Job Closed
This listing is no longer active.
Build software faster. The One DevOps Platform enables your entire org to collaborate around your code. We're hiring.
Senior Manager, Security Incident Response Team
Location
California
Posted
109 days ago
Salary
$168K - $280K / year
Seniority
Senior
Job Description
Senior Manager, Security Incident Response Team
GitLab
• Serve as trusted advisor as part of the security division’s leadership team, actively shaping the program direction. • Build and mature incident response runbooks, procedures, and capabilities. • Provide leadership to multiple security operations team shifts that will sometimes require you to work on nights or weekends. • Develop a culture of incident response excellence through a focus on investigation depth and accuracy. • Lead cross-functional collaboration between peer SecOps teams, security departments, and extended support teams such as Legal, Customer Support, and Infrastructure. • Foster a defense first mindset through actionable incident retrospective mitigations to close defense gaps, making GitLab a hard target for attackers. • Lead a team of expert security engineers with experience in security automation, deep dive forensics and incident response, AI detection and response capabilities, and GitLab the product. • Support response readiness and expertise about new GitLab corporate and product capabilities and features. • Drive insights from the alerts, investigations, and incidents handled by SIRT to improve the security posture of GitLab.
Job Requirements
- Experience assisting customers during high visibility and urgency security incidents and being comfortable representing GitLab Security during customer cybersecurity questions and escalations.
- Proven ability to deliver results across a global incident response team of 10+ engineers, and matrixed teams such as the Security division, and supporting R&D teams (Product, Engineering, Infrastructure, etc).
- Proven experience in incident response leadership and large scale incident coordination.
- Experience conducting investigations and log analysis using SIEM tools, such as Splunk or Elastic.
- Working knowledge of Google Cloud Platform (GCP) and/or AWS as well as cloud forensics
- Proficiency in proactive hunting based on threat intelligence
- Experience using GitLab (or a related DevSecOps platform like GitHub) for project tracking - Bonus points if you have experience responding to threats against a SaaS platform.
- A passion for investigation quality and depth of analysis - prioritizing quality over speed.
- Experience using AI/LLMs to automate and improve incident response processes and capabilities.
- An understanding of supply chain threats and how to defend a SaaS platform against such threats.
Benefits
- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental leave
- Home office support
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Senior Cybersecurity Operations Consultant
Trility ConsultingStart delivering technology solutions that simplify, automate, and secure your business.
• Deploy, configure, and integrate security tooling across a number of cybersecurity sub-workstreams • Execute configuration updates to redirect logs, telemetry, and security data feeds to the new MSSP • Coordinate with the MSP on endpoint agent deployments and related technical dependencies • Validate integrations and ensure consistent security visibility across on-prem and cloud environments (outside the CMMC boundary) • Support development of operational SOPs, playbooks, and integration documentationIdentify integration risks and recommend practical mitigation strategies based on hands-on experience • Provide technical input during MSSP-related decision points, including tooling compatibility and architecture considerations • Collaborate closely with Trility team members, client IT stakeholders, MSP, and MSSP partners to ensure smooth transition and stabilization
• Analyze third party records in the vendor risk management system and assist with data entry and data maintenance • Meet with internal stakeholders to complete vendor intake questionnaires • Data analysis and maintenance of ticketing system • Provide general support for Governance, Risk & Compliance functions
• Build and operationalize a fintech-grade SOC function • Own incident response end-to-end • Design and mature detection engineering • Define security KPIs & KRIs • Embed SOC into engineering and product workflows • Reduce systemic financial risk • Build and scale the SecOps team • Operationalize compliance through execution
• Monitor and respond to clients through all supported email, messaging, and phone platforms • Proactively monitor security dashboards to detect and respond to emerging threats in real-time • Identify alerts that require additional analysis and facilitate their escalation– internally or externally –for further investigation and resolution • Meet minimum standards of initial triage and analysis before escalating • Understand, identify, and research Indicators of Compromise (IOCs) to support threat detection and incident response efforts • Review and analyze security logs and event data from various sources, such as firewalls, intrusion detection systems, and endpoint security tools to identify potential security incidents • Complete all assigned internal and external reports by their deadlines, or in a timely manner if one is not provided • Receive and perform initial triage of security alerts, assess their severity, and determine appropriate actions for resolution • Contribute to tuning of managed security tools by identifying trends and optimizing alert fidelity • Stay informed about the latest cybersecurity threats, vulnerabilities, and attack techniques, and apply this knowledge to enhance the SOC's threat detection capabilities • Perform threat hunts to ensure proactive, in-depth client security • Monitor and maintain unassigned and assigned ticket queues, ensuring timely resolution and effective communication with stakeholders • Maintain average ticket processing time checkpoints in accordance with SLA’s - time to acknowledge, time to triage, and time to notify • Completing all assigned training in agreed upon time frames




