detection quality against benchmark applications with known vulnerabilities, including SAST rules mapped to CWE and OWASP and their test fixtures.
  • Define overarching architecture and specification documents, delegate component specifications, and drive implementation by AI agents and engineers.
  • Mentor engineers through code review and pairing, remove blockers, and improve internal standards.
  • Collaborate with Product Management, UX, Code Security, and Composition Analysis on technical issues and improvements.
  • Participate in on-call rotations and contribute to research, prototypes, proposals, and upstream contributions.
View Full Description & ApplyYou'll be redirected to the employer's site
152,800 - 259,200 USD per year
Apply Now