Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA

GitLab
EMEA
Workplace: RemoteFull timeFunction: CybersecuritySkills: ["Analytical thinking","Problem-solving","Written communication","Mentoring","Growth mindset"]

Lead end-to-end incident response for high-severity security events in a 24/7 follow-the-sun environment, operating during EMEA hours. Investigate complex cloud-first incidents using DFIR methods, then partner with Signals Engineering and Threat Intelligence to improve detection coverage. Build automation and AI-assisted workflows to accelerate triage, investigations, and response consistency, while documenting runbooks and mentoring engineers to raise SIRT maturity.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GitLab
GitLab
1 month ago

Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Lead end-to-end incident response for high-severity security events in a 24/7 follow-the-sun environment, operating during EMEA hours. Investigate complex cloud-first incidents using DFIR methods, then partner with Signals Engineering and Threat Intelligence to improve detection coverage. Build automation and AI-assisted workflows to accelerate triage, investigations, and response consistency, while documenting runbooks and mentoring engineers to raise SIRT maturity.
Location: EMEA
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Coordinate end-to-end incident response for high-severity security events within a 24/7 on-call model during EMEA hours.
  • •Investigate complex security incidents across cloud environments using DFIR methodologies and communicate clearly with stakeholders during incidents.
  • •Partner with Signals Engineering to design and implement detection capabilities, including SIEM use cases, alerting strategies, and telemetry pipelines.
  • •Build and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistency.
  • •Conduct RCA and lead post-incident reviews; maintain runbooks and playbooks, and mentor engineers to improve incident response maturity.

Pay and Benefits

Equity and Bonus:Equity
Perks:Paid LeaveEquityParental LeaveLearning Budget

Key Requirements

  • •Strong experience in security incident response and investigations in cloud-first environments.
  • •Hands-on experience with SIEM and EDR, and/or detection engineering.
  • •Experience with cloud platforms (AWS and GCP).
  • •Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK).
  • •Experience building automation (e.g., Python, scripting, SOAR platforms) and interest in AI/ML or data-driven detection workflows.
Experience:Cloud securityDFIRIncident responseDetection engineering
Skills:Analytical thinkingProblem-solvingWritten communicationMentoringGrowth mindset
Languages:English
Tech Stack:SIEMEDRAWSGCPGitGitLabPythonSOARMITRE ATT&CKAI/ML

Company Brief

GitLab
Provides a single application for the complete DevSecOps lifecycle, offering source code management, CI/CD, security, and collaboration tools to help teams deliver software faster and more securely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2011
WebsiteLinkedIn