Senior Security Engineer, Incident Response Team (Australia)

GitLab
Australia
Workplace: RemoteFull timeFunction: CybersecuritySkills: ["Analytical thinking","Problem-solving","Written communication","Mentoring","Growth mindset"]

Lead end-to-end incident response for high-severity security events as part of GitLab’s Security Incident Response Team (SIRT). Own detection-to-recovery workflows across the APAC window in a 24/7 follow-the-sun model, partner with Detection Engineering and Threat Intelligence to improve coverage, and build automation and AI-assisted procedures to accelerate investigations, reduce response times, and strengthen GitLab’s overall security posture.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GitLab
GitLab
22 hours ago

Senior Security Engineer, Incident Response Team (Australia)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Lead end-to-end incident response for high-severity security events as part of GitLab’s Security Incident Response Team (SIRT). Own detection-to-recovery workflows across the APAC window in a 24/7 follow-the-sun model, partner with Detection Engineering and Threat Intelligence to improve coverage, and build automation and AI-assisted procedures to accelerate investigations, reduce response times, and strengthen GitLab’s overall security posture.
Location: Australia
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Lead and coordinate end-to-end incident response for high-severity security events across the APAC window within a 24/7 follow-the-sun model.
  • •Investigate complex security incidents across cloud environments using DFIR methodologies and keep stakeholders informed with clear executive communications.
  • •Partner with Detection Engineering to design and implement detection capabilities such as SIEM use cases, alerting strategies, and telemetry pipelines.
  • •Build and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistency.
  • •Conduct RCA and post-incident reviews, maintain runbooks/playbooks, and mentor other engineers to raise incident response maturity.

Pay and Benefits

Perks:Paid LeaveEquityLearning BudgetParental Leave

Key Requirements

  • •Strong experience in security incident response and investigations in cloud-first environments.
  • •Hands-on experience with SIEM and EDR, and/or detection engineering.
  • •Experience with cloud platforms such as AWS and GCP.
  • •Familiarity with threat intelligence and adversary tactics such as MITRE ATT&CK.
  • •Experience building or working with automation (e.g., Python/scripting/SOAR) and applying AI/ML or data-driven techniques to detection, triage, or response workflows.
Experience:Cloud-firstSecurity incident response
Skills:Analytical thinkingProblem-solvingWritten communicationMentoringGrowth mindset
Languages:English
Tech Stack:GitGitLabSIEMEDRDetection engineeringAWSGCPMITRE ATT&CKPythonSOARAI/ML

Company Brief

GitLab
Provides a single application for the complete DevSecOps lifecycle, offering source code management, CI/CD, security, and collaboration tools to help teams deliver software faster and more securely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2011
WebsiteLinkedIn