Staff Software Engineer, Security Factory: Static Analysis
GitLab- Base salary
- $153k–$259k Published base salary range
- Location
- Remote - Canada, Israel, UK, or US Remote eligibility
- Employment
- Full-time Staff / Principal
About the job
About the role
As a Staff Backend Engineer on GitLab's Security Factory: Code Scanning team, you help developers find and fix security issues. You set the technical direction for the static analysis engine that finds them. Your work spans two complementary parts: on the engine side, you shape how the static analysis toolkit models a program (parsing source into intermediate representations, resolving symbols, building call graphs, and tracking tainted data across files and languages). On the evaluation side, you build and apply tooling that tests, measures, and validates what the engine finds against benchmark applications with known vulnerabilities.
What you do
- Act as the directly responsible individual (DRI) for the team's highest-scope initiatives from design through delivery.
- Set the technical direction for the AI-assisted tooling that implements, reviews, and validates engine changes and findings.
- Own the architecture of the program model and the pipeline that turns source code into findings.
- Solve technical problems of the highest scope and complexity.
- Mentor all engineers on the team through code review and pairing.
- Participate in on-call rotations.
- Define the overarching architecture and specification documents for the engine, delegating component specifications to engineers and AI agents.
- Build and maintain the harness, agent instructions, and agentic skills that keep agent-written code trustworthy.
- Stay current with research in program analysis and security.
What you bring
- Experience building your own LLM tooling, such as a harness, an agent pipeline, or evaluations.
- Extensive professional experience writing, testing, and reviewing production code in Rust, Go, or a comparable systems language.
- Experience with performance optimization and with containerized workflows and CI/CD (we use Docker heavily).
- A deep program analysis and static analysis background.
- Deep application security experience, such as vulnerability research, secure code review, or writing detection rules.
- Demonstrated capacity to communicate clearly and concisely about complex technical problems.
- A track record of taking ownership of ambiguous, team-wide problems.
- Experience defining a system's overarching architecture.
- A track record of mentoring engineers.
About the team
The Security Factory: Code Scanning team develops GitLab's SAST capabilities for customer software repositories. We work closely with the Code Security team and Composition Analysis. We rely heavily on asynchronous work across time zones.
Compensation
United States Salary Range: $152,800—$259,200 USD. The base salary range does not include any bonuses, equity, or benefits.
Skills & tags
Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.