Intermediate Software Engineer, Security Factory: Vulnerability Management
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI
Communication @ 3
ElasticSearch @ 3
JavaScript @ 3
PostgreSQL @ 3
Ruby @ 3
Ruby on Rails @ 3
Security @ 3
Swift
Vue.js @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
As an Intermediate Software Engineer on GitLab’s Vulnerability Management team, you’ll help build the core security workflows that GitLab Ultimate customers use to triage, prioritize, and act on vulnerabilities. You’ll work primarily in Ruby on Rails on backend systems, including security dashboards, vulnerability reports, and ingestion pipelines. You’ll take ownership of well-defined projects, solve technical problems with support from experienced team members, and collaborate with other engineers. You’ll also have opportunities to contribute beyond the backend when the work requires it.
You will join a full-stack team, working together with product managers, designers, and frontend engineers to solve problems across the Vulnerability Management domain.
Responsibilities
- Develop and maintain backend features for GitLab’s vulnerability management workflows.
- Ship features and improvements with minimal guidance and collaborate with the team on larger projects.
- Improve the performance, reliability, and scalability of security data ingestion and reporting systems.
- Collaborate with frontend engineers and contribute across the stack when needed.
- Work with engineers across security teams as vulnerability data and workflows come together in Vulnerability Management.
- Collaborate with Product Management and Product Design to maintain a high bar for quality.
- Craft code that meets GitLab’s internal standards for style, maintainability, and best practices for a high-scale web environment.
- Conduct code reviews and ensure community contributions receive a swift response.
- Recognize technical debt, propose solutions, and implement improvements.
- Participate in on-call rotations to assist with troubleshooting product operations, security operations, and urgent engineering issues.
- Incorporate AI into daily workflows as a productivity multiplier.
Requirements
- Experience building and maintaining backend applications with Ruby on Rails.
- Experience delivering and maintaining software systems as part of a larger engineering team.
- Ability to investigate technical problems, ask for context when needed, and work toward practical resolutions.
- Experience with relational databases such as PostgreSQL.
- Clear communication and collaboration skills in a distributed team.
- Interest in learning from others, sharing knowledge, and growing technical skills.
- Frontend development experience, including JavaScript or Vue.js, is helpful.
- Experience with Elasticsearch, graph databases, vulnerability management, application security, or related transferable skills is helpful.
About the Team
The Vulnerability Management team develops the core security workflows that help GitLab customers triage and manage vulnerabilities. The team owns the security dashboard, vulnerability reports, and ingestion pipelines, and serves as an important interface for security-related features across GitLab. The team is focused on moving beyond lists of findings toward workflows that help customers prioritize and coordinate remediation. You’ll collaborate asynchronously with a small, distributed group and with related security teams, including the Agentic Security Flows team.
Salary
The United States salary range for this role is $115,200–$172,800 USD per year. The range does not include bonuses, equity, or benefits.
Benefits
- Benefits supporting health, finances, and well-being
- Flexible paid time off
- Team Member Resource Groups
- Equity Compensation and Employee Stock Purchase Plan
- Growth and Development Fund
- Parental leave