Skip to main content

Senior Software Engineer

GitLab
Remote - Canada, United StatesUpdated 1d ago
Base salary
$139k–$235k
Published base salary range
Location
Remote - Canada, United States
Remote eligibility
Employment
Full-time
Senior
Role family
Security
Developer tools
Role skills
Apply on job-boards.greenhouse.io
Job actionsApply now
Job actionsApply now

About the job

About the Role

As a Senior Backend Engineer on GitLab's Security Factory: Code Security team, you help developers find and fix security issues in the code they write and in the open source components they depend on. Your work spans complementary parts of a complete security analysis: on the dependency analysis side, you teach the analysis engine what a project depends on by parsing dependency manifests, lockfiles, and SBOMs, and you extend the service that turns security advisories into automated merge requests that update vulnerable dependencies. On the vulnerability detection side, you grow GitLab's security analysis engine with hybrid analyzers that blend rule-based detection and AI reasoning, and you build tooling to develop, evaluate, and ship those analyzers.

What You'll Do

  • Act as the directly responsible individual (DRI) for team initiatives from design through delivery, shipping with minimal guidance in partnership with the technical lead.
  • Bring systems built by one engineer to team ownership through documentation, tests, and shared review.
  • Design and ship analyzers that pair deterministic analysis with AI-driven analysis, and build evaluation harnesses that measure false positives and missed findings against benchmark applications with known vulnerabilities, including detection rules mapped to CWE and test fixtures.
  • Package analyzers for every place GitLab runs them, including CI jobs, AI agent workflows, and command-line tools, with findings reported in GitLab's standard security report formats.
  • Design and ship manifest, lockfile, and SBOM parsing for the static analysis engine, and extend it to new ecosystems and formats.
  • Ship features across the automated remediation service that turns security advisories into dependency update merge requests, from sandboxed updates to merge request creation.
  • Solve technical problems of high scope and complexity, advocate for improvements to quality, security, and performance with Product Management and partner teams.
  • Mentor Intermediate engineers through code review and pairing, and maintain internal standards for style, maintainability, and best practices.
  • Participate in on-call rotations to assist troubleshooting product operations, security operations, and urgent engineering issues.

What You'll Bring

  • Experience building your own LLM tooling, such as a harness, an agent pipeline, or evaluations, with judgment to know when output is trustworthy.
  • Substantial professional experience writing and testing production code in a systems language, particularly Go and/or Rust, with depth in at least one. We use both, plus Ruby on the remediation side and Python for some analyzers.
  • Familiarity with package managers and dependency management in one or more language ecosystems, such as npm, Maven, pip, Bundler, or Cargo.
  • Demonstrated application security experience, such as vulnerability research, secure code review, or writing detection rules, and fluency with vulnerability classes (OWASP Top 10, CWE) and the software supply chain.
  • A track record of taking ownership of ambiguous problems and shipping with minimal guidance, with self-motivation and organizational skills suited to a remote, largely asynchronous environment.
  • Demonstrated capacity to communicate clearly and concisely about technical problems, and to write design proposals that bring a team to a decision.

Helpful Experience

  • Experience evaluating AI-driven detection against labeled data, including measuring false positives and missed findings.
  • Experience with performance optimization at scale.
  • Hands-on program analysis experience, such as parsing, ASTs, or data-flow analysis.
  • Familiarity with popular web or mobile application frameworks and how they handle input, data, and configuration.
  • Experience with containerized workflows and CI/CD (we use Docker heavily).

About the Team

The Security Factory: Code Security team builds GitLab's code-level security scanning capabilities, spanning static application security testing and dependency scanning. We work closely with the Static Analysis team on GitLab's SAST engines, with Composition Analysis on the broader software supply chain, and with other groups across the Sec Section. We rely heavily on asynchronous work across time zones.

Compensation & Benefits

The base salary range for this role's listed level is currently for residents of the United States only: $139,200—$235,200 USD. The range does not include bonuses, equity, or benefits. GitLab offers benefits to support health, finances, and well-being, including Flexible Paid Time Off, Team Member Resource Groups, Equity Compensation & Employee Stock Purchase Plan, Growth and Development Fund, and Parental Leave.

Application Instructions

Apply via the Greenhouse job posting. GitLab welcomes interest from candidates with varying levels of experience; if you're excited about this role, please apply and allow recruiters to assess your application.

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.