SlipstreamJobsFresh Startup & VC-Backed Jobs

Intermediate Security Engineer, Security Incident Response Team (SIRT)

GitLab - Remote - Remote - posted 2026-09-09

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

GitLab is seeking an Intermediate Security Engineer to join its Security Incident Response Team (SIRT), operating on a compressed 4-day work schedule with shifts running either Sunday–Wednesday or Wednesday–Saturday to provide 24/7/365 security coverage. In this role, you will be on the frontline of protecting GitLab.com and the GitLab company from security threats. Your primary responsibilities include detecting and responding to security incidents during scheduled shifts, working extensively with incident response automation tools to investigate, analyze, and resolve security events. You'll develop expertise using GitLab's security infrastructure to monitor for threats, analyze potential incidents, and coordinate response efforts across teams. Key responsibilities include leading security incident response in the 24/7 global rotation, managing incidents from detection through containment and recovery; creating and maintaining comprehensive incident response documentation, including runbooks and standard procedures; conducting post-incident analysis through root cause analysis (RCA) and lessons-learned reviews; designing and implementing automated security processes to improve operational efficiency; driving continuous improvement by identifying security gaps and implementing advanced detection and response capabilities; and collaborating across GitLab teams to develop new security capabilities and deliver technical projects that enhance infrastructure. You should thrive in high-pressure environments, remain calm while following prepared runbooks, and think critically about security challenges. This position is ideal for someone who wants to grow their incident response skills while working within GitLab's established security framework, learning to think both tactically and strategically about security while gaining hands-on experience handling real-world incidents. Required qualifications include demonstrated ability to learn and lead incident response processes independently, experience with SIEM/security logging tools, experience with cloud platforms (GCP and/or AWS), Python programming skills or strong willingness to learn, and a passion for technical documentation. A proactive approach to identifying and investigating security issues is essential.

Similar roles