Senior Security Engineer
Core
Lead end-to-end incident response and investigations for high-severity security events in a 24/7 global on-call model, defending GitLab.com and cloud environments.
Role type
Senior Security Engineer (Incident Response & DFIR)
Builds
Scalable detection and response systems, automation workflows, and AI-assisted triage pipelines.
Domain
Cybersecurity, Cloud Security, Digital Forensics and Incident Response (DFIR)
Deliverable
client delivery | production ML models | dashboards & analysis
Required skills
Security incident response, Digital Forensics and Incident Response (DFIR), SIEM administration, Cloud security (AWS & GCP), Threat intelligence, Automation (Python, SOAR), Git/GitLab security context
Preferred skills
AI/ML application in detection workflows, Adversary tactics knowledge (MITRE ATT&CK), Executive communication
Technologies
SIEM, EDR, SOAR, Python, AWS, GCP, GitLab
Responsibilities
Lead and coordinate end-to-end incident response for high-severity security events; Investigate complex security incidents across cloud environments; Build and enhance automation and AI-assisted workflows; Conduct root cause analysis and lead post-incident reviews; Partner with Signals Engineering to design detection capabilities; Mentor other engineers on incident response maturity
Seniority
Senior, hands-on IC with mentorship responsibilities