- Company Name
- GitLab
- Job Title
- Senior PSIRT Security Engineer, EMEA
- Job Description
-
Job title: Senior PSIRT Security Engineer, EMEA
Role Summary: Lead product security incident response for GitLab’s platform, analyzing, validating, and remediating vulnerabilities, managing coordinated disclosure, and driving continuous security improvements across product and development teams.
Expectations: 5+ years in vulnerability triage, remediation, and disclosure (PSIRT, bug bounty, or similar). Advanced knowledge of code security, vulnerability identification (SQLi, XSS, CSRF, SSRF, authentication/authorization flaws), and common frameworks (OWASP Top 10, STRIDE, CVE, CWE, CVSS). Proficient in scripting (Ruby, Ruby on Rails, TypeScript, JavaScript, Go, or shell). Experience with application penetration testing and bug‑bounty hunting. Strong communication skills, ability to explain technical findings to diverse audiences, and fluency in English for remote collaboration.
Key Responsibilities:
- Reproduce, assess, and document vulnerabilities, including variant hunting and exploit research.
- Consult with product and engineering teams on remediation strategies and mitigation techniques.
- Validate security fixes independently before release and support release‑preparation activities.
- Automate vulnerability triage tasks and collaborate to refine PSIRT processes and documentation.
- Manage the coordinated vulnerability disclosure program, ensuring timely and responsible communications with external stakeholders.
Required Skills:
- Vulnerability triage, remediation, and disclosure management.
- Deep code‑level understanding of security defects and logic vulnerabilities.
- Application penetration testing and vulnerability research (web‑application security).
- Programming and scripting proficiency: Ruby, TypeScript, JavaScript, Go, shell scripting.
- Familiarity with security tools: BurpSuite, standard web‑app scanners.
- Git and GitLab usage.
- Knowledge of security frameworks and standards (OWASP, STRIDE, CVE, CWE, CVSS).
- Strong analytical, critical, and creative thinking.
- Effective written and verbal communication in English.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Relevant security certifications (e.g., CEH, OSCP, GIAC) preferred but not mandatory.