About the company
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.
The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems.
Responsibilities
- Own the business outcomes for Secret Detection and Vulnerability Research, including adoption, expansion, competitive win rate, and revenue contribution. Bring a point of view on packaging and pricing, not just features.
- Set the strategy for the full secret lifecycle: prevention, detection, validation, revocation, and reporting across GitLab.com, Dedicated, and Self-Managed.
- Treat detection content as a product. Define how rules, advisories, and intelligence feeds are sourced, validated, versioned, and measured, and make quality visible to customers.
- Hold the line on detection quality. False positives are a product defect and you will own the metrics that prove precision is improving.
- Work at the level of the technology. Read the rule syntax, question the entropy heuristics, understand why a scanner missed something, and challenge engineering with informed alternatives.
- Use AI to compress the distance between question and answer. Pull your own data, prototype your own flows, synthesize research and competitive input yourself, and bring conclusions rather than requests for someone else to investigate.
- Build the case for where AI belongs in the product: triage, rule generation, remediation guidance, and reducing the human review burden per finding.
- Partner with engineering, security research, threat intelligence, Field, and GitLab's own Security team, who are one of your most demanding users.
- Communicate in writing, asynchronously, with enough precision that a distributed team can act without a meeting.
Requirements
- Domain depth in application security, vulnerability management, or security research. You have worked on or adjacent to scanners, detection content, threat intelligence, or SDLC security tooling and you know how these products actually get evaluated in a bake-off.
- Technical credibility sufficient to earn the respect of a security engineering team. You do not need to have written the scanner, but you should be able to reason about detection logic, data pipelines, CI integration, and the tradeoffs between coverage and noise.
- Commercial reasoning. You start from revenue mechanics, buyer motion, and competitive displacement, then work inward to product decisions. Candidates who reason only from feature lists outward are not a fit.
- Evidence of using AI as a force multiplier in your own work: research, analysis, data pulls, prototyping, drafting. Consuming a chat assistant occasionally is not the same as restructuring how you work.
- Judgment under ambiguity. You bring structured options and a recommendation instead of escalating an open question.
- Bias for clarity. You can take a noisy, technical, politically contested problem and produce one page that everyone can align on.