Senior PSIRT Security Engineer
Company
GitLab
Location
EMEA
Type
Full Time
Job Description
An overview of this role
The GitLab Product Security Incident Response Team (PSIRT) analyzes and validates reports of vulnerabilities in GitLab products and services collaborates with GitLab engineers and product teams to remediate and mitigate security vulnerabilities to protect customers and drives continuous security improvement through sharing insights and lessons learned. The PSIRT also manages GitLab's Coordinated Vulnerability Disclosure program.
What you'll do
-
Reproduce assess and document vulnerabilities perform variant hunting and contribute to exploitability research on security issues reported in GitLab’s products and services.
-
Support and consult with product and development teams on effective vulnerability remediation and mitigation.
-
Independently validate vulnerability fixes prior to release.
-
Support security release preparation activities.
-
Automate vulnerability triage related tasks collaborate to mature team processes and documentation
-
Participate in the vulnerability response lifecycle including coordinated vulnerability disclosure activities stakeholder communication and continuous improvement based on lessons learned from incidents.
-
Contribute to clear and actionable documentation that explains vulnerability impact risk and remediation guidance for technical and non-technical audiences helping to scale PSIRT knowledge and practices across GitLab.
What you’ll bring:
-
Demonstrated experience managing vulnerability triage remediation and disclosure in a software security context such as through a PSIRT bug bounty program or security response team.
-
Strong understanding and effective communication of code security and how to detect and remediate various classes of security defects and logic vulnerabilities.
-
Programming experience or scripting experience (Ruby Ruby on Rails TypeScript JavaScript and/or Go preferred) and an ability to read and understand code for fix validation and root cause analysis purposes.
-
Comfortable in shell scripting to automate recurring work or build PoC exploits
-
Experience performing Application Penetration Testing or Vulnerability Research / Bug Bounty Hunting. (Ability to discover and identify fixes for SQLi XSS CSRF SSRF authentication and authorization flaws and other web-based security vulnerabilities is a plus).
-
Understanding of common security vulnerabilities and security impact frameworks (e.g. OWASP Top 10 STRIDE) as well as common security frameworks and standards (CVE CWE CVSS etc).
-
Demonstrated ability to learn new technical concepts in cloud and web application security assessment.
-
Flexible effective and inclusive communication skills that create clarity; you will collaborate with technical and non-technical audiences across multiple teams on security bug types and how to mitigate or remediate security issues.
-
Demonstrated critical and creative thinking while also being an effective member of a team.
-
You’re comfortable using Git and have the ability to use GitLab effectively
-
Experience with standard web application security tools such as BurpSuite.
-
Flexible and constructive approach to problem solving that helps you navigate ambiguity and drive results.
-
Proficiency in the English language both written and verbal sufficient for success in a remote and largely asynchronous work environment
Date Posted
12/16/2025
Views
0
Similar Jobs
Senior Backend Engineer - Intents API - LI.FI
Views in the last 30 days - 0
LIFI is simplifying multichain DeFi for traditional institutions with a unified API for crosschain liquidity They seek a Senior Backend Engineer to bu...
View DetailsSenior DevOps Engineer - LI.FI
Views in the last 30 days - 0
LIFI is simplifying multichain DeFi for traditional institutions with a unified API seeking a senior DevOps engineer to enhance infrastructure The com...
View DetailsMid/Senior QA Engineer - Jumper - LI.FI
Views in the last 30 days - 0
Jumper promotes its mission to simplify multichain DeFi experiences highlighting its agile team 150k users and opportunities for QA engineers with com...
View DetailsIntermediate Site Reliability Engineer - Database Operations - GitLab
Views in the last 30 days - 0
This job description outlines a Site Reliability Engineer role focused on managing PostgreSQL infrastructure automation and scalability for GitLabs pl...
View DetailsSenior Jira Administrator - Canonical
Views in the last 30 days - 0
Canonical a leading opensource software provider is seeking a Jira Administrator to manage their Atlassian Jira Cloud platform The role involves autom...
View DetailsLead Golang Software Engineer - Commercial Systems - Canonical
Views in the last 30 days - 0
Canonical is a leading provider of opensource software and operating systems for global enterprise and technology markets The company is hiring a Lead...
View Details