Senior Security Engineer, Security Incident Response Team - EMEA
Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.
About the job
Responsibilities
- Lead and coordinate end-to-end incident response for high-severity security events within a 24/7 global on-call model during EMEA business hours.
- Prepare clear executive communications during incidents.
- Investigate complex security incidents across cloud environments using Digital Forensics and Incident Response (DFIR) methodologies.
- Partner with Signals Engineering to design and implement detection capabilities, including SIEM use cases, alerting strategies, and telemetry pipelines.
- Build and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistency.
- Partner with Threat Intelligence to contextualize threats and improve detection coverage.
- Conduct root cause analysis and lead post-incident reviews to drive continuous improvement and risk reduction.
- Develop and maintain runbooks, playbooks, and operational documentation.
- Collaborate with Engineering, Infrastructure, Legal, Product, and Communications during incidents.
- Lead proactive initiatives such as tabletop exercises.
- Mentor other engineers and help improve the team’s incident response maturity.
Requirements
- Strong experience in security incident response and investigations in cloud-first environments.
- Experience using or administering Git or GitLab in a security or engineering context.
- Hands-on experience with SIEM, EDR, and/or detection engineering.
- Experience with AWS and Google Cloud.
- Familiarity with threat intelligence and adversary tactics, including MITRE ATT&CK.
- Experience building or working with automation, such as Python, scripting, or SOAR platforms.
- Interest or experience applying AI/ML or data-driven techniques to detection, triage, or response workflows.
- Strong analytical and problem-solving skills, with the ability to operate effectively during high-severity incidents.
- Excellent written communication skills and a commitment to clear, actionable documentation.
- Growth mindset and a proactive approach to identifying and mitigating security risks.
Compensation and Benefits
- Benefits supporting health, finances, and well-being.
- Flexible paid time off.
- Team member resource groups.
- Equity compensation and employee stock purchase plan.
- Growth and development fund.
- Parental leave.
Skills
Digital Forensics And Incident Response, SIEM, Edr, Detection Engineering, AWS, GCP, Mitre Att&Ck, Python, Soar, Threat Intelligence, GitLab, AI/ML, Security Automation, Telemetry Pipelines
Similar jobs
Security Engineering jobsSenior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Leads information security governance, compliance, security operations, risk management, and incident response for a healthcare AI company. Requires 5+ years of security experience and hands-on expertise with major compliance frameworks, SIEM, incident response, and third-party risk.
Build AI-focused detection and response capabilities, investigate incidents, and hunt threats across distributed training and inference infrastructure. The role requires staff-level security engineering experience, including 3+ years securing AI/ML or distributed systems and strong automation and detection skills.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Senior security engineer who red teams formally verified systems, assesses proof and threat-model boundaries, and builds AI-driven vulnerability discovery and exploit-generation tooling. Requires hands-on offensive security, formal methods, systems expertise, software development, and rigorous technical reporting.