Manager, Security Incident Response Team (USA)
Role details
Job location
Tech stack
Job description
We're looking for a manager to lead the GitLab security incident response team (SIRT) in the Americas region. GitLab SIRT manages and investigates cybersecurity incidents across all GitLab operating environments and operates in a tierless SOC model. The team is responsible for threat hunting, alert triage, security investigations, deep-dive DFIR, and large-scale incident response, among other responsibilities.
In this role, you will manage the day-to-day work of a team of incident response engineers - setting clear performance expectations, coaching their growth, and holding the team accountable for delivering quality results. You should have a strong technical background, be comfortable owning the full incident lifecycle from alert triage to retrospective actions, and be skilled at developing others to do the same.
We are looking for someone who makes sound operational decisions under pressure and who actively looks for opportunities to "shift left" - improving defenses and leveraging AI and automation to optimize team workflows. You will implement program direction, maintain a culture of high performance, and defend GitLab infrastructure and products including GitLab.com, GitLab Dedicated, and GitLab Dedicated for Government (FedRAMP).
This role requires availability during US West Coast business hours. Candidates based on the West Coast are preferred, though candidates in other time zones who are comfortable working these hours are also welcome to apply. Some after-hours and weekend coverage may be required to support engineers during high-severity incidents.
Learn more about the Security Operations Department:
- Security Incident Response Team
- Trust and Safety Team
- Security Logging Team
- Red Team
- Signals Engineering Team
What You'll Do
- Manage day-to-day team operations - establish clear goals, performance expectations, and accountability for direct reports; monitor progress and ensure timely delivery of quality results.
- Develop and coach incident responders - provide candid, real-time feedback; advise on career growth; and foster a culture of investigation excellence, prioritizing depth and accuracy of analysis.
- Proactively identify and fill talent gaps - participate in hiring decisions with a focus on candidates who will amplify GitLab's values and raise the team's technical bar.
- Drive engagement and retention - recognize team member contributions, address engagement risks early, and create an environment of open feedback and psychological safety.
- Cascade organizational context - translate division and company-wide strategy into clear, actionable team priorities; keep team members informed in a timely manner.
- Implement and mature incident response processes - build and improve runbooks, procedures, and team capabilities that translate functional plans into tactical execution.
- Lead incident response - serve as an escalation point and incident commander for high-severity events, including occasional nights and weekends; model the standard for quality investigations.
- Enable cross-functional collaboration - coordinate effectively with peer SecOps teams, Legal, Customer Support, and Infrastructure to resolve incidents and close defense gaps through actionable retrospective mitigations.
- Align the team on defensive improvements - drive insights from alerts, investigations, and incidents to improve GitLab's security posture and support a "shift left" mindset.
- Champion remote-first practices - consistently model and coach team members on GitLab's remote working best practices, async communication norms, and handbook-first culture., Entry level Entry level Cloud * Security * Software * Cybersecurity * Automation As a Customer Success Engineer, you will provide technical guidance and best practice advice to customers post-sale, help with implementations, and develop customer enablement resources. Top Skills: Agile PlanningContinuous DeliveryContinuous IntegrationDevsecopsGitlab GitLab, As a Senior Data Analyst, you will analyze marketing performance, implement multi-touch attribution, and provide insights for strategic decisions. Top Skills: Claude With Mcp ConnectionsDbtGitlab Duo Agent PlatformSnowflakeSQLTableau GitLab, Cloud * Security * Software * Cybersecurity * Automation As a Staff Technical Program Manager, you'll lead cross-functional programs within GitLab's engineering organization, coordinating complex initiatives and aligning technical discussions with program goals. Top Skills: APIsCi/CdCloud InfrastructureDistributed SystemsGitlabJIRA
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute
Requirements
- Proven people management experience - track record of managing and developing a team of security engineers, setting performance expectations, providing coaching, and driving accountability for results.
- Incident response leadership - demonstrated experience leading complex incident response operations, including large-scale incident coordination and the full lifecycle from triage to retrospective.
- Hands-on technical background - experience conducting security investigations and log analysis using SIEM tools (e.g., Splunk, Elastic); working knowledge of GCP and/or AWS, including cloud forensics.
- Customer-facing credibility - comfortable representing GitLab Security during customer escalations and high-visibility cybersecurity discussions.
- Proactive hunting and threat intelligence - proficiency in threat hunting based on intelligence, and familiarity with supply chain threats targeting SaaS platforms.
- AI and automation mindset - experience using AI/LLMs to improve incident response workflows and automate repetitive processes.
- Platform familiarity - experience using GitLab (or a comparable DevSecOps platform) for project tracking; bonus if you have experience responding to threats against a SaaS platform.
- Prioritization under pressure - ability to make sound operational decisions quickly, escalate issues cleanly, and guide the team on balancing what is urgent versus what is important.
Due to government requirements, you must be a United States Citizen (defined as any individual who is a citizen of the United States by law, birth, or naturalization) to fill this position. About the Team
Benefits & conditions
Be an Early Applicant Easy Apply Remote Hiring Remotely in US 150K-235K Annually Senior level Easy Apply Remote Hiring Remotely in US 150K-235K Annually Senior level The role involves managing the security incident response team, handling incidents, coaching team members, and improving security processes, aiming for operational excellence in threat response. The summary above was generated by AI, The base salary range for this role's listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary. United States Salary Range $150,000-$235,000 USD How GitLab Supports Full-Time Employees
- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
About the company
GitLab is the most comprehensive AI-powered DevSecOps platform for software innovation. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation.
More than 50 million registered users and more than 50% of the Fortune 100 trust GitLab to ship better, more secure software faster.