GitLab logo
GitLabPosted 1 week ago

Senior Product Manager, Secret Detection and Vulnerability Research

RemoteUnited States

Full TimeSenior LevelLargeSoftware Platform

Job Summary

Own business outcomes for Secret Detection and Vulnerability Research, including adoption, expansion, win rate, and revenue. Set strategy for the full secret lifecycle: prevention, detection, validation, revocation, and reporting across GitLab.com, Dedicated, and Self-Managed. Treat detection content as a product by defining how rules, advisories, and intelligence feeds are sourced, validated, versioned, and measured. Hold the line on detection quality by owning metrics that prove precision is improving. Work at the technology level by reading rule syntax, questioning entropy heuristics, and challenging engineering with informed alternatives. Use AI to compress the distance between question and answer by pulling your own data, prototyping flows, and synthesizing research. Build the case for where AI belongs in the product for triage, rule generation, and reducing human review burden. Partner with engineering, security research, threat intelligence, Field, and GitLab's Security team. Communicate in writing, asynchronously, with enough precision that a distributed team can act without a meeting.

Required Qualifications

  • Domain depth in application security, vulnerability management, or security research
  • Experience with or adjacent to scanners, detection content, threat intelligence, or SDLC security tooling
  • Knowledge of how security products get evaluated in a bake-off
  • Technical credibility sufficient to earn the respect of a security engineering team
  • Ability to reason about detection logic, data pipelines, CI integration, and the tradeoffs between coverage and noise
  • Commercial reasoning starting from revenue mechanics, buyer motion, and competitive displacement
  • Evidence of using AI as a force multiplier in own work (research, analysis, data pulls, prototyping, drafting)
  • Judgment under ambiguity bringing structured options and a recommendation instead of escalating an open question
  • Bias for clarity to produce one page that everyone can align on on a noisy, technical, politically contested problem
  • Ability to communicate in writing, asynchronously, with enough precision that a distributed team can act without a meeting
  • Experience commercializing a data or intelligence asset

Desired Qualifications

  • Hands-on background as a developer, security engineer, red teamer, or researcher
  • Experience with credential and token ecosystems

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce