Staff Software Engineer, Security Factory: Static Analysis
GitLab
152.8–259.2 אלף $ לשנהRemote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States, מרחוקסניורמשרה מלאה
משרה חיצונית, ההגשה באתר החברהאושר שהמשרה פתוחה לפני 10 שעות
As a Staff Backend Engineer on GitLab’s Code Scanning team, you will set the technical direction for its static analysis engine and help developers find and fix security issues. You will shape the engine’s architecture and evaluation tooling, and guide engineers and AI agents in building and validating it.
מה תעשו
- Own the architecture of the program model and the pipeline that turns source code into findings.
- Define technical direction and specifications for the engine and its extensions to new languages and frameworks.
- Build tooling to test and measure detection quality against benchmark applications with known vulnerabilities.
- Design and maintain checks, agent instructions, and workflows that validate AI-written code and results.
- Lead high-scope initiatives from design through delivery, and mentor engineers through code review and pairing.
- Participate in on-call rotations to help troubleshoot product and security operations.
דרישות
- Professional experience writing, testing, and reviewing production code in Rust, Go, or a comparable systems language, with depth in at least one.
- Experience building LLM tooling, such as a harness, agent pipeline, or evaluation system.
- Background in program analysis and static analysis, including areas such as parsing, intermediate representations, call graphs, or taint analysis.
- Application security experience, such as vulnerability research, secure code review, or writing detection rules.
- Experience defining system architecture, owning team-wide problems, and mentoring engineers.
יתרון
- Familiarity with popular web or mobile application frameworks.
- Experience designing guardrails for agent-written code, such as mutation testing, fuzzing, or CI gates.
- Research or open-source contributions in program analysis or security.
תנאי סף
- Professional production-code experience in Rust, Go, or a comparable systems language, with depth in at least one
- Experience building LLM tooling, such as a harness, agent pipeline, or evaluations
- Application security experience
הטבות
- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development
RustGoLLM toolingStatic analysisProgram analysisApplication securityCI/CDDocker