Security Engineer on GitLab's Security Incident Response Team (SIRT)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
As a Senior Security Engineer on GitLab’s Security Incident Response Team (SIRT), you will play a critical role in defending GitLab.com and the broader GitLab environment against evolving security threats.
You will lead high-impact incidents and investigations, drive continuous improvements in defense, detection and response capabilities, and help scale security operations through automation and intelligent workflows.
Operating within a 24/7 global environment, you will own incidents end-to-end - from detection and triage through containment, eradication, and recovery - while partnering cross-functionally to strengthen GitLab’s overall security posture.
A key aspect of this role is leveraging automation and AI-driven approaches to improve detection fidelity, accelerate investigations, and reduce response times.
This role is ideal for someone who thrives in high-tempo environments, brings strong DFIR expertise, and is equally passionate about operational excellence and building scalable detection and response systems and workflows., * Lead and coordinate end-to-end incident response for high-severity security events within a 24/7 global on-call model, operating during EMEA business hours.
- Prepare clear executive communications that keep stakeholders informed during incidents.
- Investigate complex security incidents across cloud environments, applying strong Digital Forensics and Incident Response (DFIR) methodologies.
- Partner with Signals Engineering to design and implement detection capabilities, including SIEM use cases, alerting strategies, and telemetry pipelines.
- Build and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistency.
- Partner with Threat Intelligence to contextualize threats and improve detection coverage.
- Conduct root cause analysis (RCA) and lead post-incident reviews to drive continuous improvement and risk reduction.
- Develop and maintain runbooks, playbooks, and operational documentation.
- Collaborate cross-functionally during incidents and lead proactive initiatives such as tabletop exercises.
- Mentor other engineers and help elevate the team’s overall incident response maturity., The Security Incident Response Team (SIRT) is a globally distributed team of engineers spread across AMER, APAC and EMEA. The team leads security investigations, incident response support, and response resolution, as well as cyber-threat analysis, detection, and response engineering.
Despite being a global team, we work cross-regionally, using automation and processes to facilitate collaboration when resolving incidents and handling general project work.
Requirements
- Strong experience in security incident response and investigations in cloud-first environments.
- Experience using or administering Git/GitLab in a security or engineering context.
- Hands-on experience with SIEM, EDR, and/or detection engineering.
- Experience with cloud platforms (AWS, GCP).
- Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK).
- Experience building or working with automation (e.g., Python, scripting, SOAR platforms).
- Interest or experience in applying AI/ML or data-driven techniques to detection, triage, or response workflows.
- Strong analytical and problem-solving skills, with the ability to operate effectively during high-severity incidents.
- Excellent written communication skills with a passion for clear, actionable documentation.
- Growth mindset with a proactive approach to identifying and mitigating security risks.
Benefits & conditions
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation
- Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Why SmartGit Is More Than a Git Client
Dev Digest 134 - Where pixels sing?
Dev Digest 121 - AI goes offline
Dev Digest 238: People > AI, Let Git Ignore Everything & Competitive Gurning!