Intermediate Security Analyst, Vulnerability Operations

GitLab

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Canada
Salary
$115,000–$150,000 / yr
Posted
8 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $153k
This role $132k
$105k most similar roles pay here $198k

This role pays less than 69% of similar roles. Most pay $126,787–$178,912 — the shaded band above. At the midpoint, this role pays about $132k versus about $153k for comparable roles.

Based on 240 similar postings.

Employer

About GitLab

GitLab is an all-remote software company that develops an AI-powered DevSecOps platform combining source code management, CI/CD, security scanning, and project planning in a single application.

GitLab currently has 40 open roles on FindRole.

Listed pay typically runs $139,200–$235,200 across 34 roles with salary data.

Most-posted roles

View all roles at GitLab

At a glance

TL;DR · Intermediate Security Analyst, Vulnerability Operations

Intermediate Security Analyst, Vulnerability Operations joins the Product Security Vulnerability Operations team to protect customers by triaging security reports and managing vulnerability operations. This role involves triaging bug bounty reports, validating findings, assessing impact, and coordinating with internal teams like PSIRT, Legal, and Customer Success. You will manage vulnerabilities through assessment and remediation while acting as a representative in CVE-related discussions as a CNA. Key responsibilities include drafting customer-facing communications regarding security fixes and improving runbooks to enhance operational efficiency. The role requires knowledge of software vulnerabilities, web applications, APIs, CI/CD environments, and authentication. Candidates should be familiar with industry frameworks like CVE, CVSS, CWE, and OWASP Top 10. Experience with platforms like HackerOne or Bugcrowd is required to manage coordinated vulnerability disclosure and maintain accurate records for the product security lifecycle.

What you'll do

  • Triage bug bounty reports by validating findings, assessing impact, and routing them to appropriate teams.
  • Track vulnerabilities through the full lifecycle of assessment, remediation, and closure.
  • Collaborate with engineering teams to gather technical details and reproduce security issues.
  • Perform severity assessments using industry frameworks such as CVE, CVSS, CWE, and OWASP.
  • Manage GitLab’s role as a CVE Numbering Authority by preparing data for assignments and maintaining records.
  • Draft and coordinate customer-facing communications regarding security vulnerabilities, fixes, and mitigations.
  • Monitor operational metrics to identify trends, recurring issues, and opportunities for process improvement.
  • Create and update runbooks, procedures, and documentation to improve vulnerability handling efficiency.

What we're looking for

  • Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related field.
  • Foundational understanding of software vulnerabilities and security concepts including web applications, APIs, CI/CD environments, authentication, and authorization.
  • Familiarity with security terminology such as CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure.
  • Strong attention to detail and the ability to organize and prioritize multiple reports or work items.
  • Clear written and verbal communication skills for explaining technical topics to both technical and non-technical audiences.
  • Experience with a bug bounty or vulnerability disclosure platform such as HackerOne or Bugcrowd.
  • Experience reviewing security reports, participating in CTF exercises, performing vulnerability research, or working with security tooling.
  • Familiarity with CVE assignment, CNA processes, security advisories, or vulnerability databases; basic scripting, log analysis, and technical writing (preferred).

More like this

Similar roles

Lead InfoSec Engineer, Vulnerability Management

S&P Global

New York, NY 15 days ago $125,000–$145,000
Vulnerability Management SAST DAST Qualys Tanium Rapid7 Fortify Checkmarx Veracode Power BI Tableau NIST Cybersecurity Framework ISO 27001 CVE CVSS CWE AI/ML Risk Management
7+ yrs exp

Senior Associate, Threat and Vulnerability

Northern Trust

Chicago, IL 56 days ago
Vulnerability Management Threat Intelligence CVSS Zafran Qualys Azure AWS Cloud Security CTEM TTPs cyber security Security Operations Information Technology
3+ yrs exp

Senior Vulnerability Engineer

Anduril Industries

Boston, MA +2 7 days ago $191,000–$253,000
Vulnerability Research Reverse Engineering Fuzzing Python C C++ Rust Go Linux Embedded Systems Firmware Ghidra IDA Pro Binary Ninja QEMU Frida gdb lldb Hardware-in-the-loop RF Protocols

Head of Threat & Vulnerability Operations

State Street

Quincy, MA 59 days ago $120,000–$217,500
Vulnerability Management s as t Attack Surface Management Penetration Testing Bug Bounty Shift-Left risk-prioritization MTTR MTTD Cloud Security Data Analytics Reporting-as-a-Service
10+ yrs exp