高级产品经理,秘密检测与漏洞研究
Senior Product Manager, Secret Detection and Vulnerability Research
GitLab 是 DevSecOps 的智能编排平台。GitLab 帮助组织提高开发人员生产力,提升运营效率,降低安全和合规风险,并加速数字化转型。超过 5000 万注册用户,超过 50% 的财富 100 强企业* 信任 GitLab 来更快地交付更优质、更安全的软件。
我们产品中构建的原则也体现在团队的工作方式中:我们把 AI 视为核心的生产力倍增器,所有团队成员都被期望将 AI 融入日常工作中,以推动效率、创新和影响力。GitLab 是职业加速、创新繁荣、每个声音都受到重视的地方。我们的高绩效文化由价值观和持续的知识交流驱动,使团队成员能够在与行业领袖合作解决复杂问题的过程中发挥全部潜力。与我们共同创造未来,一起构建改变世界软件开发方式的技术。
*Fortune 500® 是 Fortune Media IP Limited 的注册商标,经许可使用。声明基于 GitLab 数据。财富 100 强指的是 2025 年 6 月发布的 2025 年财富 500 强榜单中排名前 20% 的公司。财富和 Fortune Media IP Limited 与 GitLab 没有隶属关系,也不认可 GitLab 的产品或服务。
职位概述
作为高级产品经理,你将负责 GitLab 的 Secret Detection(秘密检测)功能以及生成安全产品中检测内容的漏洞研究功能。Secret Detection 是平台上信号最强、流量最大的安全功能之一。泄露的凭证是真实攻击中最常见的初始访问向量,随着 AI 代理编写、提交和配置越来越多的软件,暴露的秘密范围增长速度超过了人类监控的数量。
你将负责整个闭环:以高精度检测出一个秘密,告知客户它是否仍然有效,使其被撤销,并防止下一个秘密被引入。同时,你还将把漏洞研究作为产品资产来管理,而不是后台功能。你团队生成的检测规则、通告数据、恶意包和参考情报,正是 GitLab 安全扫描器值得付费的原因,这些内容需要按照可衡量质量的节奏进行发布。
这是一个结果负责的职位——你将承担该领域的产品采用率、留存率和收入目标。
查看英文原文
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.
The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software.
*Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.
An overview of this role
As a Senior Product Manager, you will own GitLab's Secret Detection offering and the Vulnerability Research function that produces the detection content across security products. Secret Detection is one of the highest-signal, highest-volume security capabilities on the platform. Leaked credentials are the most common initial access vector in real breaches, and as AI agents write, commit, and configure more of the software, the surface area for exposed secrets grows faster than the number of humans watching it.
You will own the full loop: detect a secret with high precision, tell the customer whether it is still live, get it revoked, and prevent the next one from ever landing. In parallel, you will own vulnerability research as a product asset rather than a back-office function. The detection rules, advisory data, and malicious package and reference intelligence your team produces are what make GitLab's security scanners worth paying for, and they need to ship on a cadence with measurable quality.
This is an outcome-owning role - you will carry adoption, retention, and revenue targets for your area and be expected to explain how your roadmap moves them.
Some examples of our projects:
- Push protection and pre-receive blocking that stops a credential before it reaches a repository, without wrecking developer flow
- Secret validity checking and automated revocation partnerships with major cloud and SaaS token issuers
- Detection content pipelines that turn threat research into shipped rules, with precision and recall tracked per rule
- Intelligence-driven detection of malicious packages, dependencies, and references entering the software supply chain
What you'll do
- Own the business outcomes for Secret Detection and Vulnerability Research, including adoption, expansion, competitive win rate, and revenue contribution. Bring a point of view on packaging and pricing, not just features.
- Set the strategy for the full secret lifecycle: prevention, detection, validation, revocation, and reporting across GitLab.com, Dedicated, and Self-Managed.
- Treat detection content as a product. Define how rules, advisories, and intelligence feeds are sourced, validated, versioned, and measured, and make quality visible to customers.
- Hold the line on detection quality. False positives are a product defect and you will own the metrics that prove precision is improving.
- Work at the level of the technology. Read the rule syntax, question the entropy heuristics, understand why a scanner missed something, and challenge engineering with informed alternatives.
- Use AI to compress the distance between question and answer. Pull your own data, prototype your own flows, synthesize research and competitive input yourself, and bring conclusions rather than requests for someone else to investigate.
- Build the case for where AI belongs in the product: triage, rule generation, remediation guidance, and reducing the human review burden per finding.
- Partner with engineering, security research, threat intelligence, Field, and GitLab's own Security team, who are one of your most demanding users.
- Communicate in writing, asynchronously, with enough precision that a distributed team can act without a meeting.
What you'll bring
- Domain depth in application security, vulnerability management, or security research. You have worked on or adjacent to scanners, detection content, threat intelligence, or SDLC security tooling and you know how these products actually get evaluated in a bake-off.
- Technical credibility sufficient to earn the respect of a security engineering team. You do not need to have written the scanner, but you should be able to reason about detection logic, data pipelines, CI integration, and the tradeoffs between coverage and noise.
- Commercial reasoning. You start from revenue mechanics, buyer motion, and competitive displacement, then work inward to product decisions. Candidates who reason only from feature lists outward are not a fit.
- Evidence of using AI as a force multiplier in your own work: research, analysis, data pulls, prototyping, drafting. Consuming a chat assistant occasionally is not the same as restructuring how you work.
- Judgment under ambiguity. You bring structured options and a recommendation instead of escalating an open question.
- Bias for clarity. You can take a noisy, technical, politically contested problem and produce one page that everyone can align on.
- Bonus: hands-on background as a developer, security engineer, red teamer, or researcher; experience with credential and token ecosystems; experience commercializing a data or intelligence asset.
About the team
This role sits in GitLab's Security product management organization, which owns application security testing, vulnerability management, supply chain security, secrets management, and AI governance. The Security Section is central to GitLab's Ultimate tier and to the shift toward consumption-based product revenue, so the work is visible to senior leadership and directly tied to company results. You will work asynchronously with engineering, design, and research counterparts across multiple regions, and with the Field teams who take this to market.
How GitLab Supports Full-Time Employees
- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.
Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.
Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us.
GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.