Intermediate Security Engineer, Security Incident Response Team (SIRT)

GitLab
Australia
Workplace: RemoteFull timeFunction: CybersecuritySkills: ["Documentation","Proactive threat investigation","Critical thinking","Analytical problem-solving","Calm under pressure"]

Work as an Intermediate Security Engineer on the Security Incident Response Team (SIRT), covering incidents across a 24/7 global rotation with a compressed 4-day schedule. Detect, investigate, analyze, and resolve security events using incident response automation tools, and help strengthen GitLab’s runbooks, documentation, and security infrastructure. Contribute to automated security processes, perform post-incident RCA and lessons learned, and collaborate with cross-regional teams to improve detection and response capabilities.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GitLab
GitLab
1 day ago

Intermediate Security Engineer, Security Incident Response Team (SIRT)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Work as an Intermediate Security Engineer on the Security Incident Response Team (SIRT), covering incidents across a 24/7 global rotation with a compressed 4-day schedule. Detect, investigate, analyze, and resolve security events using incident response automation tools, and help strengthen GitLab’s runbooks, documentation, and security infrastructure. Contribute to automated security processes, perform post-incident RCA and lessons learned, and collaborate with cross-regional teams to improve detection and response capabilities.
Location: Australia
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Lead security incident response during a 24/7 global rotation, managing incidents from detection through containment and recovery.
  • •Create and maintain incident response documentation, including runbooks and standard procedures.
  • •Conduct post-incident analysis using RCA and lessons-learned reviews to improve the incident response program.
  • •Design and implement automated security processes to reduce manual intervention and improve efficiency.
  • •Collaborate across GitLab teams to develop security capabilities and deliver technical projects that enhance infrastructure.

Pay and Benefits

Schedule:4-Day Week
Perks:Paid LeaveEquityLearning BudgetParental Leave

Key Requirements

  • •Independently learn and lead incident response processes.
  • •Experience with SIEM and/or security logging tools.
  • •Hands-on experience with cloud platforms such as GCP and/or AWS.
  • •Python programming skills or a strong willingness to learn Python.
  • •Strong interest in technical documentation and conducting forensic analysis of infected hosts.
Experience:DevSecOpsIncident responseSecurity operationsSecurity investigations
Skills:DocumentationProactive threat investigationCritical thinkingAnalytical problem-solvingCalm under pressure
Languages:English
Tech Stack:PythonSIEMGCPAWS

Company Brief

GitLab
Provides a single application for the complete DevSecOps lifecycle, offering source code management, CI/CD, security, and collaboration tools to help teams deliver software faster and more securely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2011
WebsiteLinkedIn