A live role

Intermediate Security Analyst, Vulnerability Operations (North America)

from GitLab · read the original and apply on their site

Remote, Canada; Remote, United States

Our take: The real work here is triaging security vulnerability reports, judging their impact, and coordinating clear communication so GitLab customers stay protected.

If you love the detective work of a security report landing in the queue, working out whether it is real, how bad it is, and who needs to know, this role is built for you. You will grow real product security expertise while coordinating clear, respectful communication between researchers, customers, and internal teams, all within a distributed team that runs on documented process and shared knowledge. It suits an early-career, curious, deeply organized person who wants their careful work to protect real customers.

Needs

  • evaluating evidence
  • reproducing issues
  • writing documentation
  • drafting communications
  • careful diplomacy

Rewards

  • spotting trends
  • visible customer impact
  • learning new domains
  • incident response
  • improving process

Demands

  • ruthless prioritising
  • cross-team coordination
  • governance and compliance
  • managing risk

Grows

  • learning security domains
  • frameworks and scoring
  • quality reviews

Values

  • rigour
  • transparency
  • user obsession
  • defined process
  • remote working

Drains

  • record-keeping upkeep
  • queue monitoring

Would you love this work?

See how what you love doing lines up with this role - it takes about ten minutes to find out.

Find what I'd love to do next