Skip to main content
GitLab

Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA

RemoteEMEA
Published
Role
Fullstack
Experience
Senior
Employment
Full-time
Salary not disclosed
Check eligibility

Open to Anywhere in EMEA. Set where you work from to check your eligibility.

No BS summary

As a Senior Security Engineer on GitLab’s Security Incident Response Team (SIRT), you will play a critical role in defending GitLab.com and the broader GitLab environment against evolving security threats.

Core skills

Security Incident ResponseDigital ForensicsDetection Engineering

Required skills

GitGitLabSIEMEDRCloud Platforms/AWS/GCPAutomation/Python/SOARMITRE ATT&CK

Optional skills

AI/MLdata-driven techniques

Required languages

English unknown

What you'll do

  • Lead and coordinate end-to-end incident response for high-severity security events within a 24/7 global on-call model, with this role operating during EMEA business hours
  • Prepare clear executive communications that keep stakeholders informed during incidents
  • Investigate complex security incidents across cloud environments, applying strong Digital Forensics and Incident Response (DFIR) methodologies
  • Partnering with Signals Engineering to design and implement detection capabilities, including SIEM use cases, alerting strategies, and telemetry pipelines
  • Build and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistency
  • Partner with Threat Intelligence to contextualize threats and improve detection coverage
  • Conduct root cause analysis (RCA) and lead post-incident reviews to drive continuous improvement and risk reduction
  • Develop and maintain runbooks, playbooks, and operational documentation
  • Collaborate cross-functionally (Engineering, Infrastructure, Legal, Product, Communications, etc) during incidents and lead proactive initiatives (e.g. tabletops)
  • Mentor other engineers and help elevate the team’s overall incident response maturity

What they require

  • Strong experience in security incident response and investigations in cloud-first environments
  • Experience using or administering Git/GitLab in a security or engineering context
  • Hands-on experience with SIEM, EDR, and/or detection engineering
  • Experience with cloud platforms (AWS & GCP)
  • Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK)
  • Experience building or working with automation (e.g., Python, scripting, SOAR platforms)
  • Interest or experience in applying AI/ML or data-driven techniques to detection, triage, or response workflows
  • Strong analytical and problem-solving skills; ability to operate effectively during high-severity incidents
  • Excellent written communication skills with a passion for clear, actionable documentation
  • Growth mindset with a proactive approach to identifying and mitigating security risks

Benefits

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100 trust GitLab to ship better, more secure software faster.

🇺🇸 United StatesSoftwareEnterpriseabout.gitlab.com/

What people say about this company

3.3/ 5

  • Flexible remote work options are highly valued by employees.
  • Many employees appreciate the open-source nature of the product and the company's commitment to transparency.
  • Some employees report challenges with management and communication within teams.
Salary not disclosed