Intermediate Security Analyst, Vulnerability Operations

atGitLabRemoteFull-timeSecurity AnalystMid-levelSenior$115k – $150k/year

Posted 2 days ago

This is a fully remote position, open to applicants in United States, +1 more country.

📋 Description

• Review and triage incoming bug bounty reports by assessing quality, validating findings, determining impact, identifying duplicates, and routing reports appropriately.

• Manage vulnerabilities arising from vulnerability management activities, tracking them through assessment, remediation, and closure stages.

• Collaborate with PSIRT engineers and development teams to gather technical information, reproduce issues, and clarify details regarding affected products, versions, and configurations.

• Assist in severity assessments utilizing CVE, CVSS, CWE, and OWASP frameworks and terminology.

• Engage with security researchers involved in coordinated vulnerability disclosure and bug bounty initiatives.

• Prepare documentation for CVE assignments and maintain precise records as a CVE Numbering Authority.

• Serve as a representative of GitLab in CVE-related discussions and operations as a CNA representative.

• Draft and coordinate communications directed towards customers regarding vulnerabilities, fixes, mitigations, and release information.

• Maintain detailed records of issues, timelines, communications with researchers, remediation status, and follow-up actions.

• Monitor operational queues and metrics to identify trends, aging items, recurring issues, and potential areas for improvement.

• Create and enhance runbooks, procedures, templates, and documentation.

• Participate in incident handoffs, root cause analysis documentation, lessons-learned sessions, and product security evaluations.

• Develop expertise in PSIRT, bug bounty programs, vulnerability management, and coordinated vulnerability disclosures.


⛳️ Requirements

• Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related discipline.

• Basic understanding of software vulnerabilities and security principles, including web applications, APIs, CI/CD environments, authentication, and authorization.

• Familiarity with CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure processes.

• Strong attention to detail with the capability to organize and prioritize multiple reports or tasks effectively.

• Excellent written and verbal communication skills, capable of explaining technical subjects to both technical and non-technical audiences.

• Experience with bug bounty or vulnerability disclosure platforms like HackerOne or Bugcrowd.

• Background in reviewing security reports, engaging in capture-the-flag exercises, conducting vulnerability research, or utilizing security tools.

• Knowledge of CVE assignment, CNA processes, security advisories, or vulnerability databases.

• Basic experience in scripting, log analysis, issue tracking, or data analysis is a plus.

• Experience in writing technical documentation, crafting customer communications, support responses, or operational procedures is also advantageous.


🏝️ Benefits

• Benefits designed to support your health, financial well-being, and overall wellness.

• Flexible Paid Time Off policy.

• Team Member Resource Groups for support and community.

• Equity Compensation & Employee Stock Purchase Plan for financial growth.

• Growth and Development Fund to foster professional advancement.

• Parental Leave to support family needs.

People also viewed

Vision Cybersecurity1 day ago

Network Cybersecurity Analyst

BR flagBrazil OnlyFull-timeSecurity Analyst
ApplyView job
Stefanini LATAM1 day ago

Analista de Seguridad de la Información – Gestión de Alertas DLP

CO flagColombia OnlyFull-timeSecurity Analyst
ApplyView job
Bancorbrás1 day ago

Security Analyst – Purple Team, Offensive and Defensive Security

BR flagBrazil OnlyFull-timeSecurity Analyst
ApplyView job
Kemper1 day ago

Application Security Analyst

US flagAlabama, +2 more statesFull-timeSecurity Analyst$93.5k – $155.5k/year
ApplyView job
Empeople Credit Union1 day ago

Information Security Analyst

US flagIllinois OnlyFull-timeSecurity Analyst$75.8k – $113.6k/year
ApplyView job
VC31 day ago

IT Security Analyst I – Evening Shift

US flagUnited States OnlyFull-timeSecurity Analyst
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers