14 дней назад
Senior Security Engineer, Incident Response Team (Australia)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Engineer, Incident Response Team (Australia) (DFIR/AI): Leading end-to-end incident response and investigations for GitLab.com and corporate environments with an accent on cloud security, detection engineering, and automated response workflows. Focus on handling high-severity incidents, designing SIEM and telemetry capabilities, applying AI-assisted investigations, and improving operational resilience across the APAC window.
Location: Remote, Australia; coverage of the APAC window within a 24/7 follow-the-sun model and participation in a rotating on-call schedule.
Company
provides an intelligent orchestration platform for DevSecOps used by organizations to improve developer productivity, operational efficiency, security, and compliance.
What you will do
- Lead and coordinate end-to-end response for high-severity security incidents, from detection and triage through containment, eradication, and recovery.
- Investigate complex incidents across cloud environments using Digital Forensics and Incident Response methodologies.
- Design SIEM use cases, alerting strategies, detection capabilities, and telemetry pipelines with Detection Engineering.
- Build automation and AI-assisted workflows to improve triage, investigation speed, detection fidelity, and response consistency.
- Coordinate with Threat Intelligence and cross-functional partners, including Engineering, Infrastructure, Legal, Product, and Communications.
- Lead root-cause analysis, post-incident reviews, documentation, tabletop exercises, and mentoring to improve incident response maturity.
Requirements
- Strong experience in security incident response and investigations in cloud-first environments.
- Experience using or administering Git or in a security or engineering context.
- Hands-on experience with SIEM, EDR, and/or detection engineering.
- Experience with AWS and GCP, threat intelligence, adversary tactics, and MITRE ATT&CK.
- Experience building or using automation with Python, scripting, or SOAR platforms; interest or experience applying AI/ML to detection, triage, or response.
- Strong analytical, problem-solving, written communication, and incident documentation skills.
Culture & Benefits
- Work in a globally distributed Security Incident Response Team spanning AMER, APAC, and EMEA.
- Collaborate across regions through structured handovers, automation, and documented processes.
- Full-time employee benefits supporting health, finances, and well-being.
- Flexible paid time off, parental leave, equity compensation, and an employee stock purchase plan.
- Growth and Development Fund and Team Member Resource Groups.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →