GitLab logo
GitLab
Posted 10 days agoVerified live 2d ago

Intermediate Security Analyst, Vulnerability Operations (North America)

Brief overview

Remote
UndergradOr in progress
$115k–$150k/yrStated range
Vulnerability ManagementWeb Application SecurityAPI SecurityCI/CD SecurityAuthentication and AuthorizationCVSSCWEOWASP Top 10Coordinated Vulnerability DisclosureHackerOne or BugcrowdVulnerability ResearchCVE Assignment and CNA ProcessesOrganization and PrioritizationWritten and Verbal Communication

About the company

Open-core software company focused on an AI-powered DevSecOps platform.

Job description

Summary

GitLab is an intelligent orchestration platform for DevSecOps. The Security Analyst will support Product Security Vulnerability Operations by triaging security reports, coordinating vulnerability management activities, communicating with researchers and stakeholders, and improving vulnerability response processes.

Responsibilities

  • Triage incoming bug bounty reports, including reviewing report quality, validating findings, assessing potential impact, identifying duplicates, and routing reports to the appropriate teams
  • Triage vulnerabilities identified through vulnerability management activities and help track them through assessment, remediation, and closure
  • Work with PSIRT engineers and development teams to gather technical details, reproduce issues, and clarify affected products, versions, and configurations
  • Support severity assessment using frameworks and terminology such as CVE, CVSS, CWE, and OWASP
  • Communicate professionally and respectfully with security researchers participating in coordinated vulnerability disclosure and bug bounty programs
  • Support GitLab’s role as a CVE Numbering Authority by preparing information for CVE assignment, maintaining accurate records, and helping coordinate CVE-related activities
  • Represent GitLab as an acting CNA representative in CVE-related discussions and operations, escalating questions and coordinating with the appropriate internal and external stakeholders
  • Draft and coordinate customer-facing communications about security vulnerabilities, fixes, mitigations, and release information in partnership with PSIRT, Legal, Customer Success, Support, and Corporate Communications
  • Maintain accurate issue records, timelines, researcher communications, remediation status, and follow-up actions
  • Monitor queues and operational metrics to identify trends, aging items, recurring issues, and opportunities to improve response quality and consistency
  • Create and improve runbooks, procedures, templates, and other documentation that make vulnerability handling more efficient and transparent
  • Participate in incident handoffs, root cause analysis documentation, lessons-learned activities, and product security reviews
  • Build technical and operational expertise in PSIRT, bug bounty, vulnerability management, and coordinated vulnerability disclosure

Skills

  • Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related field. Relevant internships, coursework, labs, research, customer support, or practical security projects are welcome
  • Foundational understanding of software vulnerabilities and security concepts, including web applications, APIs, CI/CD environments, authentication, and authorization
  • Familiarity with security terminology such as CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure
  • Strong attention to detail and the ability to organize and prioritize multiple reports or work items
  • Clear written and verbal communication skills, with the ability to explain technical topics to both technical and non-technical audiences
  • Experience with a bug bounty or vulnerability disclosure platform such as HackerOne or Bugcrowd
  • Experience reviewing security reports, participating in capture-the-flag exercises, performing vulnerability research, or working with security tooling
  • Familiarity with CVE assignment, CNA processes, security advisories, or vulnerability databases
  • Nice to have: Basic scripting, log analysis, issue tracking, or data analysis experience; experience writing technical documentation, customer communications, support responses, or operational procedures

Qualifications

Must Haves

  • Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related field. Relevant internships, coursework, labs, research, customer support, or practical security projects are welcome
  • Foundational understanding of software vulnerabilities and security concepts, including web applications, APIs, CI/CD environments, authentication, and authorization
  • Familiarity with security terminology such as CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure
  • Strong attention to detail and the ability to organize and prioritize multiple reports or work items
  • Clear written and verbal communication skills, with the ability to explain technical topics to both technical and non-technical audiences
  • Experience with a bug bounty or vulnerability disclosure platform such as HackerOne or Bugcrowd
  • Experience reviewing security reports, participating in capture-the-flag exercises, performing vulnerability research, or working with security tooling
  • Familiarity with CVE assignment, CNA processes, security advisories, or vulnerability databases

Nice to Haves

  • Nice to have: Basic scripting, log analysis, issue tracking, or data analysis experience; experience writing technical documentation, customer communications, support responses, or operational procedures

Benefits

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave
  • All of our roles are remote

More jobs like this