SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
GitLab is seeking a Senior Product Manager to own Secret Detection and Vulnerability Research, two critical security capabilities on the DevSecOps platform. Secret Detection is one of the highest-signal, highest-volume security features, addressing the reality that leaked credentials are the most common initial access vector in real breaches. As AI agents write and commit more code, the surface area for exposed secrets grows exponentially.
You will own the complete secret lifecycle: detection with high precision, validation of whether credentials are still live, revocation coordination, and prevention of future leaks. In parallel, you will elevate Vulnerability Research from a back-office function to a product asset. The detection rules, advisory data, and malicious package intelligence your team produces are core to GitLab's security scanner value proposition and must ship on a predictable cadence with measurable quality.
Key responsibilities include: owning adoption, retention, and revenue targets for your area; setting strategy for secret prevention, detection, validation, revocation, and reporting across GitLab.com, Dedicated, and Self-Managed deployments; treating detection content as a product with defined sourcing, validation, versioning, and measurement; holding the line on detection quality and false-positive metrics; working at the technology level to understand rule syntax, entropy heuristics, and scanner gaps; using AI to compress investigation cycles and pull your own data; building the case for AI in triage, rule generation, and remediation; and partnering across engineering, security research, threat intelligence, and field teams.
You will communicate asynchronously with precision, enabling distributed teams to act without meetings. This is an outcome-owning role where you carry business metrics and explain how your roadmap drives adoption, retention, and revenue.
Required: domain depth in application security, vulnerability management, or security research; hands-on experience with scanners, detection content, threat intelligence, or SDLC security tooling; technical credibility to read rule syntax and challenge engineering with informed alternatives; and the ability to synthesize research and competitive input independently.