# Senior Product Manager, Secret Detection and Vulnerability Research

**Company**: GitLab
**Location**: Remote, United States
**Work arrangement**: remote
**Experience**: senior
**Job type**: full-time
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/gitlab/jobs/8697043002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_b20cdc1c-0ab

## Description

GitLab is seeking a Senior Product Manager for Secret Detection and Vulnerability Research. As a Senior Product Manager, you will own GitLab's Secret Detection offering and the Vulnerability Research function that produces the detection content across security products.

Secret Detection is one of the highest-signal, highest-volume security capabilities on the platform. Leaked credentials are the most common initial access vector in real breaches, and as AI agents write, commit, and configure more of the software, the surface area for exposed secrets grows faster than the number of humans watching it.

You will own the full loop: detect a secret with high precision, tell the customer whether it is still live, get it revoked, and prevent the next one from ever landing. In parallel, you will own vulnerability research as a product asset rather than a back-office function.

The detection rules, advisory data, and malicious package and reference intelligence your team produces are what make GitLab's security scanners worth paying for, and they need to ship on a cadence with measurable quality.

This is an outcome-owning role - you will carry adoption, retention, and revenue targets for your area and be expected to explain how your roadmap moves them.

Responsibilities:

- Own the business outcomes for Secret Detection and Vulnerability Research, including adoption, expansion, competitive win rate, and revenue contribution.

- Set the strategy for the full secret lifecycle: prevention, detection, validation, revocation, and reporting across GitLab.com, Dedicated, and Self-Managed.

- Treat detection content as a product. Define how rules, advisories, and intelligence feeds are sourced, validated, versioned, and measured, and make quality visible to customers.

- Hold the line on detection quality. False positives are a product defect and you will own the metrics that prove precision is improving.

- Work at the level of the technology. Read the rule syntax, question the entropy heuristics, understand why a scanner missed something, and challenge engineering with informed alternatives.

- Use AI to compress the distance between question and answer. Pull your own data, prototype your own flows, synthesize research and competitive input yourself, and bring conclusions rather than requests for someone else to investigate.

- Build the case for where AI belongs in the product: triage, rule generation, remediation guidance, and reducing the human review burden per finding.

- Partner with engineering, security research, threat intelligence, Field, and GitLab's own Security team, who are one of your most demanding users.

- Communicate in writing, asynchronously, with enough precision that a distributed team can act without a meeting.

Requirements:

- Domain depth in application security, vulnerability management, or security research.

- Technical credibility sufficient to earn the respect of a security engineering team.

- Commercial reasoning.

- Evidence of using AI as a force multiplier in your own work.

- Judgment under ambiguity.

- Bias for clarity.

Benefits:

- Benefits to support your health, finances, and well-being

- Flexible Paid Time Off

- Team Member Resource Groups

- Equity Compensation & Employee Stock Purchase Plan

- Growth and Development Fund

- Parental Leave

## Skills

### Required
- application security
- vulnerability management
- security research
- AI

### Nice to have
- credential and token ecosystems
- commercializing a data or intelligence asset

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/gitlab/jobs/8697043002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
