> Markdown version of [/jobs/ext/2277809-senior-security-engineer-security-incident-response-team-sirt-emea](https://www.wearedevelopers.com/jobs/ext/2277809-senior-security-engineer-security-incident-response-team-sirt-emea). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA - **Company:** GitLab - **Location:** Redruth, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Cyber Security, Digital Forensics, Intrusion Detection and Prevention, Python (Programming Language), Security Information and Event Management, Scripting, Mitre Att&ck, Cyber Threat Analysis, Gitlab, Git, Data Analytics, Security Orchestration, Automation & Response - **Published:** August 28, 2026 - **Apply:** https://www.totaljobs.com/job/senior-security-engineer/gitlab-job107906773 ## About the Role * Strong experience in security incident response and investigations in cloud-first environments * Experience using or administering Git/GitLab in a security or engineering context * Hands-on experience with SIEM, EDR, and/or detection engineering * Experience with cloud platforms (AWS & GCP) * Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK) * Experience building or working with automation (e.g., Python, scripting, SOAR platforms) * Interest or experience in applying AI/ML or data-driven techniques to detection, triage, or response workflows * Strong analytical and problem-solving skills; ability to operate effectively during high-severity incidents * Excellent written communication skills with a passion for clear, actionable documentation * Growth mindset with a proactive approach to identifying and mitigating security risks ## Description As a Senior Security Engineer on GitLab's Security Incident Response Team (SIRT), you will play a critical role in defending GitLab.com and the broader GitLab environment against evolving security threats. You will lead high-impact incidents and investigations, drive continuous improvements in defense, detection and response capabilities, and help scale security operations through automation and intelligent workflows. Operating within a 24/7 global environment (follow the sun model), you will own incidents end-to-end - from detection and triage through containment, eradication, and recovery - while partnering cross-functionally to strengthen GitLab's overall security posture. A key aspect of this role is leveraging automation and AI-driven approaches to improve detection fidelity, accelerate investigations, and reduce response times. You will help shape how modern tooling and data are applied to stay ahead of evolving adversary tactics. This role is ideal for someone who thrives in high-tempo environments, brings strong DFIR expertise, and is equally passionate about operational excellence and building scalable detection and response systems and workflows. What you'll do * Lead and coordinate end-to-end incident response for high-severity security events within a 24/7 global on-call model, with this role operating during EMEA business hours * Prepare clear executive communications that keep stakeholders informed during incidents * Investigate complex security incidents across cloud environments, applying strong Digital Forensics and Incident Response (DFIR) methodologies * Partnering with Signals Engineering to design and implement detection capabilities, including SIEM use cases, alerting strategies, and telemetry pipelines * Build and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistency * Partner with Threat Intelligence to contextualize threats and improve detection coverage * Conduct root cause analysis (RCA) and lead post-incident reviews to drive continuous improvement and risk reduction * Develop and maintain runbooks, playbooks, and operational documentation * Collaborate cross-functionally (Engineering, Infrastructure, Legal, Product, Communications, etc) during incidents and lead proactive initiatives (e.g. tabletops) * Mentor other engineers and help elevate the team's overall incident response maturity ## Related Videos - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)