gitlab

Intermediate Vulnerability Researcher, AST: Vulnerability Research

Apply Now

At a Glance

Location
Remote
Work Regime
remote
Posted
2026-03-17T13:25:05-04:00

Key Requirements

Domain Knowledge

  • Supply Chain

Requirements

Experience

developing or improving vulnerability detection capabilities in web security or a closely related area.

Knowledge

of the vulnerability management process and how research connects to product outcomes.

Understanding

of software composition analysis and software supply chain ecosystems.

Responsibilities

Carry out

vulnerability research and develop proof of concepts that inform GitLab security products and internal security efforts.

Curate

advisory databases for dependency scanning by reviewing, editing, and adding advisories while reducing repetitive manual work through automation.

Build

benchmarks that test the efficacy of scanning and detection products across supported security categories.

Team

The

Vulnerability Research

team at GitLab works closely with GitLab Security, Development, and Product to build, tune, and improve the efficacy of the security capabilities integrated into GitLab. We focus on practical research that strengthens detection quality, supports advisory content, and helps translate emerging vulnerability knowledge into product improvements across a distributed, asynchronous environment.

The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our

benefits

and