Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA
Senior · Удалённо · Израиль · Английский B2
Навыки
AWS
Коммуникация
Решения на данных
DevSecOps
EDR / антивирус
Форензика и реагирование
Google Cloud
Ещё 9
Git
Обучаемость
Machine Learning
Мониторинг и observability
Решение задач
Python
SIEM
SRE-практики
YARA / threat intelligence
О компании и продукте
As a Senior Security Engineer on GitLab’s Security Incident Response Team (SIRT), you will play a critical role in defending GitLab.com and the broader GitLab environment against evolving security threats.
You will lead high-impact incidents and investigations, drive continuous improvements in defense, detection and response capabilities, and help scale security operations through automation and intelligent workflows.
Operating within a 24/7 global environment (follow the sun model), you will own incidents end-to-end - from detection and triage through containment, eradication, and recovery - while partnering cross-functionally to strengthen GitLab’s overall security posture.
A key aspect of this role is leveraging automation and AI-driven approaches to improve detection fidelity, accelerate investigations, and reduce response times. You will help shape how modern tooling and data are applied to stay ahead of evolving adversary tactics.
Задачи
Lead and coordinate end-to-end incident response for high-severity security events within a 24/7 global on-call model, with this role operating during EMEA business hours
Prepare clear executive communications that keep stakeholders informed during incidents
Investigate complex security incidents across cloud environments, applying strong Digital Forensics and Incident Response (DFIR) methodologies
Partnering with Signals Engineering to design and implement detection capabilities, including SIEM use cases, alerting strategies, and telemetry pipelines
Build and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistency
Partner with Threat Intelligence to contextualize threats and improve detection coverage
Conduct root cause analysis (RCA) and lead post-incident reviews to drive continuous improvement and risk reduction
Develop and maintain runbooks, playbooks, and operational documentation
Collaborate cross-functionally (Engineering, Infrastructure, Legal, Product, Communications, etc) during incidents and lead proactive initiatives (e.g. tabletops)
Mentor other engineers and help elevate the team’s overall incident response maturity
Требования
Strong experience in security incident response and investigations in cloud-first environments
Experience using or administering Git/GitLab in a security or engineering context
Hands-on experience with SIEM, EDR, and/or detection engineering
Experience with cloud platforms (AWS & GCP)
Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK)
Experience building or working with automation (e.g., Python, scripting, SOAR platforms)
Interest or experience in applying AI/ML or data-driven techniques to detection, triage, or response workflows
Strong analytical and problem-solving skills
ability to operate effectively during high-severity incidents
Excellent written communication skills with a passion for clear, actionable documentation
Growth mindset with a proactive approach to identifying and mitigating security risks
Паспорт вакансии
История публикации
Появилась в Вакандии30 дней
Перепубликациинетпубликовалась один раз
Проверяли на источникеВидели 30 дней назад
Среди похожихНет данных46 из 30 · у похожих вакансий почти одинаковый возраст — сравнивать нечего
Откуда что взялось
Отмечено то, что вывели мы. Без пометки — значение назвал работодатель.
ГрейдSeniorвычитано из текста вакансии
Формат работыУдалённо
ГеографияИзраильвычитано из текста вакансии
Зарплата≈ 18 000 USD в месяцнаша оценка, в вакансии не названа
Почему на этом месте в выдаче
Порядок выдачи объявлен контрактом: свежесть решает между днями, полнота и зарплата — внутри дня.
Полнота карточки1004 из 4 полей: грейд, формат, география, зарплата
Зарплата названа0вилки работодателя нет, показана наша оценка
Проверка Вакандии
Источники и свежесть
Тип источника
Карьерный сайт работодателя
Найдено публикаций
1
Посмотреть публикации и даты
greenhouseОсновная публикация · 2026-07-10
G
Работодатель
GitLab
50 активных вакансий · вилка работодателя указана в 4%
Вакандия показывает вакансию, но не отправляет отклик и не проверяет работодателя. Сам отклик вы оставляете на внешнем сайте — job-boards.greenhouse.io.
Признаки мошенничества
Просят предоплату, «залог» или деньги за обучение и оборудование.
Требуют код из SMS, данные банковской карты или доступ к «Госуслугам».
Быстро уводят в мессенджер и торопят с решением.
Обещают большой доход без опыта и без деталей задач.
Настоящий работодатель не просит денег и платёжных данных до трудоустройства.
Продолжить поиск
Похожие вакансии
Причина сходства указана на каждой карточке
S
Почему похожа: похожая специализация · тот же грейд