Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
API @ 3
CI/CD @ 3
Communication @ 3
Customer Support @ 1
Data Analysis @ 1
OWASP @ 2
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
As a Security Analyst on GitLab’s Product Security Vulnerability Operations team, you will help protect GitLab customers by triaging security reports, supporting vulnerability management operations, and coordinating communications with security researchers, customers, and internal teams.
This role works closely with PSIRT engineers, Vulnerability Management, Security Engineering, Legal, Customer Success, Support, and Communications. It is intended for an early-career security professional who is curious, organized, detail-oriented, and interested in building expertise in product security response.
The role is open to candidates across North America, with a preference for candidates based on the West Coast of the United States or in British Columbia, Canada, to expand coverage in the Pacific Time Zone.
Responsibilities
- Triage incoming bug bounty reports by reviewing report quality, validating findings, assessing potential impact, identifying duplicates, and routing reports to the appropriate teams.
- Triage vulnerabilities identified through vulnerability management activities and track them through assessment, remediation, and closure.
- Work with PSIRT engineers and development teams to gather technical details, reproduce issues, and clarify affected products, versions, and configurations.
- Support severity assessment using CVE, CVSS, CWE, and OWASP frameworks and terminology.
- Communicate professionally with security researchers participating in coordinated vulnerability disclosure and bug bounty programs.
- Support GitLab’s role as a CVE Numbering Authority by preparing information for CVE assignment, maintaining accurate records, and coordinating CVE-related activities.
- Represent GitLab as an acting CNA representative in CVE-related discussions and operations, escalating questions and coordinating with internal and external stakeholders.
- Draft and coordinate customer-facing communications about security vulnerabilities, fixes, mitigations, and release information in partnership with PSIRT, Legal, Customer Success, Support, and Corporate Communications.
- Maintain accurate issue records, timelines, researcher communications, remediation status, and follow-up actions.
- Monitor queues and operational metrics to identify trends, aging items, recurring issues, and opportunities to improve response quality and consistency.
- Create and improve runbooks, procedures, templates, and other documentation to make vulnerability handling more efficient and transparent.
- Participate in incident handoffs, root cause analysis documentation, lessons-learned activities, and product security reviews.
- Build technical and operational expertise in PSIRT, bug bounty, vulnerability management, and coordinated vulnerability disclosure.
Requirements
- Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related field. Relevant internships, coursework, labs, research, customer support, or practical security projects are welcome.
- Foundational understanding of software vulnerabilities and security concepts, including web applications, APIs, CI/CD environments, authentication, and authorization.
- Familiarity with CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure.
- Strong attention to detail and the ability to organize and prioritize multiple reports or work items.
- Clear written and verbal communication skills, including the ability to explain technical topics to technical and non-technical audiences.
- Experience with a bug bounty or vulnerability disclosure platform such as HackerOne or Bugcrowd.
- Experience reviewing security reports, participating in capture-the-flag exercises, performing vulnerability research, or working with security tooling.
- Familiarity with CVE assignment, CNA processes, security advisories, or vulnerability databases.
- Basic scripting, log analysis, issue tracking, or data analysis experience is a plus.
- Experience writing technical documentation, customer communications, support responses, or operational procedures is a plus.
Team
GitLab Product Security Vulnerability Operations is a globally distributed team that helps ensure GitLab delivers secure applications customers can trust. Vulnerability Operations serves as a central point of contact for external security researchers and helps govern the policies, processes, and guidelines used to address vulnerabilities in GitLab’s supported products.
Team members collaborate across regions using documented processes, automation, and structured handoffs to support vulnerability resolution and ongoing operational improvements.
Salary
The United States base salary range for this role is $115,000–$150,000 USD. The range does not include bonuses, equity, or benefits. Salary ranges are determined based on factors including education, experience, knowledge, skills, abilities, internal equity, market data, and geographic location.
Benefits
- Benefits supporting health, finances, and well-being
- Flexible paid time off
- Team member resource groups
- Equity compensation and employee stock purchase plan
- Growth and development fund
- Parental leave
GitLab is an equal opportunity workplace and an affirmative action employer. All GitLab roles are remote, although some roles may have specific location-based eligibility requirements.