Full-Time

Intermediate Vulnerability Research Engineer

Application Security Testing: Vulnerability Research

Confirmed live in the last 24 hours

GitLab

GitLab

1,001-5,000 employees

Unified DevOps platform for software development

Data & Analytics
Enterprise Software

Compensation Overview

$98k - $210kAnnually

Mid

Remote in USA

Category
Cybersecurity
IT & Security
Requirements
  • 3+ years of direct experience in developing and improving vulnerability detection products in the context of web security.
  • Knowledge of the vulnerability management process.
  • Knowledge of software composition analysis (SCA) and software supply chain ecosystems.
  • Experience with source code analysis, static application security testing (SAST), and dynamic application security testing (DAST) along with benchmarking experience testing the efficacy of these products.
  • Knowledge about compilers, compiler design and construction.
  • Experience developing automated web security testing/analysis tools.
  • Experience in product development.
  • You have a passion for security and open source, and enjoy collaborating with cross-functional teams.
Responsibilities
  • Carry out research and come up with proofs of concepts that affect the security products and GitLab, including SAST, DAST, Secret Detection and Composition Analysis.
  • Curate advisory databases for dependency scanning. This is a semi-automatic task that includes auditing/reviewing, editing existing and adding new advisories to the database while, at the same time, trying to automate repetitive tasks away as much as possible.
  • Build/develop benchmarks to test the efficacy of scanning and detection products to constantly improve quality of results.
  • Measure and Improve the efficacy of scanning and detection products over time.
  • Write detailed technical reports.
  • Assess security product output results and conduct root cause analysis to improve efficacy.
  • Respond to internal and external customer inquiries on vulnerabilities and related topics.

GitLab provides a DevOps platform that streamlines software development by integrating various tools into a single application. This integration enhances collaboration and visibility, allowing teams to focus on product improvement rather than managing multiple tools. GitLab operates on a subscription-based model, offering features for continuous integration and deployment, and serves a diverse range of clients across various industries. The company's goal is to simplify the software development process and deliver ongoing value through regular updates and customization options.

Company Stage

IPO

Total Funding

$421.8M

Headquarters

San Francisco, California

Founded

2014

Growth & Insights
Headcount

6 month growth

5%

1 year growth

24%

2 year growth

24%
Simplify Jobs

Simplify's Take

What believers are saying

  • GitLab's potential acquisition by Datadog could significantly enhance its cloud app offerings and market reach.
  • The acquisition of Oxeye for $30-40 million strengthens GitLab's cloud security capabilities, making it a more robust platform for clients.
  • Strategic partnerships, such as with Ooredoo Kuwait and Quokka, demonstrate GitLab's commitment to enhancing its platform's security and efficiency, which can attract more clients.

What critics are saying

  • The potential sale to Datadog introduces uncertainty, which could affect employee morale and client confidence.
  • The competitive DevOps market requires GitLab to continuously innovate to maintain its edge, which can be resource-intensive.

What makes GitLab unique

  • GitLab offers a unified DevOps platform that integrates various tools required for software development, reducing the complexity of managing multiple toolchains, unlike competitors who may offer fragmented solutions.
  • The platform's versatility is demonstrated by its diverse client base, including major corporations across various industries, which is a testament to its broad appeal and adaptability.
  • GitLab's continuous updates and new feature rollouts ensure that clients receive ongoing value from their subscriptions, setting it apart from competitors with less frequent updates.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Spending Company Money

Equity Compensation

Life Insurance

Financial Wellness

Paid Time Off

Growth and Development Benefit

GitLab Contribute

Business Travel Accident Policy

Immigration

Employee Assistance Program

Incentives

All-Remote

Part-time contracts

Meal Train

Fertility & Family Planning

Parental Leave