Senior Security Engineer Security Incident Response Team EMEA
GitLab is an AI-powered DevSecOps platform that unifies the entire software development lifecycle into a single application. It helps development, security, and operations teams to collaborate and deliver software more efficiently, with security integrated at every step. The platform is trusted by millions of users and a majority of the Fortune 100.
About GitLab Inc.
GitLab is a comprehensive, AI-powered DevSecOps platform that streamlines the entire software delivery process by unifying the development lifecycle into a single application. It integrates source code management, CI/CD, security, and monitoring to help teams build, secure, and operate software more efficiently. Key features include automated security scans built into the development pipeline and AI-driven tools like GitLab Duo for code suggestions and chat, which enhance developer productivity. GitLab serves a diverse client base, from startups and open-source projects to large enterprises, including over half of the Fortune 100. The platform aims to reduce complexity, accelerate delivery cycles, and strengthen security and compliance for its users.
Skills
About the Role
You will lead high-severity security incidents from detection and triage through containment, eradication, and recovery. You will investigate cloud security events using DFIR methods, improve detections and telemetry, build automated and AI-assisted response workflows, communicate with stakeholders, conduct post-incident reviews, and maintain operational documentation.
Requirements
- Security incident response and investigation experience in cloud-first environments
- Git or GitLab experience in a security or engineering context
- SIEM, EDR, or detection engineering experience
- AWS and GCP experience
- Threat intelligence and adversary tactics knowledge, including MITRE ATT&CK
- Automation experience with Python, scripting, or SOAR platforms
- AI, machine learning, or data-driven detection, triage, or response experience or interest
- Analytical problem-solving
- Written communication
- Documentation
Responsibilities
- Lead and coordinate end-to-end incident response for high-severity security events during EMEA business hours within a 24/7 global on-call model
- Prepare executive communications during incidents
- Investigate complex cloud security incidents using DFIR methodologies
- Partner with Signals Engineering to design and implement SIEM use cases, alerting strategies, and telemetry pipelines
- Build and enhance automation and AI-assisted workflows for triage, investigations, and response
- Partner with Threat Intelligence to improve threat context and detection coverage
- Conduct root cause analysis and lead post-incident reviews
- Develop and maintain runbooks, playbooks, and operational documentation
- Collaborate cross-functionally during incidents and lead proactive initiatives such as tabletops
- Mentor engineers and improve incident response maturity
Benefits
- Health, financial, and well-being benefits
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity compensation
- Employee Stock Purchase Plan
- Parental Leave
