Overview
In this role you defend GitLab.com and the broader environment by leading high-severity security incidents in a 24/7 global on-call model. You’ll drive DFIR-driven investigations, design detection capabilities with Signals Engineering, and scale security operations through automation and AI. You’ll work across teams to improve posture, develop runbooks, and mentor others while shaping modern tooling and data usage to outpace adversaries. This is a high-tempo, impact-focused opportunity for someone who thrives on incident-driven transformation.
Pay / Benefits
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
Responsibilities
- Lead end-to-end incident response for high-severity events in a 24/7 on-call model (EMEA hours)
- Prepare executive communications to keep stakeholders informed during incidents
- Investigate complex cloud security incidents using DFIR methodologies
- Collaborate with Signals Engineering to design detection capabilities, SIEM use cases, and telemetry pipelines
- Develop automation and AI-assisted workflows to accelerate triage and response
- Work with Threat Intelligence to contextualize threats and improve coverage
- Conduct root cause analysis and lead post-incident reviews to drive improvement
- Maintain runbooks, playbooks, and operational documentation
- Coordinate with cross-functional teams during incidents and proactive exercises (tabletops)
- Mentor engineers and elevate the team’s incident response maturity
Key requirements
- Strong experience in security incident response and investigations in cloud-first environments
- Experience using or administering Git/GitLab in a security or engineering context
- Hands-on experience with SIEM, EDR, and/or detection engineering
- Experience with cloud platforms (AWS & GCP)
- Familiarity with threat intelligence and adversary tactics (MITRE ATT&CK)
- Experience building or working with automation (Python, scripting, SOAR)
- Interest or experience applying AI/ML or data-driven techniques to detection/triage/response workflows
- Strong analytical and problem-solving skills; ability to operate during high-severity incidents
- Excellent written communication for clear, actionable documentation
- Growth mindset with proactive risk mitigation
- Strong communication
- Cross-functional collaboration
- Proactive problem-solving
- DFIR (Digital Forensics and Incident Response)
- SIEM/EDR/detection engineering
- Cloud platforms (AWS, GCP)
…
