Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
GitLab

Intermediate Security Analyst, Vulnerability Operations

GitLab

. Triage incoming bug bounty reports by reviewing quality, validating findings, assessing impact, identifying duplicates, and routing reports .

Posted 9/24/2026full-timeRemote • United States, CanadaMid-LevelSenior💰 $115,000 - $150,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates foundational understanding of cybersecurity principles, software vulnerabilities, and security concepts, with experience in vulnerability management and coordinated vulnerability disclosure. Proficient in communicating technical information clearly to diverse audiences and managing multiple reports effectively.

Highest-signal resume keywords
Vulnerability ManagementCVE AssignmentBug Bounty PlatformsSecurity Report ReviewTechnical Documentation

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Software VulnerabilitiesSecurity ConceptsWeb ApplicationsAPIsCI/CD EnvironmentsAuthenticationAuthorizationScriptingLog AnalysisData Analysis
Soft Skills
Attention to DetailOrganizational SkillsClear Communication
Tools & Technologies
HackerOneBugcrowd
Industry Keywords
CVECVSSCWEOWASP Top 10Coordinated Vulnerability Disclosure

Tech Stack

Tools & technologies
Cyber Security

About the role

Key responsibilities & impact
  • Triage incoming bug bounty reports by reviewing quality, validating findings, assessing impact, identifying duplicates, and routing reports
  • Triage vulnerabilities from vulnerability management activities and track them through assessment, remediation, and closure
  • Work with PSIRT engineers and development teams to gather technical details, reproduce issues, and clarify affected products, versions, and configurations
  • Support severity assessment using CVE, CVSS, CWE, and OWASP frameworks and terminology
  • Communicate with security researchers involved in coordinated vulnerability disclosure and bug bounty programs
  • Prepare information for CVE assignment and maintain accurate records as a CVE Numbering Authority
  • Represent GitLab as an acting CNA representative in CVE-related discussions and operations
  • Draft and coordinate customer-facing communications about vulnerabilities, fixes, mitigations, and releases
  • Maintain issue records, timelines, researcher communications, remediation status, and follow-up actions
  • Monitor queues and operational metrics to identify trends, aging items, recurring issues, and improvement opportunities
  • Create and improve runbooks, procedures, templates, and documentation
  • Participate in incident handoffs, root cause analysis documentation, lessons-learned activities, and product security reviews
  • Build expertise in PSIRT, bug bounty, vulnerability management, and coordinated vulnerability disclosure

Requirements

What you’ll need
  • Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related field
  • Foundational understanding of software vulnerabilities and security concepts, including web applications, APIs, CI/CD environments, authentication, and authorization
  • Familiarity with CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure
  • Strong attention to detail and ability to organize and prioritize multiple reports or work items
  • Clear written and verbal communication skills, with ability to explain technical topics to technical and non-technical audiences
  • Experience with a bug bounty or vulnerability disclosure platform such as HackerOne or Bugcrowd
  • Experience reviewing security reports, participating in capture-the-flag exercises, performing vulnerability research, or working with security tooling
  • Familiarity with CVE assignment, CNA processes, security advisories, or vulnerability databases
  • Basic scripting, log analysis, issue tracking, or data analysis experience is nice to have
  • Experience writing technical documentation, customer communications, support responses, or operational procedures is nice to have

Benefits

Comp & perks
  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave