Manager, Security Incident Response Team (usa)

GitLab GitLab · Enterprise · United States · Remote · Security Operations

Manager for GitLab's Security Incident Response Team (SIRT) in the Americas, focusing on leading a team of incident response engineers, managing daily operations, coaching growth, and ensuring quality results. The role involves threat hunting, alert triage, security investigations, and DFIR, with an emphasis on leveraging AI and automation to optimize workflows and improve security posture.

What you'd actually do

  1. Manage day-to-day team operations - establish clear goals, performance expectations, and accountability for direct reports; monitor progress and ensure timely delivery of quality results.
  2. Develop and coach incident responders - provide candid, real-time feedback; advise on career growth; and foster a culture of investigation excellence, prioritizing depth and accuracy of analysis.
  3. Proactively identify and fill talent gaps - participate in hiring decisions with a focus on candidates who will amplify GitLab's values and raise the team's technical bar.
  4. Drive engagement and retention - recognize team member contributions, address engagement risks early, and create an environment of open feedback and psychological safety.
  5. Cascade organizational context - translate division and company-wide strategy into clear, actionable team priorities; keep team members informed in a timely manner.

Skills

Required

  • People management
  • Incident response
  • Security investigations
  • Threat hunting
  • DFIR
  • Coaching
  • Performance management
  • Hiring
  • Team development
  • Process improvement
  • Collaboration
  • Communication

Nice to have

  • AI and automation for workflow optimization
  • Shift-left security practices
  • FedRAMP

What the JD emphasized

  • manage the day-to-day work of a team of incident response engineers
  • setting clear performance expectations
  • coaching their growth
  • holding the team accountable for delivering quality results
  • strong technical background
  • owning the full incident lifecycle
  • skilled at developing others
  • sound operational decisions under pressure
  • actively looks for opportunities to "shift left"
  • improving defenses
  • leveraging AI and automation to optimize team workflows
  • implement program direction
  • maintain a culture of high performance
  • defend GitLab infrastructure and products
  • availability during US West Coast business hours
  • Some after-hours and weekend coverage may be required
  • high-severity incidents
  • Proven people management experience
  • track record of managing and developing a team of security engineers
  • setting performance expectations
  • providing coaching
  • driving accountability for results
  • Incident response leadership
  • demonstrated experience leading complex incident response operations
  • large-scale incident response