Gitlab
Senior Software Security Engineer
engineeringfull-timeBangalore, India; Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more
About the role
Overview
You will engineer security improvements to the GitLab product as well as building and maintaining the tools we use to detect and prevent abuse on our SaaS platforms. A strong software engineering background with experience in large Ruby/Rails codebases is required. As a senior engineer on the Trust and Safety team, you will predictively identify abuse patterns and trends and build anomaly detection and prevention systems to mitigate abusive users and their activities.
This role is an ideal fit for candidates with software engineering backgrounds interested in moving into security engineering. Formal security engineering experience is not a hard requirement for this role.
What you’ll do
- Maintain core abuse prevention systems and build new abuse detection rules to identify and prevent evolving platform abuse such as spam, AI/token, SEO optimization/redirects and other financially motivated abuse campaigns.
- Become a core maintainer for our in-house abuse platform (Ruby on Rails monolith) and be comfortable supporting and building new features for the platform.
- Improve and expand agentic AI capabilities in our abuse mitigation tools, including improving multi agent reasoning decision patterns with a target to reduce HITL operational load.
- Lead collaboration with peer engineering teams to deliver safety improvements for the GitLab product.
- Resolve automation gaps and create efficient, automated processes.
- Create and maintain documentation such as runbooks and procedures.
What you’ll bring
- Strong software development skills with experience in Ruby/Rails.
- Experience working on distributed applications with large codebases and deployed in cloud environments strongly preferred.
- Passion/desire to proactively develop security engineering skills.
- Comfortable working in an all remote environment where results and impact matter above hours worked.
- Strong experience with cloud native development (Google Cloud Platform (GCP) and/or AWS).
- Interest in “thinking like a hacker” and defending against attacks with an “automation first” mindset.
- Interest in handling trust and safety security incidents and collaborating with engineering teams.
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply