Search Remote Jobs

Intermediate Security Analyst, Vulnerability Operations

🔥 2 minutes ago

🌐 United States, Canada – Remote

infoinfo

💵 $115k - $150k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔐 Security Analyst

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GitLab

GitLab

1001 - 5000 employees

Founded 2014

💼 Consulting

📣 Marketing

🤖 Artificial Intelligence

💰 Secondary Market on 2020-11

Consulting • Marketing • Artificial Intelligence

GitLab is the most comprehensive AI-powered DevSecOps platform, offering tools for automated software delivery, security, and compliance throughout the software development lifecycle. It provides solutions across areas such as AI-assisted development, continuous integration/continuous deployment (CI/CD), source code management, and vulnerability management. GitLab aims to simplify and accelerate software delivery by uniting development, security, and operations on a unified platform. It is particularly recognized for its AI code assistants and has been named a leader in the Gartner Magic Quadrant™ for DevOps Platforms, making it a preferred choice for many enterprises.

📋 Description

• Triage incoming bug bounty reports by reviewing quality, validating findings, assessing impact, identifying duplicates, and routing reports • Triage vulnerabilities from vulnerability management activities and track them through assessment, remediation, and closure • Work with PSIRT engineers and development teams to gather technical details, reproduce issues, and clarify affected products, versions, and configurations • Support severity assessment using CVE, CVSS, CWE, and OWASP frameworks and terminology • Communicate with security researchers involved in coordinated vulnerability disclosure and bug bounty programs • Prepare information for CVE assignment and maintain accurate records as a CVE Numbering Authority • Represent GitLab as an acting CNA representative in CVE-related discussions and operations • Draft and coordinate customer-facing communications about vulnerabilities, fixes, mitigations, and releases • Maintain issue records, timelines, researcher communications, remediation status, and follow-up actions • Monitor queues and operational metrics to identify trends, aging items, recurring issues, and improvement opportunities • Create and improve runbooks, procedures, templates, and documentation • Participate in incident handoffs, root cause analysis documentation, lessons-learned activities, and product security reviews • Build expertise in PSIRT, bug bounty, vulnerability management, and coordinated vulnerability disclosure

🎯 Requirements

• Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related field • Foundational understanding of software vulnerabilities and security concepts, including web applications, APIs, CI/CD environments, authentication, and authorization • Familiarity with CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure • Strong attention to detail and ability to organize and prioritize multiple reports or work items • Clear written and verbal communication skills, with ability to explain technical topics to technical and non-technical audiences • Experience with a bug bounty or vulnerability disclosure platform such as HackerOne or Bugcrowd • Experience reviewing security reports, participating in capture-the-flag exercises, performing vulnerability research, or working with security tooling • Familiarity with CVE assignment, CNA processes, security advisories, or vulnerability databases • Basic scripting, log analysis, issue tracking, or data analysis experience is nice to have • Experience writing technical documentation, customer communications, support responses, or operational procedures is nice to have

🏖️ Benefits

• Benefits to support your health, finances, and well-being • Flexible Paid Time Off • Team Member Resource Groups • Equity Compensation & Employee Stock Purchase Plan • Growth and Development Fund • Parental Leave

Apply Now

Similar Jobs

🔥 24 minutes ago

Leidos

10,000+ employees

🏥 Healthcare

💼 Consulting

📦 Logistics

Cybersecurity Analyst supporting Leidos’ U.S. information systems through RMF accreditation, security assessments, and authorization packages. Managing compliance, vulnerability remediation, and continuous monitoring.

🔥 5 hours ago

Constellation West

51 - 200

🔒 Cybersecurity

🏛️ Government

💼 Consulting

Software Security Analyst/Developer securing Java applications and managing vulnerability remediation. Constellation West delivers IT engineering services to U.S. government agencies.

🔥 18 hours ago

IT Coalition

501 - 1000

🔒 Cybersecurity

🏛️ Government

☁️ SaaS

Senior Security Analyst performing NIST security assessments, vulnerability analysis, and A&A documentation. Supporting government cybersecurity missions for NIST through ITC Federal.

🕒 Yesterday

Unisys

10,000+ employees

💼 Consulting

📦 Logistics

🤖 Artificial Intelligence

Cybersecurity Analyst monitoring security events, investigating incidents, and assessing cybersecurity risks for Unisys. Maintaining network security documentation and responding to customer inquiries.

🕒 2 days ago

Cognyte

1001 - 5000

🔒 Cybersecurity

🔐 Security

🏛️ Government

Threat Intelligence Analyst researching cyber threats across open, deep, and dark web sources. Supporting Cognyte’s investigative solutions for law enforcement and national security customers.