Senior Security Detection Engineer

🔥 1 minute ago

🇺🇸 United States – Remote

💵 $139.2k - $190k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GitLab

GitLab

1001 - 5000 employees

Founded 2014

💼 Consulting

📣 Marketing

🤖 Artificial Intelligence

💰 Secondary Market on 2020-11

Consulting • Marketing • Artificial Intelligence

GitLab is the most comprehensive AI-powered DevSecOps platform, offering tools for automated software delivery, security, and compliance throughout the software development lifecycle. It provides solutions across areas such as AI-assisted development, continuous integration/continuous deployment (CI/CD), source code management, and vulnerability management. GitLab aims to simplify and accelerate software delivery by uniting development, security, and operations on a unified platform. It is particularly recognized for its AI code assistants and has been named a leader in the Gartner Magic Quadrant™ for DevOps Platforms, making it a preferred choice for many enterprises.

📋 Description

• Identify MITRE ATT&CK/top threat actor detection gaps and write behavioral detections to close them • Serve as a detection subject matter expert with deep knowledge of GitLab’s detection methodology, DaC framework, detection types, and quality thresholds • Orchestrate agents across the detection lifecycle as a detection architect, ensuring detection quality and consistency • Use SIEM/data lake platforms such as Splunk or Elastic to write and troubleshoot threat detections • Collaborate with peer GitLab teams to identify and close security observability improvement opportunities • Collaborate with incident response, red team, and threat intelligence teams to improve GitLab’s detection program and coverage • Use, maintain, and build DaC, AI, and process-efficiency automations for the signals engineering program • Detect suspicious and malicious events for GitLab, its customers, and SaaS operating environments

🎯 Requirements

• SOC, incident response or detection engineering expertise • SIEM/security data lake detection and query expertise • Proven ability to proactively detect potentially malicious patterns and collaborate with incident response to complete incident RCAs and identify and implement new detection opportunities • Strong Cloud (AWS/GCP) and some PaaS (Kubernetes/Terraform) experience • Experience orchestrating teams of agents to write detections; experience building full end-to-end agentic detection pipelines is a bonus • Passion for deep-dive threat hunting and cross-functional purple teaming and turning results into detections • Experience with mature detection capabilities such as Detections as Code, Signal vs. detection development, risk-based alerting, and behavior analytics • Must be a United States Citizen • Understanding of the GitLab application is required; experience detecting and hunting attacks against GitLab or maintaining GitLab is a bonus

🏖️ Benefits

• Benefits to support your health, finances, and well-being • Flexible Paid Time Off • Team Member Resource Groups • Equity Compensation & Employee Stock Purchase Plan • Growth and Development Fund • Parental Leave

Apply Now

Similar Jobs

🔥 10 minutes ago

Net Health

501 - 1000

🏥 Healthcare

☁️ SaaS

🤖 Artificial Intelligence

Information Security Engineer securing Net Health’s healthcare SaaS through Azure cloud projects, AI governance, and vulnerability remediation. Supporting access reviews, risk assessments, and security operations.

🔥 2 hours ago

Salesforce

10,000+ employees

💼 Consulting

📣 Marketing

☁️ SaaS

Security Architect Lead securing Salesforce customer applications through architecture reviews, threat modeling, and penetration testing. Building the Professional Services Security Assurance practice.

🔥 4 hours ago

Accelera Solutions

51 - 200

💼 Consulting

🎖️ Defense

🏥 Healthcare

Microsoft Security Administrator operating Microsoft Defender services for a Department of Defense customer. Monitoring endpoint security, SIEM integrations, compliance, and DLP controls.

🔥 12 hours ago

Primordial Labs

11 - 50

🎖️ Defense

📦 Logistics

💼 Consulting

IT, cloud, and security administrator managing Microsoft 365, AWS, and cybersecurity for Primordial Labs’ autonomous-systems platform. Supporting a fully remote US team and defense-compliance requirements.

🇺🇸 United States – Remote

💵 $125k - $175k / year

💰 $4M Seed Round - Primordial Labs on 2022-10

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🔥 14 hours ago

TherapyNotes, LLC

51 - 200

💼 Consulting

⚖️ Legal

🏥 Healthcare

Cloud Security Engineer securing TherapyNotes’ behavioral health SaaS platform, Azure infrastructure, Kubernetes workloads, and identity systems. Driving cloud compliance, incident response, and Zero Trust security.