SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
GitLab is seeking a Senior Security Engineer for its Security Incident Response Team (SIRT), a globally distributed team operating 24/7 across AMER, APAC, and EMEA regions. This role covers the APAC window with rotating on-call responsibilities.
You will lead end-to-end incident response for high-severity security events affecting GitLab.com and GitLab's cloud and corporate environments. Your responsibilities include investigating complex security incidents across cloud environments using Digital Forensics and Incident Response (DFIR) methodologies, leading incident coordination and triage, and preparing executive communications for stakeholders. You will partner with Detection Engineering to design SIEM use cases, alerting strategies, and telemetry pipelines, while collaborating with Threat Intelligence to contextualize threats and improve detection coverage.
A key focus is building and enhancing automation and AI-assisted workflows to improve investigation speed, triage efficiency, and response consistency. You will conduct root cause analysis, lead post-incident reviews, develop and maintain runbooks and playbooks, and mentor other engineers to elevate the team's incident response maturity. Cross-functional collaboration with Engineering, Infrastructure, Legal, Product, and Communications teams is essential, particularly during incidents and proactive initiatives like tabletop exercises.
The role emphasizes leveraging modern tooling, data-driven approaches, and AI to stay ahead of evolving adversary tactics while maintaining operational excellence in a high-tempo environment.
**Requirements:**
- Strong experience in security incident response and investigations in cloud-first environments
- Experience using or administering Git/GitLab in a security or engineering context
- Hands-on experience with SIEM, EDR, and/or detection engineering
- Experience with cloud platforms (AWS and GCP)
- Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK)
- Experience building or working with automation (e.g., Python, scripting, SOAR platforms)
- Interest or experience in applying AI/ML or data-driven techniques to detection, triage, or response workflows
- Strong analytical and problem-solving skills with ability to operate effectively during high-severity incidents
- Excellent written communication skills with passion for clear, actionable documentation
- Growth mindset with proactive approach to identifying and mitigating security risks