Intermediate Security Analyst, Vulnerability Operations (North America)
GitLab · Product Security
- Pay
- $115,000–$150,000/yr
- Where
- Remote, Canada; Remote, United States
- Posted
- Today
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.
The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued.
What you'd do
- Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related field.
- Relevant internships, coursework, labs, research, customer support, or practical security projects are welcome.
- Foundational understanding of software vulnerabilities and security concepts, including web applications, APIs, CI/CD environments, authentication, and authorization.
- Familiarity with security terminology such as CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure.
- Strong attention to detail and the ability to organize and prioritize multiple reports or work items.
- Clear written and verbal communication skills, with the ability to explain technical topics to both technical and non-technical audiences.
- Experience with a bug bounty or vulnerability disclosure platform such as HackerOne or Bugcrowd.
- Experience reviewing security reports, participating in capture-the-flag exercises, performing vulnerability research, or working with security tooling.
- Familiarity with CVE assignment, CNA processes, security advisories, or vulnerability databases.
- Nice to have: Basic scripting, log analysis, issue tracking, or data analysis experience; experience writing technical documentation, customer communications, support responses, or operational procedures.
- Benefits to support your health, finances, and well-being
About GitLab · Product Security
The GitLab Product Security Vulnerability Operations is a globally distributed team that helps ensure GitLab delivers secure applications customers can trust. VulnOps serves as a central point of contact for external security researchers and helps govern the policies, processes, and guidelines used to address vulnerabilities in GitLab’s supported products. Team members collaborate across regions using documented processes, automation, and structured handoffs to support vulnerability resolution…