# Intermediate Security Analyst, Vulnerability Operations (North America) at GitLab

- Company: GitLab
- What the company does: The intelligent orchestration platform for DevSecOps, enabling teams and agents to ship trusted software at enterprise scale. Backed by General Catalyst and Khosla.
- Company website: https://about.gitlab.com/
- Type: Startups
- Level: Analyst
- Location: Remote, Canada; Remote, United States
- Work setup: Remote
- Posted: 2026-09-24
- Apply by: 2026-11-08
- Apply: https://job-boards.greenhouse.io/gitlab/jobs/8821526002
- Page: https://www.1752.vc/careers/jobs/gitlab-intermediate-security-analyst-vulnerability-operations-north-america/

## About the role

As a Security Analyst on GitLab’s Product Security Vulnerability Operations team, you will help protect GitLab customers by triaging security reports, supporting vulnerability management operations, and coordinating clear communications with security researchers, customers, and internal teams.

## What they're looking for

- Triage incoming bug bounty reports, including reviewing report quality, validating findings, assessing potential impact, identifying duplicates, and routing reports to the appropriate teams
- Triage vulnerabilities identified through vulnerability management activities and help track them through assessment, remediation, and closure
- Work with PSIRT engineers and development teams to gather technical details, reproduce issues, and clarify affected products, versions, and configurations
- Support severity assessment using frameworks and terminology such as CVE, CVSS, CWE, and OWASP
- Communicate professionally and respectfully with security researchers participating in coordinated vulnerability disclosure and bug bounty programs
- Support GitLab’s role as a CVE Numbering Authority by preparing information for CVE assignment, maintaining accurate records, and helping coordinate CVE-related activities

Tags: Product Security
