Security Analyst protecting GitLab’s DevSecOps platform through vulnerability triage and CVE operations. Coordinating researchers, customers, and internal teams on secure software response.
Responsibilities
Triage incoming bug bounty reports by reviewing quality, validating findings, assessing impact, identifying duplicates, and routing reports
Triage vulnerabilities from vulnerability management activities and track them through assessment, remediation, and closure
Work with PSIRT engineers and development teams to gather technical details, reproduce issues, and clarify affected products, versions, and configurations
Support severity assessment using CVE, CVSS, CWE, and OWASP frameworks and terminology
Communicate with security researchers involved in coordinated vulnerability disclosure and bug bounty programs
Prepare information for CVE assignment and maintain accurate records as a CVE Numbering Authority
Represent GitLab as an acting CNA representative in CVE-related discussions and operations
Draft and coordinate customer-facing communications about vulnerabilities, fixes, mitigations, and releases
Monitor queues and operational metrics to identify trends, aging items, recurring issues, and improvement opportunities
Create and improve runbooks, procedures, templates, and documentation
Participate in incident handoffs, root cause analysis documentation, lessons-learned activities, and product security reviews
Build expertise in PSIRT, bug bounty, vulnerability management, and coordinated vulnerability disclosure
Requirements
Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related field
Foundational understanding of software vulnerabilities and security concepts, including web applications, APIs, CI/CD environments, authentication, and authorization
Familiarity with CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure
Strong attention to detail and ability to organize and prioritize multiple reports or work items
Clear written and verbal communication skills, with ability to explain technical topics to technical and non-technical audiences
Experience with a bug bounty or vulnerability disclosure platform such as HackerOne or Bugcrowd
Experience reviewing security reports, participating in capture-the-flag exercises, performing vulnerability research, or working with security tooling
Familiarity with CVE assignment, CNA processes, security advisories, or vulnerability databases
Basic scripting, log analysis, issue tracking, or data analysis experience is nice to have
Experience writing technical documentation, customer communications, support responses, or operational procedures is nice to have
Benefits
Benefits to support your health, finances, and well-being
Flexible Paid Time Off
Team Member Resource Groups
Equity Compensation & Employee Stock Purchase Plan
IT Security Analyst II coordinating cybersecurity monitoring, MSP oversight, audits, and incident follow - up. Supporting Veristat’s global life - sciences services and regulated technology environments.
SIEM/SOAR cybersecurity analyst monitoring threats, building alerts, and measuring controls. Supporting Wepoint’s digital transformation work for businesses and public sector organizations.
SIEM/SOAR information security analyst supporting Wepoint’s digital transformation services. Developing cybersecurity monitoring cases, alerts, dashboards, and security - control documentation.
Security Analyst II protecting Intact’s insurance operations through incident response and SIEM monitoring. Supporting security platforms, incident resolution, dashboards, and IT security initiatives.
Lead AI risk analyst securing CBC/Radio - Canada’s public - service media technology. Designing enterprise AI governance, risk assessments and adversarial testing across the AI lifecycle.
IT security analyst protecting Desjardins hardware, software, data, and access controls. Analyzing vulnerabilities, risks, and security processes while developing recommendations and action plans.