Intermediate Security Analyst, Vulnerability Operations

Posted 3 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Security Analyst protecting GitLab’s DevSecOps platform through vulnerability triage and CVE operations. Coordinating researchers, customers, and internal teams on secure software response.

Responsibilities

  • Triage incoming bug bounty reports by reviewing quality, validating findings, assessing impact, identifying duplicates, and routing reports
  • Triage vulnerabilities from vulnerability management activities and track them through assessment, remediation, and closure
  • Work with PSIRT engineers and development teams to gather technical details, reproduce issues, and clarify affected products, versions, and configurations
  • Support severity assessment using CVE, CVSS, CWE, and OWASP frameworks and terminology
  • Communicate with security researchers involved in coordinated vulnerability disclosure and bug bounty programs
  • Prepare information for CVE assignment and maintain accurate records as a CVE Numbering Authority
  • Represent GitLab as an acting CNA representative in CVE-related discussions and operations
  • Draft and coordinate customer-facing communications about vulnerabilities, fixes, mitigations, and releases
  • Maintain issue records, timelines, researcher communications, remediation status, and follow-up actions
  • Monitor queues and operational metrics to identify trends, aging items, recurring issues, and improvement opportunities
  • Create and improve runbooks, procedures, templates, and documentation
  • Participate in incident handoffs, root cause analysis documentation, lessons-learned activities, and product security reviews
  • Build expertise in PSIRT, bug bounty, vulnerability management, and coordinated vulnerability disclosure

Requirements

  • Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related field
  • Foundational understanding of software vulnerabilities and security concepts, including web applications, APIs, CI/CD environments, authentication, and authorization
  • Familiarity with CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure
  • Strong attention to detail and ability to organize and prioritize multiple reports or work items
  • Clear written and verbal communication skills, with ability to explain technical topics to technical and non-technical audiences
  • Experience with a bug bounty or vulnerability disclosure platform such as HackerOne or Bugcrowd
  • Experience reviewing security reports, participating in capture-the-flag exercises, performing vulnerability research, or working with security tooling
  • Familiarity with CVE assignment, CNA processes, security advisories, or vulnerability databases
  • Basic scripting, log analysis, issue tracking, or data analysis experience is nice to have
  • Experience writing technical documentation, customer communications, support responses, or operational procedures is nice to have

Benefits

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Job type

Full Time

Experience level

Mid levelSenior

Salary

$115,000 - $150,000 per year

Degree requirement

No Education Requirement

Tech skills

Cyber Security

Location requirements

RemoteUnited States

Report this job

Found something wrong with the page? Please let us know by submitting a report below.