Staff Software Engineer, Security Factory: Static Analysis
New
G
GitLabApplication security
Location: Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States, We rely heavily on asynchronous work across time zones.Full-TimeStaff
Salary152,800 - 259,200 USD per year
Apply NowOpens the employer's application page
Job Details
- Required Skills
- DockerRubyGoRustCI/CD
Requirements
- Experience building LLM tooling, such as a harness, agent pipeline, or evaluations, and judging when its output is trustworthy.
- Extensive professional experience writing, testing, and reviewing production code in Rust, Go, or a comparable systems language, with depth in at least one.
- Experience with performance optimization, containerized workflows, and CI/CD; Docker is used heavily.
- Deep program analysis and static analysis experience, such as parsing and ASTs, intermediate representations, call graphs, taint and data-flow analysis, type inference, incremental and fixpoint computation, or detection rules.
- Ability to read, evaluate, and apply program analysis and security research literature.
- Deep application security experience, such as vulnerability research, secure code review, or writing detection rules.
- Fluency with vulnerability classes including OWASP Top 10 and CWE.
- Ability to communicate complex technical, architectural, and organizational problems clearly and write architecture and design specifications.
- Track record of owning ambiguous, team-wide problems and delivering them to production with minimal guidance, with regular async progress updates.
- Experience defining system architecture, delegating component specifications to engineers and AI agents, and getting them implemented reliably.
- Track record of mentoring engineers, raising a team's technical bar, and influencing technical direction through consensus.
Responsibilities
- Act as the directly responsible individual for high-scope initiatives from design through delivery, shipping large features with minimal guidance.
- Set the technical direction for the static analysis engine and define its long-range goals.
- Own the architecture of the program model, including parsing, symbol resolution, intermediate representations, call graphs, and taint and data-flow analysis.
- Define how the engine and its pipeline extend to new languages and frameworks.
- Build and maintain the harness, agent instructions, agentic skills, and checks that validate agent-written code and generated findings.
- Measure detection quality against benchmark applications with known vulnerabilities, including SAST rules mapped to CWE and OWASP and their test fixtures.
- Define overarching architecture and specification documents, delegate component specifications, and drive implementation by AI agents and engineers.
- Mentor engineers through code review and pairing, remove blockers, and improve internal standards.
- Collaborate with Product Management, UX, Code Security, and Composition Analysis on technical issues and improvements.
- Participate in on-call rotations and contribute to research, prototypes, proposals, and upstream contributions.
View Full Description & ApplyYou'll be redirected to the employer's site