Senior Security Engineer, Security Incident Response Team (sirt)

GitLab GitLab · Enterprise · United States · Remote · Security Operations

Senior Security Engineer for GitLab's Security Incident Response Team (SIRT). This role focuses on defending GitLab.com and its environment against security threats, supporting FedRAMP, and leveraging automation and AI-driven approaches to improve detection, investigation, and response. Requires U.S. citizenship and residency.

What you'd actually do

  1. Lead and coordinate end-to-end incident response for high-severity security events within a 24/7 global on-call model, with this role operating during U.S. business hours.
  2. Prepare clear executive communications that keep stakeholders informed during incidents
  3. Investigate complex security incidents across cloud environments, applying strong Digital Forensics and Incident Response (DFIR) methodologies
  4. Partnering with Signals Engineering to design and implement detection capabilities, including SIEM use cases, alerting strategies, and telemetry pipelines
  5. Build and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistency

Skills

Required

  • Strong experience in security incident response and investigations in cloud-first environments
  • Experience using or administering Git/GitLab in a security or engineering context
  • Hands-on experience with SIEM, EDR, and/or detection engineering
  • Experience with cloud platforms (AWS & GCP)
  • Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK)
  • Experience building or working with automation (e.g., Python, scripting, SOAR platforms)
  • Strong analytical and problem-solving skills; ability to operate effectively during high-severity incidents
  • Excellent written communication skills with a passion for clear, actionable documentation
  • United States Citizen

Nice to have

  • Interest or experience in applying AI/ML or data-driven techniques to detection, triage, or response workflows
  • Growth mindset with a proactive approach to identifying and mitigating security risks

What the JD emphasized

  • U.S. citizenship
  • residency within the United States
  • AI-assisted workflows