Infra logo

Staff Developer Advocate, GitHub Security Lab

Infra

Location TBDRemoteJob$122–323K/yrPosted 3w agoVerified open 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$122–323K/yr
Location
Location TBDRemote
Work Authorization
Not specified

Job overview

Infra is hiring a Staff Developer Advocate, GitHub Security Lab. GitHub is seeking a Staff Developer Advocate to join the GitHub Security Lab, where the mission is to inspire and enable the community to secure open source software. The role involves acting as a subject‑matter expert and trusted ambassador, engaging researchers, maintainers and developers, and promoting GitHub Security Lab tools such as CodeQL, Dependabot and secret scanning.

Key focus areas include Understand the security community and act as a known subject matter expert, Build trusted relationships between the security community and GitHub teams, and Advocate internally by collecting feedback and influencing product improvements.

Important skills include Application Security, Technical Writing, Public Speaking, Github, Content Development, and Social Media Marketing. Preferred (not required): Copilot, Dependabot, Secret Scanning, and AI-Powered Vulnerability Detection.

Skills & qualifications

RequiredNice to have

Skills

Application SecurityTechnical WritingPublic SpeakingGithubContent DevelopmentSocial Media MarketingMentorshipInternetworkingData AnalysisCopilotCodeQLDependabotSecret ScanningAI-Powered Vulnerability DetectionGitHub Advisory DatabaseTechnical Content CreationCommunity Event LeadershipSocial Media CampaignsAI and Security IntersectionSecuring AI-Generated CodeAI for Vulnerability DiscoveryCross-Team InfluenceTechnical ExpertiseCoachingData-Driven Decision MakingStakeholder InfluenceSecurity Research Community UnderstandingOpen Source Developer Community UnderstandingGitHub Security Products KnowledgeApplication Security Landscape AnticipationTrusted Relationships BuildingInternal AdvocacyEffective CommunicationNetworkingRetrospective EvaluationTechnical Content Strategy DefinitionVulnerability ResearchAI-Assisted Security AnalysisSecure AI Development PracticesContent Quality SettingCommunity EngagementCommunity Member Journey DesignSocial Media ManagementSecure Code PracticesStatic AnalysisSecurity AdvisoriesAI-Generated Code Security ImplicationsAI-Powered Development Tools Security ImplicationsGitSoftware Development PracticesAI/ML Security TopicsSecuring LLM-Based Tools

Qualifications

10+ Years Community/Audience Engagement, IT, Software Development Experience or Related WorkEquivalent ExperienceDelivered Technical Keynote on Security Topic at Developer Conference With 1,000+ AttendeesDelivered Session at Major Security Conference (Black Hat, DEF CON, Etc)Published Regular Content (Blog, Podcast) on Security and Open Source Topics2+ Years Application Security, Secure Code Practices, or Vulnerability Research ExperienceContributions to Open Source Security Projects or Security-Focused Open Source Tools4+ Years Working With Git, GitHub, and Software Development Practices Experience2+ Years Experience With Static Analysis Tools Like CodeQL2+ Years Active Participation in Security CommunitiesAt Least One Public Contribution on AI/ML Security Topics

Full job description

About GitHub

GitHub is the world’s leading platform for agentic software development — powered by Copilot to build, scale, and deliver secure software. Over 180 million developers, including more than 90% of the Fortune 100 companies, use GitHub to collaborate, and more than 77,000 organisations have adopted GitHub Copilot.

Locations

In this role you can work from Remote, United States

Overview

GitHub is seeking a Staff Developer Advocate to join the GitHub Security Lab. The mission of the Security Lab is to inspire and enable the community to secure the open source software we all depend on. We create a home for security researchers where they can collaborate and share, with the common goal of making security easy for developers.

In this role, you will act as a known subject matter expert and trusted ambassador who engages with security researchers, open source maintainers, and enterprise developers and encourages them to get the most out of GitHub Security Lab's security tools and resources — including CodeQL, Dependabot, secret scanning, code scanning, Copilot Autofix, AI-powered vulnerability detection, and the GitHub Advisory Database.

You will define the vision and strategy for the Security Lab's developer advocacy program, producing high-quality technical content (blog posts, tutorials, training, videos, CTFs, conference talks), leading community events, and driving social media campaigns. You will grow our community from a dedicated group of security enthusiasts to everyone who cares about software security. You will also help the security community understand and navigate the evolving intersection of AI and security — from securing AI-generated code to leveraging AI for vulnerability discovery.

As a Staff-level advocate, you bring cross-team influence and deep technical expertise across multiple areas. You don't just execute — you set direction, establish frameworks that help others produce great security content, and proactively identify highly impactful unaddressed issues, mobilizing resources to resolve them before they affect the community. You mentor and sponsor others within the team, and you use data and business outcomes to inform decisions and influence stakeholders across GitHub.

Responsibilities

Understanding the Security Community Acts as a known subject matter expert of the security research and open source developer communities — their common experiences, goals, industry trends, and key developments — by meeting with community members, attending security and developer conferences, and engaging on social media. Possesses expert knowledge of GitHub's security products and services (CodeQL, code scanning, secret scanning, Dependabot, advisory database) and their potential impact on the broader security ecosystem. Strategically seeks out influencers in the security and open source spaces to understand business drivers and community objectives. Anticipates future changes in the application security landscape, including the impact of AI on security research workflows and the emerging challenges of securing AI-generated code.

Building Trusted Relationships Acts as a trusted and influential ambassador between the security community and GitHub's product, engineering, and marketing teams. Builds and maintains a broad, diverse network across security researchers, open source maintainers, and enterprise security teams. Utilizes deep understanding of community needs to share valuable insights, best practices, and technical know-how, maintaining thought leadership within the security community.

Internal Advocacy and Impact Collects and seeks out feedback from the security community and stakeholders regarding product usage, user experience, and technical issues. Communicates clearly and effectively to relevant product groups, advocating for and influencing urgent and long-term improvements to GitHub's security features. Proactively builds and manages networks of key stakeholders and leads engagement through established and informal channels to provide feedback on priorities and emerging security scenarios. Incorporates data and key metrics into findings regarding value-add and impact of advocacy initiatives. Ensures the feedback loop between community members, the Security Lab, and the GitHub product team is effective.

Supporting Key Internal Initiatives Builds and enhances trust with internal teams through networking and engagement regarding security product improvement plans. Acts as a subject matter expert for internal stakeholders on application security and the security researcher community. Regularly engages in retrospective evaluations to inform future work.

Content Development Defines, creates, and leads the technical content strategy for the Security Lab — blog posts, tutorials, training courses, videos, CTFs, puzzles, and conference talks — covering topics from traditional vulnerability research to AI-assisted security analysis and secure AI development practices. Drives interactions across technical forums, social media, and community channels to promote awareness and provide best practices. Represents the GitHub Security Lab at high-visibility security and developer conferences, hackathons, and meetups. Sets the standard for content quality and measures impact to continuously improve how we communicate with the security community.

Community Impact Actively seeks out feedback and listens to the needs of the security community, responding with relevant information and upskilling others to make a substantial impact on community growth. Designs the community member journey — from first engagement to active contributor — measuring retention and engagement along the way. Proposes strategic improvements to the community experience. Manages the Security Lab's social media presence and public forums. Applies deep knowledge of GitHub's security products, stakeholders, and strategic objectives to influence and inspire the audience.

Technical Expertise Possesses deep technical expertise in application security, secure code practices, vulnerability research, AI-assisted code analysis, and static analysis. Constantly seeks out learning and teaching opportunities and engages in conversations with key security researchers and developers to understand current developments and issues. Applies and practices technical expertise via sample code, CodeQL queries, security advisories, and demonstrations. Builds processes and systems to share technical expertise at scale and works within the industry to help inform future security developments. Understands the security implications of AI-generated code and AI-powered development tools, and can communicate best practices for secure AI adoption to both security researchers and developers. Gains broader knowledge of adjacent technologies and incorporates them into current areas of expertise.

Qualifications

Required Qualifications

  • 10+ years experience in community/audience engagement, information technology, software development, or related work

  • OR Bachelor's Degree AND 8+ years experience in community/audience engagement, information technology, software development, or related work

  • OR equivalent experience

  • Delivered at least one technical keynote on a security topic at a developer conference with 1,000+ attendees

  • OR delivered a session at a major security conference (Black Hat, DEF CON, etc)

  • OR published regular content (blog, podcast) on security and open source topics

  • 2+ years of experience in application security, secure code practices, or vulnerability research

  • OR 2+ years of experience in a Developer Advocacy function on application security, secure code practices, or vulnerability research topics

  • OR contributions to open source security projects or security-focused open source tools

  • 4+ years of experience working with Git, GitHub, and software development practices Preferred Qualifications

  • 13+ years experience in community/audience engagement, information technology, software development, public speaking, technical writing, or related work

  • OR Bachelor's Degree AND 11+ years experience in community/audience engagement, information technology, software development, public speaking, technical writing, or related work

  • OR equivalent experience

  • 2+ years of experience with static analysis tools like CodeQL

  • 2+ years of active participation in security communities

  • OR 2+ years of active participation in open source maintainer communities with a focus on security

  • OR 2+ years of mentoring or teaching application security, secure code practices, or vulnerability research

  • At least one public contribution (content, open source tooling) on AI/ML security topics — such as securing AI-generated code, AI-assisted vulnerability discovery, or red-teaming LLM-based tools Compensation Range

The base salary range for this job is USD $121,800.00 - USD $323,200.00 /Yr.

These pay ranges are intended to cover roles based across the United States. An individual's base pay depends on various factors including geographical location and review of experience, knowledge, skills, abilities of the applicant. At GitHub certain roles are eligible for benefits and additional rewards, including annual bonus and stock. These rewards are allocated based on individual impact in role. In addition, certain roles also have the opportunity to earn sales incentives based on revenue or utilization, depending on the terms of the plan and the employee's role.

This position will be open for a minimum of 3 days, with applications accepted on an ongoing basis until the position is filled. GitHub values

  • Customer-obsessed

  • Ship to learn

  • Growth mindset

  • Own the outcome

  • Better together

  • Diverse and inclusive Manager fundamentals

  • Model

  • Coach

  • Care Leadership principles

  • Create clarity

  • Generate energy

  • Deliver success Who We Are

GitHub is the world’s leading AI-powered developer platform with 150 million developers and counting. We’re also home to the biggest open-source community on earth (and 99% of the world’s software has open-source code in its DNA). Many of the apps and programs you use every day are built on GitHub. Our teams are dreamers, doers, and pioneers, leading the way in AI, driving humanitarian efforts around the globe, and even sending open source to Mars (and beyond!). At GitHub, our goal is to create the space you need to do your best work. We’re remote-first and offer competitive pay, generous learning and growth opportunities, and excellent benefits to support you, wherever you are—because we know that people flourish when they can work on their own terms. Join us, and let’s change the world, together.

EEO Statement

GitHub is made up of people from a wide variety of backgrounds and lifestyles. We embrace diversity and invite applications from people of all walks of life. We don't discriminate against employees or applicants based on gender identity or expression, sexual orientation, race, religion, age, national origin, citizenship, disability, pregnancy status, veteran status, or any other differences. Also, if you have a disability, please let us know if there's any way we can make the interview process better for you; we're happy to accommodate!

You've read the whole posting — now see how you match it.