Intermediate Security Analyst @GitLab
All Others
Salary usd 115,000 - 1..
Remote Location
Employment Type full-time
Posted 3d ago

[Hiring] Intermediate Security Analyst @GitLab

3d ago - GitLab is hiring a remote Intermediate Security Analyst. 💸 Salary: usd 115,000 - 150,000 per year 📍Location: Northern America

Role Description

As a Security Analyst on GitLab’s Product Security Vulnerability Operations team, you will help protect GitLab customers by:

  • Triage security reports
  • Support vulnerability management operations
  • Coordinate clear communications with security researchers, customers, and internal teams

This role is an excellent opportunity for an early-career security professional who is curious, organized, detail-oriented, and excited to build expertise in product security response.

This role is open to candidates across North America, with a preference for those based on the West Coast US or West Coast Canada (British Columbia).

What you’ll do

  • Triage incoming bug bounty reports, including:
    • Reviewing report quality
    • Validating findings
    • Assessing potential impact
    • Identifying duplicates
    • Routing reports to appropriate teams
  • Triage vulnerabilities identified through vulnerability management activities and help track them through assessment, remediation, and closure.
  • Work with PSIRT engineers and development teams to gather technical details, reproduce issues, and clarify affected products, versions, and configurations.
  • Support severity assessment using frameworks and terminology such as CVE, CVSS, CWE, and OWASP.
  • Communicate professionally and respectfully with security researchers participating in coordinated vulnerability disclosure and bug bounty programs.
  • Support GitLab’s role as a CVE Numbering Authority by:
    • Preparing information for CVE assignment
    • Maintaining accurate records
    • Helping coordinate CVE-related activities
  • Represent GitLab as an acting CNA representative in CVE-related discussions and operations.
  • Draft and coordinate customer-facing communications about security vulnerabilities, fixes, mitigations, and release information.
  • Maintain accurate issue records, timelines, researcher communications, remediation status, and follow-up actions.
  • Monitor queues and operational metrics to identify trends, aging items, recurring issues, and opportunities to improve response quality and consistency.
  • Create and improve runbooks, procedures, templates, and other documentation for efficient vulnerability handling.
  • Participate in incident handoffs, root cause analysis documentation, lessons-learned activities, and product security reviews.
  • Build technical and operational expertise in PSIRT, bug bounty, vulnerability management, and coordinated vulnerability disclosure.

Qualifications

  • Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related field.
  • Foundational understanding of software vulnerabilities and security concepts.
  • Familiarity with security terminology such as CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure.
  • Strong attention to detail and the ability to organize and prioritize multiple reports or work items.
  • Clear written and verbal communication skills.
  • Experience with a bug bounty or vulnerability disclosure platform such as HackerOne or Bugcrowd.
  • Experience reviewing security reports, participating in capture-the-flag exercises, performing vulnerability research, or working with security tooling.
  • Familiarity with CVE assignment, CNA processes, security advisories, or vulnerability databases.
  • Nice to have: Basic scripting, log analysis, issue tracking, or data analysis experience.

Benefits

  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave
Before You Apply
️
remote Be aware of the location restriction for this remote position: Northern America
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Intermediate Security Analyst @GitLab
All Others
Salary usd 115,000 - 1..
Remote Location
Employment Type full-time
Posted 3d ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 130,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Northern America
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 130,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 130,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 131,518+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later