
An Overview of This Role
GitLab is seeking a Senior Security Detection Engineer to join our growing Detection Engineering team. In this role, you will be responsible for building and maintaining a best-in-class detection engineering program. If you love writing threat detections, hunting for patterns of behavioral anomalies across GitLab corporate, cloud, and customer environments, and closing detection gaps, this team is for you!
We thrive on writing, maintaining, and testing our library of threat detections with a focus on automation, LLM-aided efficiencies, and behaviors over atomic indicators. We’re looking for an engineer with strong experience building and deploying threat detections using agentic AI capabilities. Bonus points if you are experienced in writing SaaS application detections, and double bonus points if that application is GitLab. Part of this role will be focused on customer threat detection—turning GitLab threat insights into actionable customer alerts.
Due to government requirements, you must be a United States Citizen (defined as any individual who is a citizen of the United States by law, birth, or naturalization) to fill this position.
What You’ll Do
- Identify MITRE ATT&CK and top threat actor detection gaps, writing behavioral detections to close them.
- Serve as a detection SME and deeply understand GitLab’s detection methodology, DaC framework, detection types, and quality thresholds.
- Act as a “detection architect” by orchestrating agents across the entire detection lifecycle and ensuring detection quality and consistency.
- Use a SIEM or data lake platform like Splunk or Elastic to write and troubleshoot threat detections.
- Collaborate with peer GitLab teams to identify and close security observability improvement opportunities.
- Collaborate with incident response, red team, and threat intelligence to cross-functionally improve GitLab’s detection program and coverage.
- Use, maintain, and build new DaC, AI, and process efficiency automations for the signals engineering program.
What You’ll Bring
- Strong understanding of the GitLab application, with a bonus for detecting/hunting attacks against GitLab or maintaining GitLab yourself.
- SOC, incident response, or detection engineering expertise.
- SIEM/security data lake detection and query expertise.
- Proven ability to proactively detect potentially malicious patterns and collaborate with incident response on root cause analyses (RCAs) to implement new detection opportunities.
- Strong Cloud (AWS/GCP) and PaaS (Kubernetes/Terraform) experience.
- Experience orchestrating teams of agents to write detections, with bonus points for building full end-to-end agentic detection pipelines.
- Passion for deep-dive threat hunting, cross-functional purple teaming, and turning results into detections.
- Experience with mature detection capabilities such as Detections as Code, signal vs. detection development, risk-based alerting, and behavior analytics.
Timezone overlap
UTC-8–-4
Benefits
Health, PTO, Parental leave, Learning, Equity, ESPP, Commission, Bonus, Wellness
Open to
US
Sign in to track applications and earn points.