Cybersecurity
GitLab
GitLab, the all-remote DevSecOps platform company, is hiring an Intermediate Security Analyst for its Product Security Vulnerability Operations team. This is an early-career security role focused on triaging bug bounty reports and vulnerability disclosures, validating findings, coordinating with PSIRT engineers and development teams, and supporting the CVE assignment process. On GitLab's own Greenhouse board the position is posted for Remote, Canada and Remote, United States; GitLab notes the role is open across North America and particularly encourages applicants on the US West Coast or in British Columbia to extend Pacific time zone coverage. The role is fully remote. Base salary for US residents is listed at 115,000 to 150,000 USD, plus equity, stock purchase plan eligibility and performance incentives where applicable; Canadian compensation follows GitLab's local bands. Full-time employment. Freshness evidence: GitLab's Greenhouse individual job endpoint shows first_published 2026-09-24 12:03 ET with updated_at 2026-09-24 12:04 ET, confirmed directly.
4 more roles like this one.
Triage incoming security reports and vulnerability disclosures from bug bounty researchers and other sources. Validate findings, reproduce issues and assess impact. Coordinate with PSIRT engineers and development teams to drive remediation. Apply CVE, CVSS, CWE and OWASP frameworks in classification and scoring. Communicate professionally with external security researchers. Prepare CVE assignment information and draft customer-facing vulnerability communications. Maintain accurate records, monitor operational metrics and create procedural documentation. Participate in incident reviews and root cause analysis.
Early-career experience in cybersecurity, software engineering, IT or a related field; internships, coursework and lab work are acceptable. Foundational understanding of software vulnerabilities and security concepts. Familiarity with CVE, CVSS, CWE, the OWASP Top 10 and coordinated disclosure. Strong attention to detail and clear written and verbal communication. Preferred: experience with bug bounty platforms such as HackerOne or Bugcrowd, security report review, capture-the-flag participation, vulnerability research, CVE or CNA process familiarity, and scripting, log analysis or technical documentation skills. Based in the United States or Canada.
Marked skills have a short guide — click one to see what to learn.
Salary not disclosed
See roles like this one
A free account opens every listing on EnRoute Jobs, saves the ones worth keeping, and scores each against your skills.
Create a free accountAlready have one? Log in