GitLab, founded in 2011 and based in San Francisco, California, maintains a distributed team of professionals that work remotely across multiple continents. Git
Manager, Security Incident Response Team
Location
United States
Posted
73 days ago
Salary
$150K - $235K / year
Seniority
Senior
Job Description
Manager, Security Incident Response Team
GitLab
• Manage day-to-day team operations - establish clear goals, performance expectations, and accountability for direct reports; monitor progress and ensure timely delivery of quality results. • Develop and coach incident responders - provide candid, real-time feedback; advise on career growth; and foster a culture of investigation excellence, prioritizing depth and accuracy of analysis. • Proactively identify and fill talent gaps - participate in hiring decisions with a focus on candidates who will amplify GitLab's values and raise the team's technical bar. • Drive engagement and retention - recognize team member contributions, address engagement risks early, and create an environment of open feedback and psychological safety. • Cascade organizational context - translate division and company-wide strategy into clear, actionable team priorities; keep team members informed in a timely manner. • Implement and mature incident response processes - build and improve runbooks, procedures, and team capabilities that translate functional plans into tactical execution. • Lead incident response - serve as an escalation point and incident commander for high-severity events, including occasional nights and weekends; model the standard for quality investigations. • Enable cross-functional collaboration - coordinate effectively with peer SecOps teams, Legal, Customer Support, and Infrastructure to resolve incidents and close defense gaps through actionable retrospective mitigations. • Align the team on defensive improvements - drive insights from alerts, investigations, and incidents to improve GitLab's security posture and support a "shift left" mindset. • Champion remote-first practices - consistently model and coach team members on GitLab's remote working best practices, async communication norms, and handbook-first culture.
Job Requirements
- Proven people management experience - track record of managing and developing a team of security engineers, setting performance expectations, providing coaching, and driving accountability for results.
- Incident response leadership - demonstrated experience leading complex incident response operations, including large-scale incident coordination and the full lifecycle from triage to retrospective.
- Hands-on technical background - experience conducting security investigations and log analysis using SIEM tools (e.g., Splunk, Elastic); working knowledge of GCP and/or AWS, including cloud forensics.
- Customer-facing credibility - comfortable representing GitLab Security during customer escalations and high-visibility cybersecurity discussions.
- Proactive hunting and threat intelligence - proficiency in threat hunting based on intelligence, and familiarity with supply chain threats targeting SaaS platforms.
- AI and automation mindset - experience using AI/LLMs to improve incident response workflows and automate repetitive processes.
- Platform familiarity - experience using GitLab (or a comparable DevSecOps platform) for project tracking; bonus if you have experience responding to threats against a SaaS platform.
- Prioritization under pressure - ability to make sound operational decisions quickly, escalate issues cleanly, and guide the team on balancing what is urgent versus what is important.
- Due to government requirements, you must be a United States Citizen (defined as any individual who is a citizen of the United States by law, birth, or naturalization) to fill this position.
Benefits
- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Security Consultant – Identity, SecOps
GuidePoint SecurityWe help organizations make smarter cybersecurity decisions that minimize risk.
• Assess, design, and improve Microsoft Entra ID / Azure AD environments • Implement and harden foundational M365 and Azure security controls • Support Identity governance, MFA, Conditional Access, PIM, RBAC, and passwordless initiatives • Assist customers with FIDO2 security key deployments and identity hardening strategies • Perform Security Architecture Reviews and technical assessments • Develop actionable remediation recommendations and implementation roadmaps • Support ITDR, SIEM, SOC, and Zero Trust aligned initiatives • Work hands-on within customer environments to validate and implement recommendations • Produce high-quality customer deliverables and technical documentation • Serve as a trusted advisor to customer security and IT teams
• Monitor security alerts and events on a daily basis using Microsoft Defender and other security tools. • Investigate suspicious activities, incidents, and anomalies on endpoints and corporate accounts. • Document security incidents and follow up on corrective actions. • Generate biweekly and monthly reports on: - Detected incidents - Relevant alerts - Policy compliance - Corporate device status - Security metrics • Verify compliance with corporate policies on laptops and assigned devices. • Monitor access controls, MFA, and user activity. • Collaborate with internal audits and compliance processes. • Maintain evidence and documentation required for SOC 2 audits. • Participate in periodic reviews of access permissions and corporate assets. • Escalate critical incidents according to established procedures. • Propose continuous improvements in security controls and monitoring.
Senior Security Operations Engineer
TASC (Total Administrative Services Corporation)Our mission is to improve the health, wealth, and well-being of our customers, employees, and community
• Own day-to-day security operations for AWS-based cloud and serverless workloads including threat detection, alert triage, incident response, forensics, and post-incident learning. • Build and tune detections and automations (SIEM rules, SOAR/runbooks, detection-as-code) to reduce MTTA/MTTR and eliminate noisy alerts. • Secure our delivery pipelines & runtime Harden CI/CD and software supply chain, and drive “secure by default” patterns in our SDLC. • Lead cloud/serverless hardening (IaC reviews, policy-as-code, least privilege IAM design, network segmentation). • Partner with DevOps and Engineering teams to evolve identity & access, endpoint/EDR posture. • Coordinate vulnerability management end-to-end: scanning, prioritization, remediation, and reporting. • Contribute to security governance (policies, standards, tabletop exercises, BCP/DR inputs) and support compliance efforts (e.g., SOC 2/PCI DSS). • Build security tooling and integrations for engineers, acknowledging that ease of use and low friction will encourage adoption and adherence. • Define metrics/KPIs and regularly communicate risk & progress to engineering and leadership. • Mentor engineers on secure design and champion a positive, enablement-first security culture. • Participate in architecture and threat modeling discussions to identify security risks early in the design process.
• Collaborate with cross-functional teams to design, implement, and manage our security and identity platforms. • Develop, integrate, and maintain account- and system-provisioning solutions as we progress toward a Zero Trust architecture. • Partner with application owners and business stakeholders to provide security subject-matter expertise and guidance on security standards and policies to protect customers and maintain a secure environment. • Administer identity and security operations platforms (e.g., Okta, Active Directory, Active Directory Certificate Services (ADCS), ADFS, Azure, Intune, AWS/IAM, certificate and secrets management). • Manage Active Directory deployments and rebuild the ADCS environment. • Lead and contribute to Okta projects and manage permissions effectively. • Provide Tier 3 support for all Identity and Security Operations issues. • Develop policies and procedures for identity and security systems. • Serve as a subject-matter expert (SME) for SSO, SAML, and SCIM for application owners and business stakeholders. • Work closely with other security and infrastructure teams to proactively identify, protect, and defend the enterprise from cybersecurity threats and to resolve complex issues. • Mentor and train other team members. • Participate in on-call rotations as required.




