Senior Product Manager, Secret Detection and Vulnerability Research

Other Jobs To Apply

<strong>An overview of this role</strong><br/><br/>As a <strong>Senior Product Manager</strong>, you will own GitLab's Secret Detection offering and the Vulnerability Research function that produces the detection content across security products. Secret Detection is one of the highest-signal, highest-volume security capabilities on the platform. Leaked credentials are the most common initial access vector in real breaches, and as AI agents write, commit, and configure more of the software, the surface area for exposed secrets grows faster than the number of humans watching it.<br/><br/>You will own the full loop: detect a secret with high precision, tell the customer whether it is still live, get it revoked, and prevent the next one from ever landing. In parallel, you will own vulnerability research as a product asset rather than a back-office function. The detection rules, advisory data, and malicious package and reference intelligence your team produces are what make GitLab's security scanners worth paying for, and they need to ship on a cadence with measurable quality.<br/><br/>This is an outcome-owning role - you will carry adoption, retention, and revenue targets for your area and be expected to explain how your roadmap moves them.<br/><br/><strong>Some examples of our projects:</strong><br/><ul><li>Push protection and pre-receive blocking that stops a credential before it reaches a repository, without wrecking developer flow</li><li>Secret validity checking and automated revocation partnerships with major cloud and SaaS token issuers</li><li>Detection content pipelines that turn threat research into shipped rules, with precision and recall tracked per rule</li><li>Intelligence-driven detection of malicious packages, dependencies, and references entering the software supply chain</li></ul><strong>What you'll do</strong><br/><ul><li><strong>Own</strong> the business outcomes for Secret Detection and Vulnerability Research, including adoption, expansion, competitive win rate, and revenue contribution. Bring a point of view on packaging and pricing, not just features.</li><li><strong>Set</strong> the strategy for the full secret lifecycle: prevention, detection, validation, revocation, and reporting across GitLab.com, Dedicated, and Self-Managed.</li><li><strong>Treat</strong> detection content as a product. Define how rules, advisories, and intelligence feeds are sourced, validated, versioned, and measured, and make quality visible to customers.</li><li><strong>Hold</strong> the line on detection quality. False positives are a product defect and you will own the metrics that prove precision is improving.</li><li><strong>Work</strong> at the level of the technology. Read the rule syntax, question the entropy heuristics, understand why a scanner missed something, and challenge engineering with informed alternatives.</li><li><strong>Use</strong> AI to compress the distance between question and answer. Pull your own data, prototype your own flows, synthesize research and competitive input yourself, and bring conclusions rather than requests for someone else to investigate.</li><li><strong>Build</strong> the case for where AI belongs in the product: triage, rule generation, remediation guidance, and reducing the human review burden per finding.</li><li><strong>Partner</strong> with engineering, security research, threat intelligence, Field, and GitLab's own Security team, who are one of your most demanding users.</li><li><strong>Communicate</strong> in writing, asynchronously, with enough precision that a distributed team can act without a meeting.</li></ul><strong>What you'll bring</strong><br/><ul><li><strong>Domain depth</strong> in application security, vulnerability management, or security research. You have worked on or adjacent to scanners, detection content, threat intelligence, or SDLC security tooling and you know how these products actually get evaluated in a bake-off.</li><li><strong>Technical credibility</strong> sufficient to earn the respect of a security engineering team. You do not need to have written the scanner, but you should be able to reason about detection logic, data pipelines, CI integration, and the tradeoffs between coverage and noise.</li><li><strong>Commercial reasoning.</strong> You start from revenue mechanics, buyer motion, and competitive displacement, then work inward to product decisions. Candidates who reason only from feature lists outward are not a fit.</li><li><strong>Evidence of using AI as a force multiplier</strong> in your own work: research, analysis, data pulls, prototyping, drafting. Consuming a chat assistant occasionally is not the same as restructuring how you work.</li><li><strong>Judgment under ambiguity.</strong> You bring structured options and a recommendation instead of escalating an open question.</li><li><strong>Bias for clarity.</strong> You can take a noisy, technical, politically contested problem and produce one page that everyone can align on.</li><li><strong>Bonus:</strong> hands-on background as a developer, security engineer, red teamer, or researcher; experience with credential and token ecosystems; experience commercializing a data or intelligence asset.</li></ul><strong>About the team</strong><br/><br/>This role sits in GitLab's Security product management organization, which owns application security testing, vulnerability management, supply chain security, secrets management, and AI governance. The Security Section is central to GitLab's Ultimate tier and to the shift toward consumption-based product revenue, so the work is visible to senior leadership and directly tied to company results. You will work asynchronously with engineering, design, and research counterparts across multiple regions, and with the Field teams who take this to market.<br/><br/><strong><strong>How GitLab Supports Full-Time Employees</strong></strong><br/><ul><li>Benefits to support your health, finances, and well-being</li><li>Flexible Paid Time Off </li><li>Team Member Resource Groups</li><li>Equity Compensation & Employee Stock Purchase Plan</li><li>Growth and Development Fund</li><li>Parental Leave </li></ul><br/>Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.<br/><br/><strong>Country Hiring Guidelines: </strong>GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process. <br/><br/><strong>Privacy Policy: </strong>Please review our Recruitment Privacy Policy. Your privacy is important to us.

Back to blog

Other Jobs To Apply

Offensive Security Researcher

Customer Service and Sales Representative – Remote in CT, NH, ME

Calling All Stay-at-Home Parents

Ways to Make Money From Home

Paid Product Tester

Call Center Agent (PT or FT - 100% Work From Home)

Administrative Assistant / Data Entry Clerk (Remote Work From Home)

Amazon Fresh Grocery Associate

Amazon Flex Representative

Senior Specialist, Premium Support (English/Spanish)

Apple Remote Jobs Entry Level (Work At Home) ID-1678

VP, Aircraft Management Sales (Remote, Northeast US)

Licensed Healthcare Insurance Agent - Remote USA

Remote Telemedicine Veterinarian

Lead-Inside Sales

Licensed Healthcare Insurance Agent - Remote USA

Remote Jobs No Experience | Online Reputation Management | $25 - $30/hr

Guest Services Associate: Travel Concierge & Customer Care

Remote Travel Advisor (Travel Agent Specializing in Disney Vacations)

American Airlines Customer Service Representative (Remote)

Sales Assistant | Qatar Duty Free

Immediate Hiring: YouTube Content Moderator Jobs Remote $27Hr

Administrative Data Entry

Side Gig Work From Home - More Money For You!

Graphic Design Internship '26 - DAYBREAKER

Senior Project Manager (100% Remote)

Coder - Inpatient (CCS/CIC REQUIRED), Remote, Sign on Bonus Eligible

Cybersecurity Job Readiness Training

NOW HIRING: Remote Sales Associates – Entry Level | Start ASAP

United Airlines Reservations Representative (Remote)

Work From Home Data Entry / Typist Virtual

Data Analyst 4 - PART TIME/ REMOTE

Needed: Freelance Writers for Flexible, Consistent, Ongoing Work

Call Center Representative Agent Work From Home - Part-Time Focus Group Panelist

Paid Product Tester

Conversion Optimization Manager - Apple Retail Online

Entry Level Medical Coding Specialist

Remote Teleradiologist – Flexible Evening Shifts (IL License Required)

Work From Home Customer Service Rep

Weekend Jobs Inc. ? Flexible Weekend Job Opportunities

Risk Manager, Dietary Supplements, OTC Drugs, and Bodycare

Strategy Director (P&C Insurance)

Work From Home Customer Service Rep

Work from Anywhere Remote - Customer Service Representative - 19+ Hourly

Remote Technical Customer Support - QA and Game Dev - 7/26

Remote Game Tester

Remote Freight Sales Executive $80K-$100K - Nashville, TN | Apply Now

Remote Data Entry Clerk No Experience

Data Analyst - Junior Level (Remote)

Part-Time Typing Jobs from Home at Typing Solutions Co.

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...