
Intermediate Security Analyst, Vulnerability Operations
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States, +1 more country.
• Review and triage incoming bug bounty reports by assessing quality, validating findings, determining impact, identifying duplicates, and routing reports appropriately.
• Manage vulnerabilities arising from vulnerability management activities, tracking them through assessment, remediation, and closure stages.
• Collaborate with PSIRT engineers and development teams to gather technical information, reproduce issues, and clarify details regarding affected products, versions, and configurations.
• Assist in severity assessments utilizing CVE, CVSS, CWE, and OWASP frameworks and terminology.
• Engage with security researchers involved in coordinated vulnerability disclosure and bug bounty initiatives.
• Prepare documentation for CVE assignments and maintain precise records as a CVE Numbering Authority.
• Serve as a representative of GitLab in CVE-related discussions and operations as a CNA representative.
• Draft and coordinate communications directed towards customers regarding vulnerabilities, fixes, mitigations, and release information.
• Maintain detailed records of issues, timelines, communications with researchers, remediation status, and follow-up actions.
• Monitor operational queues and metrics to identify trends, aging items, recurring issues, and potential areas for improvement.
• Create and enhance runbooks, procedures, templates, and documentation.
• Participate in incident handoffs, root cause analysis documentation, lessons-learned sessions, and product security evaluations.
• Develop expertise in PSIRT, bug bounty programs, vulnerability management, and coordinated vulnerability disclosures.
• Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related discipline.
• Basic understanding of software vulnerabilities and security principles, including web applications, APIs, CI/CD environments, authentication, and authorization.
• Familiarity with CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure processes.
• Strong attention to detail with the capability to organize and prioritize multiple reports or tasks effectively.
• Excellent written and verbal communication skills, capable of explaining technical subjects to both technical and non-technical audiences.
• Experience with bug bounty or vulnerability disclosure platforms like HackerOne or Bugcrowd.
• Background in reviewing security reports, engaging in capture-the-flag exercises, conducting vulnerability research, or utilizing security tools.
• Knowledge of CVE assignment, CNA processes, security advisories, or vulnerability databases.
• Basic experience in scripting, log analysis, issue tracking, or data analysis is a plus.
• Experience in writing technical documentation, crafting customer communications, support responses, or operational procedures is also advantageous.
• Benefits designed to support your health, financial well-being, and overall wellness.
• Flexible Paid Time Off policy.
• Team Member Resource Groups for support and community.
• Equity Compensation & Employee Stock Purchase Plan for financial growth.
• Growth and Development Fund to foster professional advancement.
• Parental Leave to support family needs.
Vision Cybersecurity
Stefanini LATAM
Bancorbrás
Kemper
Get handpicked remote jobs straight to your inbox weekly.