Security Incident Response Team Manager
You will lead the day-to-day work of incident response engineers, set clear goals and performance expectations, coach their development, and ensure quality delivery. You will oversee the full incident lifecycle, including alert triage, investigations, forensics, large-scale response, and retrospective mitigation actions. You will act as an escalation point and incident commander for high-severity events, coordinate with Security Operations, Legal, Customer Support, and Infrastructure, and improve runbooks, defenses, automation, and incident response workflows. You will also support hiring, engagement, retention, remote-first practices, and clear communication of organizational priorities.
Responsibilities
- Manage day-to-day operations of the incident response team
- Set clear goals, performance expectations, and accountability for direct reports
- Coach incident responders and provide real-time feedback
- Participate in hiring decisions and identify talent gaps
- Drive team engagement, retention, and psychological safety
- Translate organizational strategy into actionable team priorities
- Build and improve incident response runbooks, procedures, and capabilities
- Lead high-severity incident response as an escalation point and incident commander
- Coordinate with Security Operations, Legal, Customer Support, and Infrastructure to resolve incidents
- Drive defensive improvements from alerts, investigations, and incidents
- Model and coach remote-first and asynchronous communication practices
Requirements
- Proven experience managing and developing security engineers
- Experience leading complex incident response operations, including large-scale coordination and the lifecycle from triage to retrospective
- Experience conducting security investigations and log analysis using SIEM tools such as Splunk or Elastic
- Working knowledge of GCP and/or AWS, including cloud forensics
- Ability to represent GitLab Security during customer escalations and cybersecurity discussions
- Proficiency in intelligence-led threat hunting and familiarity with supply chain threats targeting SaaS platforms
- Experience using AI or LLMs to improve incident response workflows and automate repetitive processes
- Experience using GitLab or a comparable DevSecOps platform for project tracking
- Ability to make sound operational decisions under pressure and prioritize urgent work
- United States citizenship
- Availability during United States West Coast business hours
Benefits
- Health, financial, and well-being benefits
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity compensation
- Employee Stock Purchase Plan
- Parental leave