Description
We're looking for a manager to lead the GitLab security incident response team (SIRT) in the Americas region. The team is responsible for managing and investigating cybersecurity incidents across all GitLab operating environments and operates in a tierless SOC model.
In this role, you will manage the day-to-day work of a team of incident response engineers, setting clear performance expectations, coaching their growth, and holding the team accountable for delivering quality results. You should have a strong technical background, be comfortable owning the full incident lifecycle from alert triage to retrospective actions, and be skilled at developing others to do the same.
We are looking for someone who makes sound operational decisions under pressure and who actively looks for opportunities to 'shift left' - improving defenses and leveraging AI and automation to optimize team workflows. You will implement program direction, maintain a culture of high performance, and defend GitLab infrastructure and products, including GitLab.com, GitLab Dedicated, and GitLab Dedicated for Government (FedRAMP).
This role requires availability during US West Coast business hours. Candidates based on the West Coast are preferred, though candidates in other time zones who are comfortable working these hours are also welcome to apply. Some after-hours and weekend coverage may be required to support engineers during high-severity incidents.
Key Responsibilities:
- Manage day-to-day team operations, establishing clear goals, performance expectations, and accountability for direct reports;
- Develop and coach incident responders, providing candid, real-time feedback, advising on career growth, and fostering a culture of investigation excellence;
- Proactively identify and fill talent gaps, participating in hiring decisions with a focus on candidates who will amplify GitLab's values and raise the team's technical bar;
- Drive engagement and retention, recognizing team member contributions, addressing engagement risks early, and creating an environment of open feedback and psychological safety;
- Cascade organisational context, translating division and company-wide strategy into clear, actionable team priorities;
- Implement and mature incident response processes, building and improving runbooks, procedures, and team capabilities;
- Lead incident response, serving as an escalation point and incident commander for high-severity events;
- Enable cross-functional collaboration, coordinating effectively with peer SecOps teams, Legal, Customer Support, and Infrastructure;
- Align the team on defensive improvements, driving insights from alerts, investigations, and incidents to improve GitLab's security posture;
- Champion remote-first practices, consistently modelling and coaching team members on GitLab's remote working best practices, async communication norms, and handbook-first culture.
Key Requirements:
- Proven people management experience, track record of managing and developing a team of security engineers;
- Incident response leadership, demonstrated experience leading complex incident response operations;
- Hands-on technical background, experience conducting security investigations and log analysis using SIEM tools;
- Customer-facing credibility, comfortable representing GitLab Security during customer escalations and high-visibility cybersecurity discussions;
- Proactive hunting and threat intelligence, proficiency in threat hunting based on intelligence;
- AI and automation mindset, experience using AI/LLMs to improve incident response workflows and automate repetitive processes;
- Platform familiarity, experience using GitLab (or a comparable DevSecOps platform) for project tracking;
- Prioritisation under pressure, ability to make sound operational decisions quickly.