gitlab
Intermediate Vulnerability Researcher, AST: Vulnerability Research
At a Glance
- Location
- Remote
- Work Regime
- remote
- Posted
- 2026-03-17T13:25:05-04:00
Key Requirements
Domain Knowledge
- Supply Chain
Requirements
Experience
developing or improving vulnerability detection capabilities in web security or a closely related area.
Knowledge
of the vulnerability management process and how research connects to product outcomes.
Understanding
of software composition analysis and software supply chain ecosystems.
Responsibilities
Carry out
vulnerability research and develop proof of concepts that inform GitLab security products and internal security efforts.
Curate
advisory databases for dependency scanning by reviewing, editing, and adding advisories while reducing repetitive manual work through automation.
Build
benchmarks that test the efficacy of scanning and detection products across supported security categories.
Team
The
Vulnerability Research
team at GitLab works closely with GitLab Security, Development, and Product to build, tune, and improve the efficacy of the security capabilities integrated into GitLab. We focus on practical research that strengthens detection quality, supports advisory content, and helps translate emerging vulnerability knowledge into product improvements across a distributed, asynchronous environment.
The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our
benefits
and