Senior Security Engineer, Security Incident Response Team (SIRT)
Job description
About the role
This role is responsible for leading the end-to-end lifecycle of high-severity security incidents within GitLab's global environment. You will serve on the front lines of defense, managing crises with precision while implementing long-term improvements to detection and response capabilities. The position requires a blend of technical depth, operational discipline, and cross-team collaboration. You will work within a follow-the-sun model, ensuring continuous coverage and rapid response regardless of time zone. Success in this role will directly strengthen the security and reliability of GitLab.com for all customers.
Key facts
What you'll do
- Own the full incident lifecycle, guiding cases from initial detection through containment, eradication, and recovery while maintaining meticulous documentation.
- Coordinate with internal and external stakeholders, preparing executive-level updates and ensuring alignment across technical and business teams during active security events.
- Design and refine SIEM views and alert logic in partnership with Signals Engineering, focusing on GitLab-specific workflows and data patterns to detect subtle adversarial activity.
- Build and improve automation and AI-assisted tools to speed up triage and maintain consistent investigation quality across the Security Incident Response Team.
- Conduct digital forensics on cloud infrastructure, with an emphasis on AWS and GCP assets, tracing artifacts across accounts and regions to reconstruct attack paths.
- Use threat intelligence to identify adversary behaviors and convert insights into improved telemetry and detection rules that prevent future compromise.
- Author durable runbooks and decision trees that remain effective under real-world conditions, using them to mentor other responders and elevate team maturity over time.
- Lead post-incident reviews, performing root cause analysis and implementing controls to reduce the likelihood of recurrence and strengthen overall security posture.
- Own external and internal communications during sustained security events, ensuring leadership and partners remain informed with clear and timely updates.
- Collaborate closely with Legal, Engineering, Product, and other functions to ensure responses comply with policy and preserve customer trust throughout the incident lifecycle.
- Mentor responders through coaching, tabletop exercises, and shared standards, advancing the overall maturity of the security operations function across the organization.
- Drive continuous improvement by analyzing incident trends, identifying systemic gaps, and proposing enhancements to detection, response, and prevention measures.
- Partner with engineering teams to ensure remediation efforts are implemented effectively and integrated into the software development lifecycle.
- Maintain current knowledge of the threat landscape relevant to SaaS platforms and cloud infrastructure to anticipate emerging risks.
- Support on-call rotations as part of a follow-the-sun model, providing rapid response and coverage across different time zones.
- Contribute to the development and maintenance of security playbooks, ensuring they reflect current best practices and operational realities.
- Utilize Git and GitLab internals to investigate source code changes, CI/CD pipelines, and access patterns during forensic investigations.
- Leverage SIEM platforms and EDR tools to build and tune detection rules that uncover subtle adversary activity within complex environments.
- Work with limited supervision, demonstrating ownership and judgment when making critical decisions under pressure during security incidents.
Requirements
- Bring hands-on experience with Digital Forensics and Incident Response in cloud-first environments, including the ability to trace evidence across multiple accounts and regions.
- Understand Git and GitLab internals well enough to investigate source code changes, CI/CD pipelines, and access patterns as they relate to security incidents.
- Possess practical experience using SIEM platforms and EDR tools to build detection rules that uncover subtle adversary activity in dynamic environments.
- Demonstrate knowledge of major cloud platforms, specifically AWS and GCP, including their logging, identity, and network controls relevant to incident response.
- Show ability to read threat intelligence reports and map adversary tactics to concrete detection and mitigation controls within security tooling.
- Communicate clearly and effectively in both writing and speech, even while managing complex incidents under tight time constraints and high pressure.
- Have a strong grasp of security fundamentals, including intrusion detection, malware analysis, log analysis, and incident handling procedures.
- Be able to work within a follow-the-sun model, supporting global operations and ensuring continuity of response at any hour.
Nice to have
Experience guiding partners through complex incident response scenarios and sharing outcomes across regions is valued. Proficiency with GitLab, AWS, GCP, SIEM, EDR, threat intelligence, Digital Forensics, Incident Response, and automation tools will support success in this role.
Practical notes
Please confirm all details, including specific requirements and application procedures, on the official job page before applying. Only information from the original source has been used; no additional claims have been introduced.