Jobs and Careers
GI

Senior Security Engineer, Red Team

GitLab
UKRemotefull_timeVerifiedPosted 5 Jun 2023
💰 $266,400/yr($124,300/yr$266,400/yr)

About the role

The GitLab DevSecOps platform empowers 100,000+ organizations to deliver software faster and more efficiently. We are one of the world’s largest all-remote companies with 2,000+ team members and values that foster a culture where people embrace the belief that everyone can contribute. Learn more about Life at GitLab.

An overview of this role

We are looking for a senior-level Red Team engineer, meaning someone who has 2+ years experience conducting adversary emulation exercises either as an internal Red Team operator or as a consultant. If you’re a penetration tester who also does Red Team engagements, that’s great too! This role is focused on the latter, so it’s important that you understand the difference and can demonstrate experience with both.

You will be writing very detailed reports, creating videos, and communicating complex topics to folks across the organization with various levels of security knowledge. As a senior member of our team, you’ll also spend time teaching and mentoring other engineers.

GitLab’s environment is very different to traditional organizations, and attacking it takes creativity. There are no wireless corporate networks to sniff, there is no Active Directory to roast, and you won’t find a single hash being passed. To be successful on our Red Team, you must be able to adapt traditional attack techniques to an all-remote, all-cloud, and SaaS-based environment.

Our Red Team operations are planned in-depth, and typically span three months each. This means you will have the time to dig deep into developing and executing realistic attack techniques. As our organization grows and matures, so does our Red Team! You will have an opportunity to shape our roadmap and help us become better attackers.

Outside of these planned operations, we also make room for what we call “open-scope” work. This gives you the opportunity to get creative, pursuing your own interests and ideas while helping to identify and reduce risk. We are possibly the most transparent Red Team in the world, and you will be encouraged to write blogs based on your research, contribute to our public handbook, and publish open-source tools and exploits.

The recommendations we provide internally are taken very seriously, and our work has a direct impact on the organization and the product. We have a great relationship with our friends on the Blue Team, and you’ll be able to collaborate with folks from all over the organization to help make things more secure.

Some further links to explore:

What you’ll do  

  • Maintain a deep understanding of GitLab’s product offerings, how they work, and how they could be attacked or abused
  • Propose, plan, lead, and execute Red Team operations based on realistic threats to the organization
  • Automate attack techniques, creating custom tooling for specific operations and contributing to general-purpose open source tools
  • Deploy and manage attack infrastructure for stealth operations
  • Write detailed reports covering the goals and outcomes of Red Team operations, including significant observations and recommendations
  • Collaborate with GitLab’s Security Incident Response Team (SIRT) to improve detection and response capabilities
  • Collaborate with GitLab’s Infrastructure Security Team to propose defensive improvements to cloud environments
  • Collaborate across multiple product teams to propose enhancements and additions to GitLab’s SaaS and self-hosted offerings
  • Collaborate with non-technical teams to propose process and policy enhancements and additions
  • Stay informed on current security trends, advisories, publications, and academic research that is relevant our organization
  • Publish blogs and submit talks to sec

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GitLab

View company profile →