Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA

GitLab

Source: GreenhouseLocation: EU/EMEAPublished: Jul 10, 2026Confirmed active: Sep 11, 2026
Full-time40 hrs/weekTechnology

Our assessment

  • Our reading of the full posting text confirms it: fully remote.
  • 35 more open roles from this employer in our index. 35 of them fully remote.

This section only: calculated automatically by nomado24, from our own job index and our own reading of the posting text. Not stated by the employer.

Job description

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.

The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software.

  • Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.

An overview of this role

As a Senior Security Engineer on GitLab’s Security Incident Response Team (SIRT), you will play a critical role in defending GitLab.com and the broader GitLab environment against evolving security threats. This role operates on a compressed 4-day work schedule, with a full-time week's hours condensed into four longer working days. Shifts run either Sunday through Wednesday or Wednesday through Saturday to provide 24/7/365 security coverage.

You will lead high-impact incidents and investigations, drive continuous improvements in defense, detection and response capabilities, and help scale security operations through automation and intelligent workflows.

Operating within a 24/7 global environment (follow the sun model), you will own incidents end-to-end - from detection and triage through containment, eradication, and recovery - while partnering cross-functionally to strengthen GitLab’s overall security posture. A key aspect of this role is leveraging automation and AI-driven approaches to improve detection fidelity, accelerate investigations, and reduce response times. You will help shape how modern tooling and data are applied to stay ahead of evolving adversary tactics.

This role is ideal for someone who thrives in high-tempo environments, brings strong DFIR expertise, and is equally passionate about operational excellence and building scalable detection and response systems and workflows.

What you’ll do

  • Lead and coordinate end-to-end incident response for high-severity security events within a 24/7 global on-call model, with this role operating during EMEA business hours
  • Prepare clear executive communications that keep stakeholders informed during incidents
  • Investigate complex security incidents across cloud environments, applying strong Digital Forensics and Incident Response (DFIR) methodologies
  • Partnering with Signals Engineering to design and implement detection capabilities, including SIEM use cases, alerting strategies, and telemetry pipelines
  • Build and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistency
  • Partner with Threat Intelligence to contextualize threats and improve detection coverage
  • Conduct root cause analysis (RCA) and lead post-incident reviews to drive continuous improvement and risk reduction
  • Develop and maintain runbooks, playbooks, and operational documentation
  • Collaborate cross-functionally (Engineering, Infrastructure, Legal, Product, Communications, etc) during incidents and lead proactive initiatives (e.g. tabletops)
  • Mentor other engineers and help elevate the team’s overall incident response maturity

What you’ll bring

  • Strong experience in security incident response and investigations in cloud-first environments
  • Experience using or administering Git/GitLab in a security or engineering context
  • Hands-on experience with SIEM, EDR, and/or detection engineering
  • Experience with cloud platforms (AWS & GCP)
  • Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK)
  • Experience building or working with automation (e.g., Python, scripting, SOAR platforms)
  • Interest or experience in applying AI/ML or data-driven techniques to detection, triage, or response workflows
  • Strong analytical and problem-solving skills; ability to operate effectively during high-severity incidents
  • Excellent written communication skills with a passion for clear, actionable documentation
  • Growth mindset with a proactive approach to identifying and mitigating security risks

About the team

The Security Incident Response …

greenhouseSecurity Operationsen

This role is provided by an external source. Applications are handled on the source website.

New remote jobs like “Security Engineer” by email

Only when something fitting appears. Free, unsubscribe any time.

You confirm your subscription by email (double opt-in) and can unsubscribe at any time via the link in every email. Our Privacy Policy.

Prepare your application with AI

Have the AI advisor draft a cover letter, analyze how your profile fits this role, and prep you for the interview.

Sign in & prepare with AI

Free, you'll continue right where you left off after signing in.

Or let us search for you

Matching job categories

Not the right job?