Senior Threat Intelligence Engineer
Job description
About the role
We are seeking an experienced Threat Intelligence Engineer to proactively identify and analyze security risks. Your primary goal will be to provide actionable insights that enable informed decision-making and anticipate potential threats to GitLab and its software supply chain. This role is crucial in shaping our security posture by staying ahead of emerging attack vectors. You will operate at the intersection of security analysis and engineering to transform raw data into strategic defense mechanisms. The position demands a proactive mindset focused on identifying patterns before they escalate into critical incidents. You will serve as a key liaison between technical detection and executive security strategy. Your work will directly influence the security roadmap and resilience of the GitLab platform.
Key facts
What you'll do
Monitor the global threat landscape, focusing on risks pertinent to GitLab and its software supply chain, and synthesize findings into concise reports for stakeholder awareness.
Manage and enhance our Threat Intelligence Platform, designing data collection pipelines that ingest and normalize intelligence from diverse internal and external sources.
Assist incident response efforts by performing deep analysis of malware artifacts and tracking threat actor infrastructure to disrupt active campaigns.
Contribute to collaborative exercises such as red team and blue team simulations that test and refine defensive strategies against newly identified threats.
Cultivate relationships with industry peers and information sharing groups to exchange tactical intelligence and collaborate on addressing shared security concerns.
Develop automated solutions using code and AI to correlate disparate data points, increase team efficiency, and improve the accuracy of threat intelligence processes.
Evaluate new tools and frameworks to integrate modern research methodologies into the existing threat hunting and analysis workflows.
Conduct hypothesis-driven investigations to explore potential vulnerabilities and attack paths within the context of the broader threat environment.
Translate complex technical findings into clear narratives that support security awareness training and improve organizational risk perception.
Continuously refine the threat intelligence lifecycle, ensuring collection, processing, analysis, and dissemination stages are optimized for timely decision support.
Requirements
Demonstrated success in delivering threat intelligence that has positively impacted an organization's security posture through measurable outcomes and reduced risk.
Experience operating a Threat Intelligence Platform and managing high-volume threat data feeds from sources such as honeypots, commercial feeds, and internal logs.
Proficiency in researching adversaries using open-source intelligence techniques and structured analytical methods to draw reliable conclusions.
Ability to automate repetitive tasks through scripting, with a demonstrated preference for Python to handle data manipulation and report generation.
Strong professional communication skills, both written and verbal, for clearly explaining complex security topics to technical and non-technical audiences.
A methodical approach to evidence handling and data validation to maintain the integrity and reliability of intelligence products.
Proven ability to work independently and collaboratively within a distributed security operations team that values transparency and documentation.
Commitment to continuous learning and adapting to new tactics, techniques, and procedures used by threat actors across the software supply chain.
Nice to have
Experience with reverse engineering malware, particularly for macOS, Linux, and code repositories, to uncover hidden functionality and attacker intent.
Publicly available work, such as blog posts or open-source projects, that demonstrate thought leadership or practical contributions to the threat intelligence community.
Practical notes
The base salary range for this role in the United States is $140,000 to $200,000 USD annually, excluding bonuses, equity, and benefits. Salary is determined by factors including experience, skills, location, and market data.
GitLab offers comprehensive benefits, flexible paid time off, equity compensation, and a growth and development fund.
We encourage candidates to apply even if they do not meet every qualification.
GitLab is an equal opportunity employer and values diversity.