Senior Security Detection Engineer
GitLab · Remote, United States
About this role
**Senior Security Detection Engineer** ## About the role Join GitLab’s growing **Detection Engineering** team, responsible for building and maintaining a best-in-class detection engineering program. If you enjoy writing threat detections, hunting for behavioral anomalies across GitLab corporate, cloud, and customer environments, and closing detection gaps, this team is for you. You’ll help write, maintain, and test a library of threat detections with a focus on **automation**, **LLM-aided efficiencies**, and **behaviors over atomic indicators**. The role also includes **customer threat detection**, turning GitLab threat insights into actionable customer alerts. ## What you’ll do - Identify **MITRE ATT&CK / top threat actor detection gaps** and write **behavioral detections** to close them - Serve as a **detection SME**, deeply understanding GitLab’s detection methodology, **DaC framework**, detection types, and quality thresholds - Act as a **“detection architect”** by orchestrating agents across the detection lifecycle and ensuring quality and consistency - Use and troubleshoot detections using a **SIEM / data lake** platform such as **Splunk** or **Elastic** - Collaborate with peer GitLab teams to identify and close **security observability** improvement opportunities - Work cross-functionally with **incident response**, **red team**, and **threat intelligence** to improve GitLab’s detection coverage - Use, maintain, and build new **DaC**, **AI**, and **process efficiency** automations for the signals engineering program ## What you’ll bring - Understanding of the **GitLab application** (bonus if you’ve detected/hunted attacks against GitLab or maintained GitLab yourself) - **SOC, incident response, or detection engineering** expertise - **SIEM / security data lake** detection and query expertise - Proven ability to proactively detect potentially malicious patterns and partner with incident response to complete incident RCAs and implement new detection opportunities - Strong **Cloud (AWS/GCP)** experience and some **PaaS** experience (e.g., **Kubernetes / Terraform**) - Experience orchestrating teams of **agents** to write detections (bonus for end-to-end agentic detection pipelines) - Passion for deep-dive threat hunting, cross-functional purple teaming, and turning results into detections - Experience with mature detection capabilities such as: - **Detections as Code** - **Signal vs. detection development** - **Risk-based alerting** - **Behavior analytics** ## Eligibility - Due to government requirements, you **must be a United States Citizen** to fill this position. ## Salary (US) - **$139,200 – $190,000 USD** (base salary range for US residents only) ## GitLab benefits (high level) - Benefits for health, finances, and well-being - Flexible Paid Time Off (PTO) - Team Member Resource Groups - Equity compensation and employee stock purchase plan - Growth and Development Fund - Parental leave *Please note:* GitLab welcomes candidates with varying levels of experience—many successful applicants may not meet every requirement. If you’re excited about the role, apply and let recruiters assess your fit.
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.