Remote Jobs

Gitlab logo

Intermediate Backend Engineer, Application Security Testing: Composition Analysis

Gitlab

Location
United States of America
Posted
Salary Range
98k - 210k USD

Enhance security posture by developing features for GitLab's products like Dependency Scanning and Container Scanning. Collaborate with cross-functional teams to maintain high quality in a fast-paced environment. Enjoy remote work and comprehensive benefits including equity compensation and home office support.

GuidePoint Security logo

Vulnerability Management Engineer

GuidePoint Security

Location
United States of America
Posted

Vulnerability Management Engineer job at GuidePoint Security, requiring 5+ years of infosec experience and Tenable expertise.

GuidePoint Security logo

Application Security Engineer

GuidePoint Security

Location
United States of America
Posted

As an Application Security Engineer, you will work with tools like Burp Suite Pro and Invicti to identify and remediate vulnerabilities, integrate security tools into CI/CD pipelines, and collaborate with teams to enhance application security practices. You'll need strong technical skills in secure development lifecycles and excellent communication abilities.

Binance logo

Application Security Engineer

Binance

Location
Brunei Darussalam
Posted

Application Security Engineer at Binance: Collaborate on mobile security, blockchain security, and AI tools

Gusto, Inc. logo

Principal Security Engineer - Application Security

Gusto, Inc.

Location
Canada
Posted
Salary Range
225k - 285k USD

Security Engineering role at Gusto, designing safe features with safety & privacy in mind, building security tools & services, 12+ yrs info sec exp reqd.

Messari logo

Research Analyst

Messari

Location
United States of America
Posted
Salary Range
90k - 90k USD

Conduct comprehensive research on crypto projects, author detailed reports, and engage with the crypto community as part of Messari’s Protocol Services team. Utilize data analysis tools like SQL and Python to provide insights and support decision-making.

Welocalize logo

Research Analyst

Welocalize

Location
Georgia
Posted

Research Analyst for Welo Data - AI Services, improving search engine results with strong analytical skills and attention to detail.

GuidePoint Security logo

Application Security Analyst

GuidePoint Security

Location
United States of America
Posted

Assist in delivering Application Security services at GuidePoint Security by performing DevSecOps assessments, architecture reviews, threat modeling, and designing secure pipelines. Contribute to client engagements, deliver comprehensive reports, and strengthen application security capabilities while staying updated with industry trends and tools.

Leonardo.Ai logo

AI Research

Leonardo.Ai

Location
Australia
Posted
Salary Range
36k - 36k AUD

Join Leonardo.AI as a Generative AI Research Intern to work on cutting-edge projects in areas like LLMs, Deep Learning, and Diffusion Models. Gain hands-on experience with leading researchers in the field while enjoying flexible work arrangements and comprehensive benefits.

Welocalize logo

Research Analyst (Spain)

Welocalize

Location
Spain
Posted

Freelance Research Analyst (Spain) - Evaluate search results, collaborate with data teams, and enhance algorithm performance.

Binance logo

Macro Research Analyst

Binance

Location
Brunei Darussalam
Posted

Join Binance Research team as a Macro Research Analyst & shape the future of crypto industry with institutional-grade research reports

Binance logo

Research Data Analyst

Binance

Location
Brunei Darussalam
Posted

Research Data Analyst at Binance: Build sophisticated visualizations, machine learning models & analyze large volumes of on-chain data

Irreducible logo

Research Engineer, Cryptography Team

Irreducible

Location
Croatia
Posted

Join Irreducible's Cryptography team as a Research Engineer and contribute to the development of Binius, a binary field proof system for zk-SNARKs. Collaborate with a talented team and shape the future of cryptographic computing.

ClinChoice logo

Clinical Research Associate

ClinChoice

Location
United Kingdom
Posted

Join ClinChoice as a Freelance CRA to perform clinical trial monitoring, ensure regulatory compliance, collect data, and support study sites while enjoying professional development and a supportive culture.

ClinChoice logo

Clinical Research Associate

ClinChoice

Location
Netherlands
Posted

Join ClinChoice as a Freelance Clinical Research Associate to support clinical trials with a leading pharmaceutical company. Gain experience in monitoring, compliance, and project management while working in a global, inclusive environment that values diversity and professional development.

ClinChoice logo

Clinical Research Associate

ClinChoice

Location
France
Posted

Join ClinChoice as a Freelance Clinical Research Associate to support clinical trials, ensuring compliance with GCP/ICH guidelines. Work on diverse projects across pharmaceutical, biotech, medical device, and consumer health companies. Collaborate with a dedicated team in a quality-focused culture while enjoying professional growth opportunities.

Gitlab logo

Intermediate Vulnerability Research Engineer - Application Security Testing: Vulnerability Research

Gitlab

Salary Range

98k - 210k USD / YEAR

Job Summary

As a Vulnerability Research Engineer at GitLab, you will be at the forefront of our R&D efforts within the Engineering department. Your role involves enhancing GitLab's security detection capabilities across SAST, DAST, Secret Detection, and Composition Analysis. You'll conduct research on software vulnerabilities, exploitation methods, and novel approaches in software security to improve our security products. Additionally, you'll curate advisory databases for dependency scanning, develop benchmarks to test product efficacy, and respond to customer inquiries. GitLab offers a remote work environment with benefits including flexible PTO, equity compensation, growth opportunities, and home office support.

Skills

Software composition analysis (SCA)SASTDASTSecret DetectionComposition AnalysisSecurity Product DevelopmentCompiler DesignAutomated Web Security Testing Tools

An overview of this role

You'll be at the forefront of our R&D efforts within our Engineering department in this role. You’ll be expected to focus on improving GitLab’s security detection capabilities in our Application Security Testing stage groups. This includes SAST, DAST, Secret Detection and Composition Analysis, and future products.

Vulnerability Research Engineers perform research to analyze software vulnerabilities, exploitation methods, track new vectors, discover novel methods and approaches in software security, and apply this knowledge to the security products and GitLab itself. 

What You’ll Do  

  • Carry out research and come up with proofs of concepts that affect the security products and GitLab, including SAST, DAST, Secret Detection and Composition Analysis.

  • Curate advisory databases for dependency scanning. This is a semi-automatic task that includes auditing/reviewing, editing existing and adding new advisories to the database while, at the same time, trying to automate repetitive tasks away as much as possible.

  • Build/develop benchmarks to test the efficacy of scanning and detection products to constantly improve quality of results.

  • Measure and Improve the efficacy of scanning and detection products over time.

  • Write detailed technical reports.

  • Assess security product output results and conduct root cause analysis to improve efficacy.

  • Respond to internal and external customer inquiries on vulnerabilities and related topics.

What You’ll Bring 

  • 3+ years of direct experience in developing and improving vulnerability detection products in the context of web security.

  • Knowledge of the vulnerability management process.

  • Knowledge of software composition analysis (SCA) and software supply chain ecosystems.

  • Experience with source code analysis, static application security testing (SAST), and dynamic application security testing (DAST) along with benchmarking experience testing the efficacy of these products.

  • Knowledge about compilers, compiler design and construction.

  • Experience developing automated web security testing/analysis tools.

  • Experience in product development.

  • You have a passion for security and open source, and enjoy collaborating with cross-functional teams.

About the team

The Vulnerability Research team works closely with GitLab Security, Development, and Product teams to build, tune and improve the efficacy of the security products that are integrated into GitLab.

Thanks to our Transparency value, you can get a better sense of what the team does daily by browsing some of our past information sharing sessions.

How GitLab will support you

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.