Senior Security Detection Engineer

at GitLab
USD 139,200-190,000 per year
SENIOR
✅ Remote

Tech Stack

AI AWS @ 7 GCP @ 7 Kubernetes @ 4 LLM Observability Security @ 6 Splunk Terraform @ 4

Details

You will join GitLab's Detection Engineering team, which is responsible for building and maintaining a best-in-class detection engineering program. The role focuses on writing threat detections, hunting for behavioral anomalies across GitLab corporate, cloud, and customer environments, and closing detection gaps through automation, LLM-aided efficiencies, and behavior-based analysis. The role also includes customer threat detection by turning GitLab threat insights into actionable customer alerts.

Due to government requirements, candidates must be United States citizens.

Responsibilities

  • Identify MITRE ATT&CK and top threat actor detection gaps and write behavioral detections to close them.
  • Serve as a detection subject-matter expert with a deep understanding of GitLab's detection methodology, Detections as Code framework, detection types, and quality thresholds.
  • Act as a detection architect by orchestrating agents across the entire detection lifecycle and ensuring detection quality and consistency.
  • Use SIEM or security data lake platforms such as Splunk or Elastic to write and troubleshoot threat detections.
  • Collaborate with GitLab teams to identify and close security observability improvement opportunities.
  • Collaborate with incident response, red team, and threat intelligence teams to improve GitLab's detection program and coverage.
  • Use, maintain, and build Detections as Code, AI, and process-efficiency automations for the signals engineering program.

Requirements

  • Understanding of the GitLab application; experience detecting and hunting attacks against GitLab or maintaining GitLab is a bonus.
  • Expertise in SOC operations, incident response, or detection engineering.
  • Expertise in SIEM or security data lake detection and query development.
  • Proven ability to proactively detect potentially malicious patterns and collaborate with incident response on incident root-cause analyses to identify and implement new detection opportunities.
  • Strong cloud experience with AWS or GCP.
  • Experience with PaaS technologies such as Kubernetes and Terraform.
  • Experience orchestrating teams of agents to write detections; experience building end-to-end agentic detection pipelines is a bonus.
  • Passion for deep-dive threat hunting and cross-functional purple teaming, with the ability to turn findings into detections.
  • Experience with mature detection capabilities, including Detections as Code, signal versus detection development, risk-based alerting, and behavior analytics.
  • United States citizenship is required due to government requirements.

Benefits

  • Benefits supporting health, finances, and well-being.
  • Flexible paid time off.
  • Team member resource groups.
  • Equity compensation and employee stock purchase plan.
  • Growth and development fund.
  • Parental leave.

More jobs at GitLab

Similar jobs