Intermediate Security Analyst, Vulnerability Operations (North America)

GitLab
Canada, United States
Workplace: RemoteFull timeUSD 115,000 - 150,000 annuallyFunction: CybersecuritySkills: ["Curiosity","Organization","Detail-oriented","Professional written communication","Verbal communication"]

Help protect customers by triaging bug bounty and vulnerability management reports, validating findings, and routing issues for assessment, remediation, and closure. Partner with PSIRT engineers and development teams to reproduce and clarify affected products and configurations. Support severity assessment with CVE/CVSS/CWE/OWASP terminology, prepare CVE numbering authority information, coordinate customer-facing security communications, and improve runbooks and operational metrics.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GitLab
GitLab
1 day ago

Intermediate Security Analyst, Vulnerability Operations (North America)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 17 hours agoStatus: Live

Job Summary

Help protect customers by triaging bug bounty and vulnerability management reports, validating findings, and routing issues for assessment, remediation, and closure. Partner with PSIRT engineers and development teams to reproduce and clarify affected products and configurations. Support severity assessment with CVE/CVSS/CWE/OWASP terminology, prepare CVE numbering authority information, coordinate customer-facing security communications, and improve runbooks and operational metrics.
Location: Canada, United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Triage incoming bug bounty reports by reviewing quality, validating findings, assessing impact, identifying duplicates, and routing to appropriate teams.
  • •Triage vulnerabilities from vulnerability management and track them through assessment, remediation, and closure.
  • •Partner with PSIRT engineers and development teams to gather technical details, reproduce issues, and clarify affected products, versions, and configurations.
  • •Support severity assessment using CVE, CVSS, CWE, and OWASP terminology and maintain accurate issue records and timelines.
  • •Draft and coordinate customer-facing communications and help coordinate CVE Numbering Authority activities, including acting as an acting CNA representative when needed.

Pay and Benefits

Salary: USD 115,000 - 150,000 annually
Perks:Paid LeaveEquityLearning BudgetParental Leave

Key Requirements

  • •Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related field.
  • •Foundational understanding of software vulnerabilities and security concepts, including web applications, APIs, and CI/CD environments.
  • •Familiarity with security terminology such as CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure.
  • •Strong attention to detail with the ability to organize and prioritize multiple reports or work items.
  • •Experience with a bug bounty or vulnerability disclosure platform such as HackerOne or Bugcrowd.
Experience:DevSecOpsProduct securityBug bountyVulnerability managementCoordinated vulnerability disclosure
Skills:CuriosityOrganizationDetail-orientedProfessional written communicationVerbal communication
Tech Stack:CVECVSSCWEOWASP Top 10OWASPHackerOneBugcrowdAPIsCI/CDAuthenticationAuthorization

Company Brief

GitLab
Provides a single application for the complete DevSecOps lifecycle, offering source code management, CI/CD, security, and collaboration tools to help teams deliver software faster and more securely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2011
WebsiteLinkedIn