A live role

Intermediate Security Engineer, Security Incident Response Team (SIRT)

from GitLab · read the original and apply on their site

Remote, Australia

Our take: The real work here is staying calm through live security incidents, working them from detection to recovery, and building the automation and runbooks that make GitLab and its users safer.

If you go quiet and clear-headed when the alarms go off, this is where you belong: real security incidents, worked from detection through to recovery, backed by solid runbooks and a global team that hands off cleanly across regions. You will not just react, you will build the automation and detection that make the next incident easier, and grow into thinking like both attacker and defender. The compressed four-day shifts and 24/7 rotation are the honest cost of always-on protection, and the payoff is genuine impact on data millions of people trust.

Needs

  • responding to incidents
  • hunting root causes
  • automating security toil
  • writing clear runbooks
  • some python scripting
  • spotting threats early

Rewards

  • protecting real users
  • visible security impact
  • mission that matters

Demands

  • staying calm under fire
  • carrying the pager
  • high-stakes calls
  • compressed shift weeks

Grows

  • incident response mastery
  • attacker and defender thinking
  • learning new domains
  • forensic investigation

Values

  • defined process
  • rigour and review
  • remote working
  • learning culture
  • user safety first

Drains

  • writing endless runbooks
  • off-hours shifts
  • following set procedures

Would you love this work?

See how what you love doing lines up with this role - it takes about ten minutes to find out.

Find what I'd love to do next