Skip to main content
GitLab

Senior Product Manager, Secret Detection and Vulnerability Research

RemoteUnited States only
Published
Role
Product
Experience
Senior
Employment
Full-time
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior product manager for Secret Detection and Vulnerability Research owning detection content and full secret lifecycle. Must have domain depth in application security/vulnerability management and technical credibility to work with security engineering. Remote role hiring in the United States (US eligibility signal).

Core skills

Secret Detection

Required skills

application securityvulnerability managementsecurity researchdetection contentthreat intelligencedata pipelinesCI integrationAI for product/automation

Optional skills

developer experience (hands-on background)security engineeringred teamingcredential and token ecosystemscommercializing data or intelligence assets

What you'll do

  • Own the business outcomes for Secret Detection and Vulnerability Research, including adoption, expansion, competitive win rate, and revenue contribution.
  • Bring a point of view on packaging and pricing, not just features.
  • Set the strategy for the full secret lifecycle: prevention, detection, validation, revocation, and reporting across GitLab.com, Dedicated, and Self-Managed.
  • Treat detection content as a product and define how rules, advisories, and intelligence feeds are sourced, validated, versioned, and measured.
  • Hold the line on detection quality and own precision metrics to reduce false positives.
  • Work at the technical level: read rule syntax, question heuristics, understand scanner misses, and propose informed engineering alternatives.
  • Use AI to improve workflows: triage, rule generation, remediation guidance, and reduce human review burden.
  • Pull data, prototype flows, synthesize research and competitive input, and present conclusions rather than requests.
  • Partner with engineering, security research, threat intelligence, Field, and GitLab's Security team.
  • Communicate in writing asynchronously with enough precision for distributed teams to act without meetings.

What they require

  • Domain depth in application security, vulnerability management, or security research.
  • Experience with scanners, detection content, threat intelligence, or SDLC security tooling and understanding how these products are evaluated.
  • Technical credibility to reason about detection logic, data pipelines, CI integration, and tradeoffs between coverage and noise.
  • Commercial reasoning starting from revenue mechanics, buyer motion, and competitive displacement.
  • Evidence of using AI as a force multiplier in work (research, analysis, data pulls, prototyping, drafting).
  • Judgment under ambiguity and ability to bring structured options with recommendations.
  • Bias for clarity and ability to produce concise alignment artifacts for noisy technical problems.

Benefits

  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave
  • Support for health, finances, and well-being

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100 trust GitLab to ship better, more secure software faster.

🇺🇸 United StatesSoftwareEnterpriseabout.gitlab.com/

What people say about this company

3.3/ 5

  • Flexible remote work options are highly valued by employees.
  • Many employees appreciate the open-source nature of the product and the company's commitment to transparency.
  • Some employees report challenges with management and communication within teams.
Salary not disclosed