Skip to main content

Staff Software Engineer, Security Factory: Static Analysis

GitLab
Remote - Canada, Israel, UK, or USUpdated 1d ago
Base salary
$153k–$259k
Published base salary range
Location
Remote - Canada, Israel, UK, or US
Remote eligibility
Employment
Full-time
Staff / Principal
Role family
Security
Developer tools
Role skills
Apply on job-boards.greenhouse.io
Job actionsApply now
Job actionsApply now

About the job

About the role

As a Staff Backend Engineer on GitLab's Security Factory: Code Scanning team, you help developers find and fix security issues. You set the technical direction for the static analysis engine that finds them. Your work spans two complementary parts: on the engine side, you shape how the static analysis toolkit models a program (parsing source into intermediate representations, resolving symbols, building call graphs, and tracking tainted data across files and languages). On the evaluation side, you build and apply tooling that tests, measures, and validates what the engine finds against benchmark applications with known vulnerabilities.

What you do

  • Act as the directly responsible individual (DRI) for the team's highest-scope initiatives from design through delivery.
  • Set the technical direction for the AI-assisted tooling that implements, reviews, and validates engine changes and findings.
  • Own the architecture of the program model and the pipeline that turns source code into findings.
  • Solve technical problems of the highest scope and complexity.
  • Mentor all engineers on the team through code review and pairing.
  • Participate in on-call rotations.
  • Define the overarching architecture and specification documents for the engine, delegating component specifications to engineers and AI agents.
  • Build and maintain the harness, agent instructions, and agentic skills that keep agent-written code trustworthy.
  • Stay current with research in program analysis and security.

What you bring

  • Experience building your own LLM tooling, such as a harness, an agent pipeline, or evaluations.
  • Extensive professional experience writing, testing, and reviewing production code in Rust, Go, or a comparable systems language.
  • Experience with performance optimization and with containerized workflows and CI/CD (we use Docker heavily).
  • A deep program analysis and static analysis background.
  • Deep application security experience, such as vulnerability research, secure code review, or writing detection rules.
  • Demonstrated capacity to communicate clearly and concisely about complex technical problems.
  • A track record of taking ownership of ambiguous, team-wide problems.
  • Experience defining a system's overarching architecture.
  • A track record of mentoring engineers.

About the team

The Security Factory: Code Scanning team develops GitLab's SAST capabilities for customer software repositories. We work closely with the Code Security team and Composition Analysis. We rely heavily on asynchronous work across time zones.

Compensation

United States Salary Range: $152,800—$259,200 USD. The base salary range does not include any bonuses, equity, or benefits.

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.