FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Staff Software Engineer, Security Factory – Static Analysis
GitLab. Act as the directly responsible individual for the team's highest-scope initiatives from design through delivery .
Posted 10/10/2026full-timeRemote • United States, Canada, Israel, United KingdomLead💰 $152,800 - $259,200 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in building and optimizing AI-assisted tooling, with a strong focus on program analysis, application security, and production code development in systems languages. Proven ability to lead architectural decisions, mentor engineers, and drive initiatives from concept to delivery.
Highest-signal resume keywords
Rust ProgrammingGo ProgrammingDeep Program AnalysisApplication SecurityCI/CD with Docker
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Production Code WritingTesting and ReviewingPerformance OptimizationStatic AnalysisTaint AnalysisData-Flow AnalysisArchitecture SpecificationVulnerability ResearchMutation TestingFuzzing
Soft Skills
Clear CommunicationMentoring EngineersProblem SolvingTeam CollaborationInfluencing Technical Direction
Tools & Technologies
GitLabDockerCI/CD PipelinesAgent PipelinesHarnesses
Industry Keywords
OWASP Top 10CWE Vulnerability ClassesASTsControl-Flow GraphsIncremental Computation
Tech Stack
Tools & technologiesDockerOpen SourceRubyRustGo
About the role
Key responsibilities & impact- Act as the directly responsible individual for the team's highest-scope initiatives from design through delivery
- Ship large features with minimal guidance and shape the team's long-range goals
- Bring systems built by one engineer to team ownership through documentation, tests, and shared review
- Set technical direction for AI-assisted tooling that implements, reviews, and validates engine changes and findings
- Design checks for agent-written changes and generated results, and measure detection quality against benchmark applications with known vulnerabilities
- Own the architecture of the program model, including parsing, symbol resolution, intermediate representations, call graphs, taint analysis, and data-flow analysis
- Own the pipeline that turns source code into findings and define its extension to new languages and frameworks
- Solve high-scope technical problems and advocate for quality, security, and performance improvements
- Collaborate with Product Management, UX, Code Security, Composition Analysis, and other partner teams
- Mentor engineers through code review and pairing, remove blockers, and improve internal standards
- Participate in on-call rotations for product operations, security operations, and urgent engineering issues
- Define architecture and specification documents and drive implementation by AI agents and engineers
- Build and maintain harnesses, agent instructions, agentic skills, coding and reviewing agents, independent review panels, and performance, API, and dependency gates
- Stay current with program analysis and security research, run AI-assisted research and spikes, and turn findings into prototypes, proposals, and upstream contributions
- Develop GitLab's SAST capabilities for customer software repositories
Requirements
What you’ll need- Experience building your own LLM tooling, such as a harness, an agent pipeline, or evaluations, with the judgment to know when output is trustworthy
- Extensive professional experience writing, testing, and reviewing production code in Rust, Go, or a comparable systems language, with depth in at least one
- Willingness to work across Rust, Go, and Ruby
- Experience with performance optimization and containerized workflows and CI/CD, including Docker
- Deep program analysis and static analysis background, including parsing and ASTs, intermediate representations, SSA, control-flow and call graphs, taint and data-flow analysis, type inference, incremental and fixpoint computation, or detection rules
- Ability to read, evaluate, and apply research literature
- Deep application security experience, including vulnerability research, secure code review, or writing detection rules
- Fluency with OWASP Top 10 and CWE vulnerability classes
- Ability to communicate clearly and concisely about complex technical, architectural, and organizational problems
- Ability to write architecture and design specifications that bring a team to a decision
- Track record of owning ambiguous, team-wide problems and shipping from concept to production with minimal guidance
- Experience defining overarching architecture, delegating component specifications to engineers and AI agents, and getting them implemented reliably
- Track record of mentoring engineers, raising technical standards, and influencing technical direction by achieving consensus
- Familiarity with popular web or mobile application frameworks (helpful)
- Experience designing guardrails for agent-written code, such as mutation testing, fuzzing, and CI gates (helpful)
- Research community engagement through publications, tool papers, or upstream open source contributions (helpful)
Benefits
Comp & perks- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave