> Markdown version of [/jobs/ext/2160167-intermediate-software-engineer-security-factory-vulnerability-management](https://www.wearedevelopers.com/jobs/ext/2160167-intermediate-software-engineer-security-factory-vulnerability-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Intermediate Software Engineer, Security Factory Vulnerability Management - **Company:** GitLab - **Location:** Redruth, UK - **Experience:** Experienced - **Salary:** £115,200.0 - £172,800.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Code Review, Cyber Security, Relational Databases, Elasticsearch, Graph Database, PostgreSQL, Software Maintenance, Ruby on Rails, Software Vulnerability Management, Data Ingestion, Software Security, Technical Debt, Backend, Gitlab, Vue.js, Front End Software Development - **Published:** August 21, 2026 - **Apply:** https://www.totaljobs.com/job/intermediate-software-engineer/gitlab-job107882110 ## About the Role * Experience delivering and maintaining software systems as part of a larger engineering team. * The ability to investigate technical problems, ask for context when needed, and work toward a practical resolution. * Experience working with relational databases such as PostgreSQL. * Clear communication and collaboration skills in a distributed team. * An interest in learning from others, sharing knowledge, and growing your technical skills. * Frontend development experience, including JavaScript or Vue.js, is helpful. * Experience with Elasticsearch, graph databases, vulnerability management, application security, or related transferable skills is helpful. ## Description As an Intermediate Software Engineer on GitLab's Vulnerability Management team, you'll help build the core security workflows that GitLab Ultimate customers use to triage, prioritize, and act on vulnerabilities. You'll work primarily in Ruby on Rails on backend systems, including security dashboards, vulnerability reports, and ingestion pipelines. You'll take ownership of well-defined projects, solve technical problems with support from experienced team members, and collaborate with other engineers. You'll also have opportunities to contribute beyond the backend when the work requires it. You will join a fullstack team, working together with product managers, designers, and frontend engineers to solve problems across the Vulnerability Management domain., * Develop and maintain backend features for GitLab's vulnerability management workflows. * Confidently ship features and improvements with minimal guidance and support from other team members; collaborate with the team on larger projects. * Help improve the performance, reliability, and scalability of security data ingestion and reporting systems. * Collaborate with frontend engineers and contribute across the stack when needed. * Work with engineers across security teams as vulnerability data and workflows come together in Vulnerability Management. * Collaborate with Product Management and Product Design to maintain a high bar for quality * Craft code that meets our internal standards for style, maintainability, and best practices for a high-scale web environment * Conduct code reviews within our Code Review Guidelines and ensure community contributions receive a swift response * Recognize impediments to our efficiency as a team ("technical debt"), propose and implement solutions * Participate in on-call rotations to assist troubleshooting product operations, security operations, and urgent engineering issues., The Vulnerability Management team develops the core security workflows that help GitLab customers triage and manage vulnerabilities. The team owns areas including the security dashboard, vulnerability reports, and ingestion pipelines, and serves as an important interface for security-related features across GitLab. The team is focused on moving beyond lists of findings toward workflows that help customers prioritize and coordinate remediation. You'll collaborate asynchronously with a small, distributed group and with related security teams, including the Agentic Security Flows team. ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Lessons learned from building a thriving Vue.js SaaS application](https://www.wearedevelopers.com/videos/1666-lessons-learned-from-building-a-thriving-vue-js-saas-application) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)