1

Application Security Researcher Jobs (NOW HIRING)

An overview of the role We are seeking a Principal Security Researcher to join our Application Security Team to conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities.

An overview of the role We are seeking a Staff Security Research Engineer to join our Application Security Team to conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities.

This is an exciting security research opportunity for a skilled professional passionate about ... Analyze application and infrastructure behavior to identify weaknesses that may not be apparent ...

Join a security-focused research team protecting some of the most important protocols and financial ... Web2 security experience in areas such as penetration testing, web application security ...

As a member of the Vectra AI Security Research team, you will be part of a highly experienced ... Knowledgeable in network and application protocols, and traffic analysis (network forensics)

New

As a member of the Vectra AI Security Research team, you will be part of a highly experienced ... Knowledgeable in network and application protocols, and traffic analysis (network forensics)

We are looking for strong security researchers with strong intuition to identify, analyze, and investigate application vulnerabilities. You'll collaborate with AI researchers and engineers to uncover ...

Experience with static application security testing, software composition analysis, SARIF, secure ... Security Research IC5 - The typical base pay range for this role across the U.S. is USD $142,800 ...

Dive deep into terabytes of SaaS Application data to identify new attack vectors, emerging threats ... Collaborate with security researchers and data scientists to define new threat detection strategies ...

As a member of the Vectra AI Security Research team, you will be part of a highly experienced ... Knowledgeable in network and application protocols, and traffic analysis (network forensics)

As a member of the Vectra AI Security Research team, you will be part of a highly experienced ... Knowledgeable in network and application protocols, and traffic analysis (network forensics)

As a Windows Security Researcher, you will be part of a team focused on conducting security ... in application materials based on available information. These tools assist our recruitment team ...

... application within working systems: someone who can discover novel failure modes, build rigorous ... Develop and answer open-ended AI security research questions that helps NVIDIA understand, measure ...

... application within working systems: someone who can discover novel failure modes, build rigorous ... Develop and answer open-ended AI security research questions that helps NVIDIA understand, measure ...

... application within working systems: someone who can discover novel failure modes, build rigorous ... Develop and answer open-ended AI security research questions that helps NVIDIA understand, measure ...

New

... application within working systems: someone who can discover novel failure modes, build rigorous ... Develop and answer open-ended AI security research questions that helps NVIDIA understand, measure ...

next page

Showing results 1-20

Application Security Researcher information

See salary details

$47

$51

$54

How much do application security researcher jobs pay per hour?

As of Sep 15, 2026, the average hourly pay for application security researcher in the United States is $51.44, according to ZipRecruiter salary data. Most workers in this role earn between $49.76 and $53.12 per hour, depending on experience, location, and employer.

What cities are hiring for Application Security Researcher jobs?

Cities with the most Application Security Researcher job openings:

What states have the most Application Security Researcher jobs?

States with the most job openings for Application Security Researcher jobs include:

What are popular job titles related to Application Security Researcher jobs?

For Application Security Researcher jobs, the most frequently searched job titles are:

Infographic showing various Application Security Researcher job openings in the United States as of September 2026, with employment types broken down into 50% Full Time, and 50% Contract. Highlights an 50% Hybrid, and 50% Remote job distribution, with an average salary of $107,000 per year, or $51.4 per hour.

Principal Security Researcher

Remote

GitLab
IT Services • 1 - 5K employees

Full-time

Posted 9 days ago


Job description

An overview of the role

We are seeking a Principal Security Researcher to join our Application Security Team to conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities. As GitLab transforms software development through intelligent collaboration between developers and specialized AI agents, we need security researchers who can proactively identify and validate vulnerabilities before they impact our platform or customers.

In this role, you'll be at the forefront of security research, working with our GitLab DevSecOps platform, Duo Agent Platform, GitLab Duo Chat, and AI workflows that represent the future of human/AI collaborative development. You'll develop novel testing methodologies (including for AI agent security), conduct hands-on penetration testing, and translate emerging threats into actionable security improvements. Your research will directly influence how we build and secure the next generation of AI-powered DevSecOps tools, ensuring GitLab remains the most secure software factory platform on the market.

This position offers the unique opportunity to shape security and AI security practices in one of the world's largest DevSecOps platforms, working with engineering teams who are pushing the boundaries of what's possible with AI-assisted software development. You'll have access to cutting-edge AI systems and the freedom to explore creative attack scenarios while contributing to the security of millions of developers worldwide.

This role reports to the Senior Manager of Application Security.

What you'll do 
  • Conduct and lead security research projects across multiple functional areas.
  • Identify novel, systemic, and chained vulnerabilities in GitLab, where individual weaknesses combine for outsized impact.
  • Validate security vulnerabilities through hands-on testing, developing proof-of-concept exploits that demonstrate real-world attack scenarios.
  • Assess emerging industry vulnerability classes against the GitLab codebase, and drive remediation of the class rather than the instance.
  • Lead security research into GitLab's AI and agentic surfaces, and define the security requirements that engineering teams build against.
  • Build and direct the tooling and automation that scales security research, including agent-assisted vulnerability discovery across our codebase.
  • Research the security posture of open source tools and dependencies integrated with GitLab, report findings to their maintainers, and track mitigation following our responsible disclosure guidelines.
  • Solve technical problems of the highest scope, complexity, and ambiguity.
  • Help shape the team and sub-department roadmap.
  • Lead the integration of security research results into the engineering and business functions that need to act on them.
  • Teach, mentor, and advise other domain experts and individual contributors across several teams.
  • Share knowledge and novel vulnerability types with the security community.
What you'll bring
  • 10+ years of experience in security research, penetration testing, or offensive security roles
  • Strong ability in discovering and exploiting vulnerabilities in large codebase and complex systems
  • Proficiency in two or more of Ruby, Go, Python, TypeScript, or Rust. 
  • Ability to read and analyze code across multiple languages and codebases
  • Strong knowledge of AI frameworks
  • Strong understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation
  • At ease in establishing and driving complex remediation initiatives involving cross-functional teams
  • Excellent written communication skills with an ability to articulate complex topics in a clear and concise manner.
  • Ability to translate complex technical findings into clear risk assessments and remediation recommendations
  • Strong analytical and problem-solving skills with creative thinking about attack scenarios
  • Nice to Have: Published security research or conference presentations; background in software engineering with distributed systems expertise; experience with GitLab or similar DevSecOps platforms
About the team

Security Researchers are a part of our Application Security team, who address complex security challenges facing GitLab and its customers to enable GitLab to be the most secure software factory platform on the market. We focus on systemic product security risks and work cross-functionally to mitigate them while maintaining Engineering's development velocity.