GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to enhance developer productivity and reduce security risks. The Senior Security Engineer will lead incident response for high-severity security events, drive improvements in security operations, and leverage automation and AI to enhance detection and response capabilities.
Responsibilities:
- Lead and coordinate end-to-end incident response for high-severity security events within a 24/7 global on-call model, with this role operating during U.S. business hours
- Prepare clear executive communications that keep stakeholders informed during incidents
- Investigate complex security incidents across cloud environments, applying strong Digital Forensics and Incident Response (DFIR) methodologies
- Partnering with Signals Engineering to design and implement detection capabilities, including SIEM use cases, alerting strategies, and telemetry pipelines
- Build and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistency
- Partner with Threat Intelligence to contextualize threats and improve detection coverage
- Conduct root cause analysis (RCA) and lead post-incident reviews to drive continuous improvement and risk reduction
- Develop and maintain runbooks, playbooks, and operational documentation
- Collaborate cross-functionally (Engineering, Infrastructure, Legal, Product, Communications, etc) during incidents and lead proactive initiatives (e.g. tabletops)
- Mentor other engineers and help elevate the team’s overall incident response maturity
Requirements:
- U.S. citizenship and residency within the United States
- Strong experience in security incident response and investigations in cloud-first environments
- Experience using or administering Git/GitLab in a security or engineering context
- Hands-on experience with SIEM, EDR, and/or detection engineering
- Experience with cloud platforms (AWS & GCP)
- Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK)
- Experience building or working with automation (e.g., Python, scripting, SOAR platforms)
- Interest or experience in applying AI/ML or data-driven techniques to detection, triage, or response workflows
- Strong analytical and problem-solving skills; ability to operate effectively during high-severity incidents
- Excellent written communication skills with a passion for clear, actionable documentation
- Growth mindset with a proactive approach to identifying and mitigating security risks