GitLab logo
    G

    Senior Security Engineer, Security Incident Response Team (SIRT)

    GitLab
    Remote, US
    Remote
    Senior
    Full Time
    about 16 hours ago
    💰$139,200 - $218,400
    remotesecurityincident responsecloudautomationAIDFIR

    Requirements

    • Strong experience in security incident response and investigations in cloud-first environments
    • Experience using or administering Git/GitLab in a security or engineering context
    • Hands-on experience with SIEM, EDR, and/or detection engineering
    • Experience with cloud platforms (AWS & GCP)
    • Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK)
    • Experience building or working with automation (e.g., Python, scripting, SOAR platforms)
    • Interest or experience in applying AI/ML or data-driven techniques to detection, triage, or response workflows
    • Strong analytical and problem-solving skills; ability to operate effectively during high-severity incidents
    • Excellent written communication skills with a passion for clear, actionable documentation
    • Growth mindset with a proactive approach to identifying and mitigating security risks
    • Must be a United States Citizen and reside within the United States

    What You'll Do

    • Lead and coordinate end-to-end incident response for high-severity security events within a 24/7 global on-call model
    • Prepare clear executive communications that keep stakeholders informed during incidents
    • Investigate complex security incidents across cloud environments using Digital Forensics and Incident Response (DFIR) methodologies
    • Partner with Signals Engineering to design and implement detection capabilities including SIEM use cases, alerting strategies, and telemetry pipelines
    • Build and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistency
    • Partner with Threat Intelligence to contextualize threats and improve detection coverage
    • Conduct root cause analysis (RCA) and lead post-incident reviews to drive continuous improvement and risk reduction
    • Develop and maintain runbooks, playbooks, and operational documentation
    • Collaborate cross-functionally during incidents and lead proactive initiatives such as tabletops
    • Mentor other engineers and help elevate the team’s overall incident response maturity

    Benefits

    • Benefits to support your health, finances, and well-being
    • Flexible Paid Time Off
    • Team Member Resource Groups
    • Equity Compensation & Employee Stock Purchase Plan
    • Growth and Development Fund
    • Parental leave
    • Home office support

    About GitLab

    GitLab is a web-based Git repository manager that offers a variety of features for software development teams.

    San Francisco, CA, US
    1000 - 5000
    Developer Tools