# Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA

**Company**: GitLab
**Location**: Remote, EMEA
**Work arrangement**: remote
**Experience**: senior
**Job type**: full-time
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/gitlab/jobs/8628447002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_a1fe4ad6-ec6

## Description

As a Senior Security Engineer on GitLab's Security Incident Response Team (SIRT), you will play a critical role in defending GitLab.com and the broader GitLab environment against evolving security threats.

You will lead high-impact incidents and investigations, drive continuous improvements in defense, detection and response capabilities, and help scale security operations through automation and intelligent workflows.

Operating within a 24/7 global environment (follow the sun model), you will own incidents end-to-end - from detection and triage through containment, eradication, and recovery - while partnering cross-functionally to strengthen GitLab's overall security posture.

Key responsibilities include:

- Leading and coordinating end-to-end incident response for high-severity security events within a 24/7 global on-call model

- Preparing clear executive communications that keep stakeholders informed during incidents

- Investigating complex security incidents across cloud environments, applying strong Digital Forensics and Incident Response (DFIR) methodologies

- Partnering with Signals Engineering to design and implement detection capabilities

- Building and enhancing automation and AI-assisted workflows to improve triage, investigation speed, and response consistency

- Conducting root cause analysis (RCA) and leading post-incident reviews to drive continuous improvement and risk reduction

Requirements:

- Strong experience in security incident response and investigations in cloud-first environments

- Experience using or administering Git/GitLab in a security or engineering context

- Hands-on experience with SIEM, EDR, and/or detection engineering

- Experience with cloud platforms (AWS & GCP)

- Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK)

- Experience building or working with automation (e.g., Python, scripting, SOAR platforms)

- Strong analytical and problem-solving skills; ability to operate effectively during high-severity incidents

- Excellent written communication skills with a passion for clear, actionable documentation

Benefits:

- Benefits to support your health, finances, and well-being

- Flexible Paid Time Off

- Team Member Resource Groups

- Equity Compensation & Employee Stock Purchase Plan

- Growth and Development Fund

- Parental Leave

## Skills

### Required
- security incident response
- Digital Forensics and Incident Response (DFIR)
- SIEM
- EDR
- detection engineering
- cloud platforms (AWS & GCP)
- threat intelligence
- adversary tactics (MITRE ATT&CK)
- automation (Python, scripting, SOAR platforms)

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/gitlab/jobs/8628447002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
