Senior Product Manager, Secret Detection and Vulnerability Research

<strong>An overview of this role</strong><br/><br/>As a <strong>Senior Product Manager</strong>, you will own GitLab's Secret Detection offering and the Vulnerability Research function that produces the detection content across security products. Secret Detection is one of the highest-signal, highest-volume security capabilities on the platform. Leaked credentials are the most common initial access vector in real breaches, and as AI agents write, commit, and configure more of the software, the surface area for exposed secrets grows faster than the number of humans watching it.<br/><br/>You will own the full loop: detect a secret with high precision, tell the customer whether it is still live, get it revoked, and prevent the next one from ever landing. In parallel, you will own vulnerability research as a product asset rather than a back-office function. The detection rules, advisory data, and malicious package and reference intelligence your team produces are what make GitLab's security scanners worth paying for, and they need to ship on a cadence with measurable quality.<br/><br/>This is an outcome-owning role - you will carry adoption, retention, and revenue targets for your area and be expected to explain how your roadmap moves them.<br/><br/><strong>Some examples of our projects:</strong><br/><ul><li>Push protection and pre-receive blocking that stops a credential before it reaches a repository, without wrecking developer flow</li><li>Secret validity checking and automated revocation partnerships with major cloud and SaaS token issuers</li><li>Detection content pipelines that turn threat research into shipped rules, with precision and recall tracked per rule</li><li>Intelligence-driven detection of malicious packages, dependencies, and references entering the software supply chain</li></ul><strong>What you'll do</strong><br/><ul><li><strong>Own</strong> the business outcomes for Secret Detection and Vulnerability Research, including adoption, expansion, competitive win rate, and revenue contribution. Bring a point of view on packaging and pricing, not just features.</li><li><strong>Set</strong> the strategy for the full secret lifecycle: prevention, detection, validation, revocation, and reporting across GitLab.com, Dedicated, and Self-Managed.</li><li><strong>Treat</strong> detection content as a product. Define how rules, advisories, and intelligence feeds are sourced, validated, versioned, and measured, and make quality visible to customers.</li><li><strong>Hold</strong> the line on detection quality. False positives are a product defect and you will own the metrics that prove precision is improving.</li><li><strong>Work</strong> at the level of the technology. Read the rule syntax, question the entropy heuristics, understand why a scanner missed something, and challenge engineering with informed alternatives.</li><li><strong>Use</strong> AI to compress the distance between question and answer. Pull your own data, prototype your own flows, synthesize research and competitive input yourself, and bring conclusions rather than requests for someone else to investigate.</li><li><strong>Build</strong> the case for where AI belongs in the product: triage, rule generation, remediation guidance, and reducing the human review burden per finding.</li><li><strong>Partner</strong> with engineering, security research, threat intelligence, Field, and GitLab's own Security team, who are one of your most demanding users.</li><li><strong>Communicate</strong> in writing, asynchronously, with enough precision that a distributed team can act without a meeting.</li></ul><strong>What you'll bring</strong><br/><ul><li><strong>Domain depth</strong> in application security, vulnerability management, or security research. You have worked on or adjacent to scanners, detection content, threat intelligence, or SDLC security tooling and you know how these products actually get evaluated in a bake-off.</li><li><strong>Technical credibility</strong> sufficient to earn the respect of a security engineering team. You do not need to have written the scanner, but you should be able to reason about detection logic, data pipelines, CI integration, and the tradeoffs between coverage and noise.</li><li><strong>Commercial reasoning.</strong> You start from revenue mechanics, buyer motion, and competitive displacement, then work inward to product decisions. Candidates who reason only from feature lists outward are not a fit.</li><li><strong>Evidence of using AI as a force multiplier</strong> in your own work: research, analysis, data pulls, prototyping, drafting. Consuming a chat assistant occasionally is not the same as restructuring how you work.</li><li><strong>Judgment under ambiguity.</strong> You bring structured options and a recommendation instead of escalating an open question.</li><li><strong>Bias for clarity.</strong> You can take a noisy, technical, politically contested problem and produce one page that everyone can align on.</li><li><strong>Bonus:</strong> hands-on background as a developer, security engineer, red teamer, or researcher; experience with credential and token ecosystems; experience commercializing a data or intelligence asset.</li></ul><strong>About the team</strong><br/><br/>This role sits in GitLab's Security product management organization, which owns application security testing, vulnerability management, supply chain security, secrets management, and AI governance. The Security Section is central to GitLab's Ultimate tier and to the shift toward consumption-based product revenue, so the work is visible to senior leadership and directly tied to company results. You will work asynchronously with engineering, design, and research counterparts across multiple regions, and with the Field teams who take this to market.<br/><br/><strong><strong>How GitLab Supports Full-Time Employees</strong></strong><br/><ul><li>Benefits to support your health, finances, and well-being</li><li>Flexible Paid Time Off </li><li>Team Member Resource Groups</li><li>Equity Compensation & Employee Stock Purchase Plan</li><li>Growth and Development Fund</li><li>Parental Leave </li></ul><br/>Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.<br/><br/><strong>Country Hiring Guidelines: </strong>GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process. <br/><br/><strong>Privacy Policy: </strong>Please review our Recruitment Privacy Policy. Your privacy is important to us.

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...

Other Jobs To Apply

Principal IT Technical Program Manager, Infrastructure

Account Manager

Specialist, Platform Product

Merchandise Planner

Business Development Director - Google Cloud Platform

REMOTE DISNEY VACATION SPECIALIST

Program Manager III- PGM Basecamp

Update Business Information for Ebay, Walmart, Amazon.

Delta Airlines Careers Remote( Customer service ) – Work From Home – Part Time

Data Engineer (Fully Remote)

(Remote) Amazon Data Entry Jobs from Home - No Experience - Apply Now

Remote Senior QA Automation Architect

Account Manager - X (Formerly Twitter)

Remote Retention Marketing Manager, DTC eCommerce

Data Entry Specialist (Entry Level, Remote) – Earn $70K–$80K/Year - Part Time

Remote Telemedicine Veterinarian

Sr. Manager, Merchandising

VP, GTM, UCANZ

Software Engineer (Frontend/Vue) - HENNGE Email DLP

Software Engineer (Data Analytics), AI & Data Platforms (AiDP)

Talent Coach

AI/ML Engineer for an AI-Driven E-Commerce Platform

Brand & Product Marketing Growth Leader

QA Tester - BaseCamp (Remote)

TESTING SPECIALIST/TESTER

Customer Engineer/Buffer - Flexforce - Customer Engineer

Sr. Software Engineer (AI Orchestration Zone, Backend Leaning)

Senior Manager, IT

Sr Developer - Kubernetes, GitOps / GitHub, service meshes

Principal – GitHub & Azure DevOps Platform Engineering

Senior Software Engineer,Billing

Post Task Github Project Contributor Remotely

Business Development Representative

Renewals Manager - West

Staff Product Manager, RevOps & Finance Systems

Intermediate Support Engineer (SHIFT)

Fullstack Engineer (TypeScript), AI Engineering: Duo Client SDK

Data Analyst for Ecom brand – Need deep research on Shopify analytics

E-Commerce, PLG Commercial (SaaS + Shopify)

UI/UX Designer (Shopify & Ecommerce) for a USA Client - Remote

Shopify & Etsy Customer Service Agent – Remote

Shopify Expert (Remote)

Remote Veterinary Care Representative - Pharmacy Order Management

[Remote] Rust backend architect Engineer – Twitter/X Style Infrastructure

Seasonal: Guest Advocate (Cashier), General Merchandise, Inbound (Stocking) (T3273)

Target Entry Level Remote Jobs ($21/Hr WFH Jobs) -

Measure Tech – Part-Time

Territory Associate Relations Manager (Houston & Dallas)

Online Experience Analyst - The Company Store

YouTube Operations Associate Manager- Contract