Senior Software Engineer, Security Factory: Code Security

New
G
GitLabApplication security
Location: Remote, Canada; Remote, United States, We rely heavily on asynchronous work across time zones.Full-TimeSenior
Salary139,200 - 235,200 USD per year
Apply NowOpens the employer's application page

Job Details

Required Skills
GoRustCI/CD

Requirements

  • Experience building LLM tooling, such as a harness, agent pipeline, or evaluations, and judging when its output is trustworthy.
  • Substantial professional experience writing and testing production code in a systems language, with depth in Go and/or Rust.
  • Willingness to work across Go, Rust, Ruby, and Python.
  • Familiarity with package managers and dependency management in one or more ecosystems, such as npm, Maven, pip, Bundler, or Cargo.
  • Demonstrated application security experience, such as vulnerability research, secure code review, or writing detection rules.
  • Fluency with vulnerability classes, including OWASP Top 10 and CWE, and the software supply chain.
  • Ability to take ownership of ambiguous problems and ship with minimal guidance in a remote, largely asynchronous environment.
  • Ability to communicate clearly and concisely about technical problems and write design proposals that help a team reach decisions.
  • Helpful experience evaluating AI-driven detection against labeled data, including measuring false positives and missed findings.
  • Helpful experience optimizing performance at scale and with program analysis such as parsing, ASTs, or data-flow analysis.
  • Helpful familiarity with web or mobile application frameworks and containerized workflows and CI/CD, including Docker.

Responsibilities

  • Own team initiatives from design through delivery, partnering with the technical lead and shipping with minimal guidance.
  • Bring engineer-built systems into team ownership through documentation, tests, and shared review.
  • Design and ship analyzers combining deterministic analysis and AI-driven analysis, along with evaluation harnesses for benchmark applications with known vulnerabilities.
  • Build detection rules mapped to CWE and test fixtures that validate them.
  • Package analyzers for CI jobs, AI agent workflows, and command-line tools, reporting findings in GitLab's standard security report formats.
  • Design and ship manifest, lockfile, and SBOM parsing, extending support to additional ecosystems and formats.
  • Ship features for the automated remediation service, from sandboxed dependency updates to merge request creation.
  • Address complex technical problems and advocate for quality, security, and performance improvements with Product Management, engineering stakeholders, and partner teams.
  • Mentor Intermediate engineers through code review and pairing, and maintain internal standards through review.
  • Participate in on-call rotations for product operations, security operations, and urgent engineering issues.
View Full Description & ApplyYou'll be redirected to the employer's site
139,200 - 235,200 USD per year
Apply Now