Senior Threat Engineer
The Senior Threat Engineer designs scalable threat-detection, decisioning, and response workflows, using investigation, automation, and operational data to improve accuracy and reduce manual review. The role requires significant cybersecurity operations experience and strong analytical, communication, and cross-functional collaboration skills.
About the job
Responsibilities
- Design, build, and improve detection, decisioning, and response workflows for the Verdict Engine.
- Own complex threat-detection and workflow problems from investigation concept through implementation, validation, and iteration.
- Translate threat research and investigative reasoning into scalable detections, enrichment, triage logic, and automated decisions.
- Analyze operational data to identify false positives, false negatives, latency issues, and opportunities to improve workflow categories.
- Increase system autonomy, reducing manual review while improving service quality and consistency.
- Support complex or novel cases and incorporate lessons into future automated handling.
- Improve the clarity, accuracy, and calibration of customer-facing outputs.
- Identify customer pain points and use those insights to improve verdict logic, response content, and product behavior.
- Partner with product, engineering, and security teams on platform capabilities, data quality, and operational leverage.
- Define best practices, operating principles, and technical standards for Threat Engineering.
- Document detection concepts, workflow logic, and operating principles.
- Provide technical leadership through execution, judgment, and mentorship.
Requirements
- Significant cybersecurity operations experience in threat detection and response, detection engineering, incident response, threat hunting, or SOC operations.
- Strong investigative and analytical skills, including the ability to convert ambiguous signals into practical detection logic and workflow improvements.
- Experience building, tuning, or maintaining security automations, detections, playbooks, rules, or enrichment pipelines.
- Ability to independently own complex technical or operational problem areas and drive improvements through ambiguity.
- Strong written and verbal communication skills, including documenting logic and explaining threats, tradeoffs, and outcomes.
- Ability to collaborate with product, engineering, and security stakeholders.
- Comfort using data to evaluate detection quality and workflow performance.
- Preference for simple, scalable solutions that reduce unnecessary complexity and manual work.
Nice-to-haves
- Experience in high-volume security operations environments.
- Experience with SIEM, EDR, SOAR, case management, and telemetry enrichment systems.
- Scripting or query-writing experience for investigations, automation, or workflow analysis.
- Experience improving operational quality through experimentation, measurement, and continuous iteration.
- Experience in workflow design, detection engineering, automation, or security product development.
- Experience mentoring engineers, setting technical direction, or influencing detection and response practices.
Benefits
- 100% medical coverage, including outpatient care.
- Life insurance.
- 25+ paid holidays.
- Annual home office stipend.
- 7% employer pension contribution.
- Mental and physical health wellness programs.
- Competitive compensation and advancement opportunities.
Skills
Threat Detection, Incident Response, Threat Hunting, Soc Operations, Detection Engineering, Security Automation, SIEM, Edr, Soar, Playbooks, Security Enrichment Pipelines, Scripting, Query Writing, Workflow Design, Telemetry
Similar jobs
Security Engineering jobsSenior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Build AI-focused detection and response capabilities, investigate incidents, and hunt threats across distributed training and inference infrastructure. The role requires staff-level security engineering experience, including 3+ years securing AI/ML or distributed systems and strong automation and detection skills.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Senior security engineer who red teams formally verified systems, assesses proof and threat-model boundaries, and builds AI-driven vulnerability discovery and exploit-generation tooling. Requires hands-on offensive security, formal methods, systems expertise, software development, and rigorous technical reporting.
Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.