Skip to main content
GitLab

Senior Security Engineer, Security Incident Response Team (SIRT)

RemoteIsrael, United Kingdom only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to IL, GB only. Set where you work from to check your eligibility.

No BS summary

Senior security incident response engineer for GitLab’s SIRT, working EMEA business hours from Israel or the United Kingdom. Needs cloud-first incident response/DFIR experience, Git/GitLab, SIEM/EDR, AWS/GCP, automation, and threat-intel familiarity.

Core skills

SIEM/EDRIncident ResponseDFIR

Required skills

GitGitLabAWSGCPMITRE ATT&CKPythonScriptingSOAR platformsAI/ML

What you'll do

  • Lead and coordinate end-to-end incident response for high-severity security events in a 24/7 global on-call model during EMEA business hours
  • Prepare clear executive communications during incidents
  • Investigate complex security incidents across cloud environments using DFIR methodologies
  • Partner with Signals Engineering to design and implement detection capabilities, SIEM use cases, alerting strategies, and telemetry pipelines
  • Build and enhance automation and AI-assisted workflows for triage, investigation, and response consistency
  • Partner with Threat Intelligence to contextualize threats and improve detection coverage
  • Conduct root cause analysis and lead post-incident reviews
  • Develop and maintain runbooks, playbooks, and operational documentation
  • Collaborate with Engineering, Infrastructure, Legal, Product, Communications, and other teams during incidents and proactive initiatives
  • Mentor other engineers and improve the team’s incident response maturity

What they require

  • Strong experience in security incident response and investigations in cloud-first environments
  • Experience using or administering Git/GitLab in a security or engineering context
  • Hands-on experience with SIEM, EDR, and/or detection engineering
  • Experience with cloud platforms AWS and GCP
  • Familiarity with threat intelligence and adversary tactics such as MITRE ATT&CK
  • Experience building or working with automation such as Python, scripting, or SOAR platforms
  • Interest or experience in applying AI/ML or data-driven techniques to detection, triage, or response workflows
  • Strong analytical and problem-solving skills
  • Ability to operate effectively during high-severity incidents
  • Excellent written communication skills and clear documentation ability
  • Growth mindset with a proactive approach to identifying and mitigating security risks

Benefits

  • Benefits to support health, finances, and well-being
  • Flexible paid time off
  • Team Member Resource Groups
  • Equity compensation and Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental leave

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100 trust GitLab to ship better, more secure software faster.

🇺🇸 United StatesSoftwareEnterpriseabout.gitlab.com/

What people say about this company

3.3/ 5

  • Flexible remote work options are highly valued by employees.
  • Many employees appreciate the open-source nature of the product and the company's commitment to transparency.
  • Some employees report challenges with management and communication within teams.

Details

Apply routeGreenhouse
Salary not disclosed