InterviewHack.ai
Start free
Jobs / Gitlab

Intermediate Security Analyst, Vulnerability Operations (North America)

Gitlab·Remote, Canada; Remote, United StatesRemotemid

In short

  • →Analista de seguridad intermedio que gestiona reportes de vulnerabilidades y coordinación con investigadores.
  • →Trabajas diariamente con equipos técnicos, legales y de soporte para evaluar, priorizar y comunicar fallos de seguridad.
  • →Destacado: Representas a GitLab como CNA (Autoridad de Numeración de CVE) en discusiones clave.

Proficiency in written and spoken English is required.

Apply on company site ↗Share on WhatsApp

In ~1 minute you get: who interviews you, the likely questions answered from your CV, and your CV tailored to this job. Free, no card.

🎧Land the interview? Bring the copilot. Our free extension listens to the live interview and flashes 3-4-word anchors from your resume and prep — glance, connect, talk. Get the extension →

What they ask for

  • ✓Experiencia en análisis de vulnerabilidades o seguridad de productos.
  • ✓Conocimiento de frameworks como CVE, CVSS, CWE y OWASP.
  • ✓Habilidades de comunicación clara con investigadores de seguridad.
  • ✓Capacidad para triage de reportes, validación de hallazgos y eliminación de duplicados.
  • ✓Organización y atención al detalle en seguimiento de casos y plazos.
  • ✓Disponibilidad para trabajar en horarios que cubran el huso horario del Pacífico (EE.UU. o Canadá).

Don't tick every box? That's normal — your free dossier shows your gaps and how to cover them in the interview.

GitLabPSIRTCVECVSSCWEOWASPBug bounty programsCoordinated vulnerability discInternal ticketing systemsCross-functional collaboration

Who should you write to at Gitlab?

Your free dossier identifies the people who'd interview you — their background, what they value, and how to reach out so you stand out before applying.

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Security Analyst on GitLab’s Product Security Vulnerability Operations team, you will help protect GitLab customers by triaging security reports, supporting vulnerability management operations, and coordinating clear communications with security researchers, customers, and internal teams. You will work closely with PSIRT engineers, Vulnerability Management, Security Engineering, Legal, Customer Success, Support, and Communications. This role is an excellent opportunity for an early-career security prfessional who is curious, organized, detail-oriented, and excited to build expertise in product security response. This role is open to candidates across North America, though we encourage applications from those based on the West Coast US or West Coast Canada (British Columbia) as the team is looking to expand coverage in the Pacific Time Zone. What you’ll do • Triage incoming bug bounty reports, including reviewing report quality, validating findings, assessing potential impact, identifying duplicates, and routing reports to the appropriate teams. • Triage vulnerabilities identified through vulnerability management activities and help track them through assessment, remediation, and closure. • Work with PSIRT engineers and development teams to gather technical details, reproduce issues, and clarify affected products, versions, and configurations. • Support severity assessment using frameworks and terminology such as CVE, CVSS, CWE, and OWASP. • Communicate professionally and respectfully with security researchers participating in coordinated vulnerability disclosure and bug bounty programs. • Support GitLab’s role as a CVE Numbering Authority by preparing information for CVE assignment, maintaining accurate records, and helping coordinate CVE-related activities. • Represent GitLab as an acting CNA representative in CVE-related discussions and operations, escalating questions and coordinating with the appropriate internal and external stakeholders. • Draft and coordinate customer-facing communications about security vulnerabilities, fixes, mitigations, and release information in partnership with PSIRT, Legal, Customer Success, Support, and Corporate Communications. • Maintain accurate issue records, timelines, researcher communications, remediation status, and follow-up actions. • Monitor queues and operational metrics to identify tr

Looking for something similar?

Leave your email and we'll alert you when matching jobs appear.

Don't apply unprepared

We research who's interviewing you, tailor your CV and rehearse you live — first one free.

InterviewHack.ai

Prepare for the exact interview: who's interviewing you, a tailored CV, and a real coach.

Product

JobsCompanies hiringFree ATS checkerInterview-English checkSalary checkLATAM salary reportFree coursesBlogTailored CVSpoken practiceIt's free

Remote jobs

ReactPythonFull-StackLATAMArgentinaMexicoSee all →

Prepare

Spoken practiceFrontendBackendAI EngineerBy companySell with your CV

Company

For employersAboutContactPrivacyTerms

© 2026 InterviewHack.ai · Your CV is yours. Never used to train anything. · A product of IA-PTY

Similar open roles

Senior Frontend Engineer

Gitlab · Bangalore, India

→

Staff Software Engineer - NLP

Gitlab · Bangalore, India

→

Backend Engineer, Create: Repository Management

Gitlab · Remote, United Kingdom

→

Staff Frontend Engineer

Gitlab · Bangalore, India

→