Full-Time

Intermediate Vulnerability Research Engineer

Application Security Testing: Vulnerability Research

Confirmed live in the last 24 hours

GitLab

GitLab

1,001-5,000 employees

Unified DevOps platform for software development

Consulting
Enterprise Software

Compensation Overview

$98k - $210kAnnually

Mid

Remote in USA

Candidates must be based in California, Colorado, Hawaii, New Jersey, New York, Washington, DC, Illinois, or Minnesota.

Category
Cybersecurity
IT & Security

You match the following GitLab's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • 3+ years of direct experience in developing and improving vulnerability detection products in the context of web security.
  • Knowledge of the vulnerability management process.
  • Knowledge of software composition analysis (SCA) and software supply chain ecosystems.
  • Experience with source code analysis, static application security testing (SAST), and dynamic application security testing (DAST) along with benchmarking experience testing the efficacy of these products.
  • Knowledge about compilers, compiler design and construction.
  • Experience developing automated web security testing/analysis tools.
  • Experience in product development.
  • You have a passion for security and open source, and enjoy collaborating with cross-functional teams.
Responsibilities
  • Carry out research and come up with proofs of concepts that affect the security products and GitLab, including SAST, DAST, Secret Detection and Composition Analysis.
  • Curate advisory databases for dependency scanning. This is a semi-automatic task that includes auditing/reviewing, editing existing and adding new advisories to the database while, at the same time, trying to automate repetitive tasks away as much as possible.
  • Build/develop benchmarks to test the efficacy of scanning and detection products to constantly improve quality of results.
  • Measure and Improve the efficacy of scanning and detection products over time.
  • Write detailed technical reports.
  • Assess security product output results and conduct root cause analysis to improve efficacy.
  • Respond to internal and external customer inquiries on vulnerabilities and related topics.

GitLab provides a DevOps platform that simplifies software development by integrating various tools into a single application. This platform enhances collaboration and visibility, allowing teams to focus on improving their products instead of managing multiple tools. GitLab operates on a subscription-based model, offering features for continuous integration and deployment, and regularly updates its platform to ensure ongoing value for clients. The company's goal is to streamline the software development process for a diverse range of industries.

Company Stage

IPO

Total Funding

$421.8M

Headquarters

San Francisco, California

Founded

2014

Growth & Insights
Headcount

6 month growth

0%

1 year growth

1%

2 year growth

-2%
Simplify Jobs

Simplify's Take

What believers are saying

  • Acquiring Oxeye enhances GitLab's cloud security, appealing to security-conscious enterprises.
  • Partnership with Ooredoo Kuwait expands GitLab's influence in the telecommunications sector.
  • Potential sale to Datadog could create strategic synergies and expand market reach.

What critics are saying

  • AI-powered coding assistants like Claude pose a competitive threat to GitLab's platform.
  • Potential sale to Datadog may lead to strategic shifts misaligned with customer expectations.
  • Integration of Oxeye may distract from GitLab's core DevOps offerings.

What makes GitLab unique

  • GitLab offers a unified DevOps platform, reducing complexity in software development.
  • The platform integrates tools for collaboration, visibility, and speed, enhancing development processes.
  • GitLab's open-source model fosters continuous innovation with a large developer community.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Spending Company Money

Equity Compensation

Life Insurance

Financial Wellness

Paid Time Off

Growth and Development Benefit

GitLab Contribute

Business Travel Accident Policy

Immigration

Employee Assistance Program

Incentives

All-Remote

Part-time contracts

Meal Train

Fertility & Family Planning

Parental Leave