Senior Software Engineer, Security Factory: Code Security
New
G
GitLabApplication security
Location: Remote, Canada; Remote, United States, We rely heavily on asynchronous work across time zones.Full-TimeSenior
Salary139,200 - 235,200 USD per year
Apply NowOpens the employer's application page
Job Details
- Required Skills
- GoRustCI/CD
Requirements
- Experience building LLM tooling, such as a harness, agent pipeline, or evaluations, and judging when its output is trustworthy.
- Substantial professional experience writing and testing production code in a systems language, with depth in Go and/or Rust.
- Willingness to work across Go, Rust, Ruby, and Python.
- Familiarity with package managers and dependency management in one or more ecosystems, such as npm, Maven, pip, Bundler, or Cargo.
- Demonstrated application security experience, such as vulnerability research, secure code review, or writing detection rules.
- Fluency with vulnerability classes, including OWASP Top 10 and CWE, and the software supply chain.
- Ability to take ownership of ambiguous problems and ship with minimal guidance in a remote, largely asynchronous environment.
- Ability to communicate clearly and concisely about technical problems and write design proposals that help a team reach decisions.
- Helpful experience evaluating AI-driven detection against labeled data, including measuring false positives and missed findings.
- Helpful experience optimizing performance at scale and with program analysis such as parsing, ASTs, or data-flow analysis.
- Helpful familiarity with web or mobile application frameworks and containerized workflows and CI/CD, including Docker.
Responsibilities
- Own team initiatives from design through delivery, partnering with the technical lead and shipping with minimal guidance.
- Bring engineer-built systems into team ownership through documentation, tests, and shared review.
- Design and ship analyzers combining deterministic analysis and AI-driven analysis, along with evaluation harnesses for benchmark applications with known vulnerabilities.
- Build detection rules mapped to CWE and test fixtures that validate them.
- Package analyzers for CI jobs, AI agent workflows, and command-line tools, reporting findings in GitLab's standard security report formats.
- Design and ship manifest, lockfile, and SBOM parsing, extending support to additional ecosystems and formats.
- Ship features for the automated remediation service, from sandboxed dependency updates to merge request creation.
- Address complex technical problems and advocate for quality, security, and performance improvements with Product Management, engineering stakeholders, and partner teams.
- Mentor Intermediate engineers through code review and pairing, and maintain internal standards through review.
- Participate in on-call rotations for product operations, security operations, and urgent engineering issues.
View Full Description & ApplyYou'll be redirected to the employer's site