The opportunity
The Security Incident Response Team (SIRT) is a globally distributed team of engineers split across 3 core regions; AMER, APAC and EMEA, and is at the forefront of security events that impact both GitLab. com and GitLab cloud and corporate environments.
What you'll do
Lead and coordinate end-to-end incident response for high-severity security: events within a 24/7 global on-call model, with this role operating during EMEA business hours
Prepare clear executive communications that keep stakeholders informed during incidents
Investigate complex security incidents across cloud environments, applying: strong Digital Forensics and Incident Response (DFIR) methodologies
Partnering with Signals Engineering to design and implement detection: capabilities, including SIEM use cases, alerting strategies, and telemetry pipelines
Build and enhance automation and AI-assisted workflows to improve triage,: investigation speed, and response consistency
Partner with Threat Intelligence to contextualize threats and improve detection coverage
What they're looking for
- Conduct root cause analysis (RCA) and lead post-incident reviews to drive: continuous improvement and risk reduction
- Develop and maintain runbooks, playbooks, and operational documentation
- Collaborate cross-functionally (Engineering, Infrastructure, Legal, Product,: Communications, etc) during incidents and lead proactive initiatives (e.g. tabletops)
- Mentor other engineers and help elevate the team’s overall incident response maturity