GitLab logo
GitLab

GitLab, founded in 2011 and based in San Francisco, California, maintains a distributed team of professionals that work remotely across multiple continents. Git

Manager, Security Incident Response Team

Location

United States

Posted

73 days ago

Salary

$150K - $235K / year

Seniority

Senior

Job Description

Manager, Security Incident Response Team

GitLab

• Manage day-to-day team operations - establish clear goals, performance expectations, and accountability for direct reports; monitor progress and ensure timely delivery of quality results. • Develop and coach incident responders - provide candid, real-time feedback; advise on career growth; and foster a culture of investigation excellence, prioritizing depth and accuracy of analysis. • Proactively identify and fill talent gaps - participate in hiring decisions with a focus on candidates who will amplify GitLab's values and raise the team's technical bar. • Drive engagement and retention - recognize team member contributions, address engagement risks early, and create an environment of open feedback and psychological safety. • Cascade organizational context - translate division and company-wide strategy into clear, actionable team priorities; keep team members informed in a timely manner. • Implement and mature incident response processes - build and improve runbooks, procedures, and team capabilities that translate functional plans into tactical execution. • Lead incident response - serve as an escalation point and incident commander for high-severity events, including occasional nights and weekends; model the standard for quality investigations. • Enable cross-functional collaboration - coordinate effectively with peer SecOps teams, Legal, Customer Support, and Infrastructure to resolve incidents and close defense gaps through actionable retrospective mitigations. • Align the team on defensive improvements - drive insights from alerts, investigations, and incidents to improve GitLab's security posture and support a "shift left" mindset. • Champion remote-first practices - consistently model and coach team members on GitLab's remote working best practices, async communication norms, and handbook-first culture.

Job Requirements

  • Proven people management experience - track record of managing and developing a team of security engineers, setting performance expectations, providing coaching, and driving accountability for results.
  • Incident response leadership - demonstrated experience leading complex incident response operations, including large-scale incident coordination and the full lifecycle from triage to retrospective.
  • Hands-on technical background - experience conducting security investigations and log analysis using SIEM tools (e.g., Splunk, Elastic); working knowledge of GCP and/or AWS, including cloud forensics.
  • Customer-facing credibility - comfortable representing GitLab Security during customer escalations and high-visibility cybersecurity discussions.
  • Proactive hunting and threat intelligence - proficiency in threat hunting based on intelligence, and familiarity with supply chain threats targeting SaaS platforms.
  • AI and automation mindset - experience using AI/LLMs to improve incident response workflows and automate repetitive processes.
  • Platform familiarity - experience using GitLab (or a comparable DevSecOps platform) for project tracking; bonus if you have experience responding to threats against a SaaS platform.
  • Prioritization under pressure - ability to make sound operational decisions quickly, escalate issues cleanly, and guide the team on balancing what is urgent versus what is important.
  • Due to government requirements, you must be a United States Citizen (defined as any individual who is a citizen of the United States by law, birth, or naturalization) to fill this position.

Benefits

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Related Categories

Related Job Pages

More Security Operations Jobs

GuidePoint Security logo

Security Consultant – Identity, SecOps

GuidePoint Security

We help organizations make smarter cybersecurity decisions that minimize risk.

Full TimeRemoteTeam 201-500H1B Sponsor

• Assess, design, and improve Microsoft Entra ID / Azure AD environments • Implement and harden foundational M365 and Azure security controls • Support Identity governance, MFA, Conditional Access, PIM, RBAC, and passwordless initiatives • Assist customers with FIDO2 security key deployments and identity hardening strategies • Perform Security Architecture Reviews and technical assessments • Develop actionable remediation recommendations and implementation roadmaps • Support ITDR, SIEM, SOC, and Zero Trust aligned initiatives • Work hands-on within customer environments to validate and implement recommendations • Produce high-quality customer deliverables and technical documentation • Serve as a trusted advisor to customer security and IT teams

District Of Columbia + 5 moreAll locations: District Of Columbia | New Jersey | North Carolina | Maryland | Pennsylvania | Virginia
Job Closed
Ethics Code logo

Senior Security Operations Analyst, SOC

Ethics Code

A freelancing platform headquartered in LATAM

Full TimeRemoteTeam 51-200H1B No Sponsor

• Monitor security alerts and events on a daily basis using Microsoft Defender and other security tools. • Investigate suspicious activities, incidents, and anomalies on endpoints and corporate accounts. • Document security incidents and follow up on corrective actions. • Generate biweekly and monthly reports on: - Detected incidents - Relevant alerts - Policy compliance - Corporate device status - Security metrics • Verify compliance with corporate policies on laptops and assigned devices. • Monitor access controls, MFA, and user activity. • Collaborate with internal audits and compliance processes. • Maintain evidence and documentation required for SOC 2 audits. • Participate in periodic reviews of access permissions and corporate assets. • Escalate critical incidents according to established procedures. • Propose continuous improvements in security controls and monitoring.

India
Job Closed
TASC (Total Administrative Services Corporation) logo

Senior Security Operations Engineer

TASC (Total Administrative Services Corporation)

Our mission is to improve the health, wealth, and well-being of our customers, employees, and community

Full TimeRemoteTeam 501-1,000Since 1975H1B No Sponsor

• Own day-to-day security operations for AWS-based cloud and serverless workloads including threat detection, alert triage, incident response, forensics, and post-incident learning. • Build and tune detections and automations (SIEM rules, SOAR/runbooks, detection-as-code) to reduce MTTA/MTTR and eliminate noisy alerts. • Secure our delivery pipelines & runtime Harden CI/CD and software supply chain, and drive “secure by default” patterns in our SDLC. • Lead cloud/serverless hardening (IaC reviews, policy-as-code, least privilege IAM design, network segmentation). • Partner with DevOps and Engineering teams to evolve identity & access, endpoint/EDR posture. • Coordinate vulnerability management end-to-end: scanning, prioritization, remediation, and reporting. • Contribute to security governance (policies, standards, tabletop exercises, BCP/DR inputs) and support compliance efforts (e.g., SOC 2/PCI DSS). • Build security tooling and integrations for engineers, acknowledging that ease of use and low friction will encourage adoption and adherence. • Define metrics/KPIs and regularly communicate risk & progress to engineering and leadership. • Mentor engineers on secure design and champion a positive, enablement-first security culture. • Participate in architecture and threat modeling discussions to identify security risks early in the design process.

United States
Full TimeRemoteTeam 5,001-10,000Since 1995H1B No Sponsor

• Collaborate with cross-functional teams to design, implement, and manage our security and identity platforms. • Develop, integrate, and maintain account- and system-provisioning solutions as we progress toward a Zero Trust architecture. • Partner with application owners and business stakeholders to provide security subject-matter expertise and guidance on security standards and policies to protect customers and maintain a secure environment. • Administer identity and security operations platforms (e.g., Okta, Active Directory, Active Directory Certificate Services (ADCS), ADFS, Azure, Intune, AWS/IAM, certificate and secrets management). • Manage Active Directory deployments and rebuild the ADCS environment. • Lead and contribute to Okta projects and manage permissions effectively. • Provide Tier 3 support for all Identity and Security Operations issues. • Develop policies and procedures for identity and security systems. • Serve as a subject-matter expert (SME) for SSO, SAML, and SCIM for application owners and business stakeholders. • Work closely with other security and infrastructure teams to proactively identify, protect, and defend the enterprise from cybersecurity threats and to resolve complex issues. • Mentor and train other team members. • Participate in on-call rotations as required.

Brazil