Software Security Engineer

GitLab
San Francisco, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 166K

Job location

Remote

Tech stack

Amazon Web Services (AWS)
Software as a Service
Computer Security
Distributed Systems
Red Team (Cyber Security)
Ruby
Runbook
Software Engineering
Google Cloud Platform
Cloud Platform System
Large Language Models
Software Security
Cyber Threat Analysis
Gitlab
Containerization
Codebase

Job description

You will engineer security improvements to the GitLab product as well as building and maintaining the tools we use to detect and prevent abuse on our SaaS platforms. A strong software engineering background with experience in large Ruby/Rails codebases is required. As an engineer on the Trust and Safety team, you will predictively identify abuse patterns and trends and build prevention systems to mitigate abusive users. The Trust and Safety team both maintains core abuse prevention platforms as well as cross functionally builds customer safety mechanisms on GitLab, such as the introduction of Compromised Password Detection for GitLab.com (link).

This role is an ideal fit for candidates with software engineering backgrounds interested in moving into security engineering. Formal security engineering experience is not a requirement for this role.

Find out more about the Trust and Safety team and responsibilities here:

  • Trust and Safety

What you'll do

  • Maintain core abuse prevention systems and build new abuse detection rules to identify and prevent evolving abuse patterns such as platform abuse, cryptomining, platform spam and abuse of terms of service
  • Maintain and build new capabilities in our in-house abuse platform
  • Improve and expand agentic AI capabilities in our abuse mitigation tools
  • Collaborate with peers to deliver safety improvements for the GitLab product
  • Resolve automation gaps and create efficient, automated processes
  • Create and maintain documentation such as runbooks and procedures

Requirements

  • Strong software development skills with experience in Ruby/Rails
  • Experience working on distributed applications with large codebases and deployed in cloud environments strongly preferred
  • Passion/desire to proactivity develop security engineering skills
  • Comfortable working in an all remote environment where results and impact matter above hours worked
  • Interest in "thinking like a hacker" and defending against attacks with an "automation first" mindset
  • Interest in cloud native development (Google Cloud Platform (GCP) and/or AWS)
  • Interest in handling trust and safety security incidents (platform abuse, cryptomining, platform spam)

About the team

Trust and Safety is a global team tasked with keeping abusive behaviors off of GitLab.com. The team relies on automations, LLM aided predictive analysis, and user behavior analysis to proactively detect and prevent abuse on the Gitlab platform. The Trust and Safety team closely collaborates with peer teams within Security Operations, including Security Incident Response, Signals Engineering, Threat Intelligence, and the Red Team.

The base salary range for this role's listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.

About the company

GitLab is the most comprehensive AI-powered DevSecOps platform for software innovation. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. 

More than 50 million registered users and more than 50% of the Fortune 100 trust GitLab to ship better, more secure software faster.

Apply for this position