Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Cybersecurity Incident Manager (USA)

$168k - $270k

GrabJobs

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of the role The Cybersecurity Incident Manager (Incident Commander) leads and coordinates critical security incident response across GitLab.com, GitLab Dedicated, and GitLab’s corporate environments. This role serves as the primary authority during high-impact security events, orchestrating cross-functional teams, managing incident lifecycles from detection through resolution, and driving continuous improvement in GitLab's incident response capabilities. As the founding Incident Commander in the team, you will also build upon and mature the incident command function. While this role does not carry a formal on-call rotation, the nature of security incident response may occasionally require availability outside of core business hours for high-severity events. Find out more about the Security Operations Department here: Security Incident Response Team What you’ll do Incident Command & Crisis Leadership: Serve as the primary Incident Commander for critical and complex security events across GitLab.com and corporate infrastructure, providing decisive leadership during high-stress situations Cross-Functional Coordination: Orchestrate response efforts across Security Operations, Infrastructure, Legal, Engineering, Product, and executive stakeholders, maintaining clear communication streams and unified action plans Technical Collaboration Leadership: Lead technical calls and/or establish effective async collaboration during incidents, managing participant contributions, keeping discussions focused, and ensuring efficient progress toward resolution Blameless Post-Incident Reviews: Conduct comprehensive post-incident reviews and retrospectives, driving the creation of action items, process improvements, and systemic enhancements Playbook Development: Design, maintain, and continuously improve incident response playbooks, runbooks, and standard operating procedures for various incident scenarios in conjunction with SIRT engineers Process Engineering: Build and refine incident command frameworks, communication protocols, and escalation procedures that scale across a global, all-remote organization Training & Mentorship: Develop and deliver incident command training programs, mentor incident commanders at various levels, and build organizational muscle memory for effective incident response Stakeholder Communication: Translate technical incident details into clear, actionable communications for executive leadership, customers, and internal stakeholders Automation & Tooling: Identify opportunities for automation in incident response workflows and collaborate with engineering teams to build tools that enhance incident management capabilities Threat Landscape Awareness: Maintain deep understanding of current threat actors, attack vectors, and security trends to inform incident response preparedness What you’ll bring 10+ years of experience in information security, with at least 5 years focused on incident response, security operations, or related disciplines Demonstrated experience serving as Incident Commander for critical security events in complex, distributed environments Command Presence: Proven ability to lead and coordinate teams during high-stress, high-impact incidents with clarity, authority, and calm decisiveness Strong knowledge of attacker tactics, techniques, and procedures (eg MITRE ATT&CK framework) Technical proficiency with cloud infrastructure (GCP, AWS), container orchestration (Kubernetes), and modern application architectures Experience with security information and event management (SIEM) platforms, log analysis, and security monitoring tools Excellent written and verbal communication skills, including the ability to communicate technical concepts to non-technical stakeholders and executive leadership Demonstrated ability to build relationships and coordinate effectively across security, engineering, legal, and business teams Ability to identify systemic issues from incident patterns and drive organizational improvements Share our values , and work in accordance with those values Nice to haves: Experience working with / in Site Reliability Engineering (SRE), DevOps, or Infrastructure Engineering; Experience with GitLab the product and familiarity with DevSecOps practices; Experience working in an all-remote or distributed team environment Due to government requirements, you must be a United States Citizen (defined as any individual who is a citizen of the United States by law, birth, or naturalization) to fill this position. About the Team The Security Operations department protects GitLab, the GitLab SaaS services, and GitLab customers on SaaS offerings. The Principal Security Incident Commander works as part of the Security Incident Response Team (SIRT) , a follow-the-sun team across three geographical regions. The Signals Engineering team, Threat Intelligence, Trust and Safety, Security Logging and Red Team teams make up the rest of the Security Operations department. The base salary range for this role’s listed level is currently for residents of theUnited States only. This range is intended to reflect the role's base salary rate in locations throughout the US.Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data,and geographic location.The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity . Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary. United States Salary Range $168,000 - $270,000 USD How GitLab Supports Full-Time Employees Benefits to support your health, finances, and well-being Flexible Paid Time Off Team Member Resource Groups Equity Compensation & Employee Stock Purchase Plan Growth and Development Fund Parental leave Home office support Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application. Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process. Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us. GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law . If you have a disability or special need that requires accommodation , please let us know during the recruiting process .

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Principal Cybersecurity Incident Manager (USA) in Seattle, WA vacancy
  • (USA) Principal, Software Engineer, Information Security Multiple locations Regular/ Permanent...  ...as Code (IaC) to programmatically manage the lifecycle, configuration, and security...  ..., engineering, information systems, cybersecurity, or related area and 5years' experience... 
    Principal
    Permanent employment
    Full time
    Temporary work
    Part time

    Walmart

    Bellevue, WA
    2 days ago
  • $136k - $184k

     ...AWS Security Incident Response is looking for a Security Engineer who investigates with urgency, communicates with clarity, and turns every...  ..., paid time off, and parental leave. Learn more about our benefits at USA, WA, Seattle - 136,000.00 - 184,000.00 USD annually
    Suggested
    Internship
    Immediate start
    Flexible hours

    Amazon

    Seattle, WA
    2 days ago
  •  ...Principal, Software Engineer Join Walmart as a Principal Software...  ..., design docs, mentoring, incident follow-ups, and raising operational...  ...→ agent core logic → tool manager → local tools). Develop...  ...engineers, data scientists, cybersecurity experts, and service... 
    Principal
    Contract work
    Temporary work
    Local area

    Walmart

    Bellevue, WA
    4 days ago
  • $87.7k - $164k

    Ernst & Young Oman is seeking a Cyber Triage and Forensics Incident Analyst in Seattle. This role involves investigating security incidents, performing digital forensic analyses, and supporting remediation efforts. The ideal candidate will have over 5 years of experience... 
    Suggested
    Flexible hours

    Ernst & Young Oman

    Seattle, WA
    3 days ago
  •  ...based in Bellevue, WA, OfferUp consistently ranks among leading shopping apps on iOS and Android. What Will You Do? As a Principal Product Manager - Consumer at OfferUp, you will lead a talented team of engineers, designers, and stakeholders through complex trade-offs... 
    Principal
    Local area

    Experimentation Jobs

    Bellevue, WA
    10 hours ago
  • $177.5k - $233k

    A leading performance apparel company in Seattle is hiring a Staff Cybersecurity Analyst to enhance operations in incident response and threat intelligence. The ideal candidate will have a Bachelor's degree in a related field and 9-12 years of security operation experience... 

    lululemon

    Seattle, WA
    1 day ago
  • A healthcare organization is looking for a senior cybersecurity professional to manage and enhance the security of data and systems. This role requires...  ...threat monitoring, coordinating responses to incidents, and collaborating with various teams to improve security... 

    Kaiser Permanente

    Renton, WA
    2 days ago
  • $168k - $280k

     ...of GitLab. An overview of this role We’re looking for a senior manager to lead the GitLab security incident response team (SIRT) in the Americas region. GitLab SIRT manages and investigates cybersecurity incidents for all GitLab operating environments and operates in... 
    Remote work
    Home office
    Flexible hours
    Shift work
    Night shift
    Weekend work

    GrabJobs

    Seattle, WA
    10 hours ago
  • $90k

     ...currently seeking an educational leader for the role of Campus Principal for our Seattle Campus! Why you’ll love working with us At OneSchool...  ...for their learning journey. In North America we operate in the USA, Canada and the Caribbean, with 21 campuses located throughout... 
    Principal
    Full time

    OneSchool Global

    Burien, WA
    6 days ago
  • $140.8k - $190.5k

     ...Cybersecurity Trust And Protection Sr Information Security Manager Be unstoppable with us! T-Mobile is synonymous...  ...Manager (ISM) is a Principal Cybersecurity Engineer...  ..., monitoring, incident response and investigations...  ...today! T-Mobile USA, Inc. is an Equal Opportunity... 
    Permanent employment
    Full time
    Temporary work
    Work experience placement
    Local area

    Phenom People

    Bellevue, WA
    2 days ago
  • $147k - $237.5k

     ...place. Who We Are In order to be the cybersecurity partner of choice, we must trailblaze...  ...control & workflows, vulnerability management, and detection/response systems. Collaborate...  ...design reviews, threat modeling, and incident analysis. Help teams make high-... 
    Principal
    Remote work
    Flexible hours

    Palo Alto Networks

    Seattle, WA
    1 day ago
  •  ...Protocol (MCP) in real-world environments. We’re looking for a Principal Backend Engineer who thrives at the intersection of AI,...  ...grasp of reliability engineering principles (SLOs, observability, incident response). Fluency in Go (preferred) or another modern systems... 
    Principal
    Temporary work
    Remote work
    Home office

    Docker

    Seattle, WA
    10 hours ago
  •  ...Summary: This senior level employee is primarily responsible for managing and directing the maintenance and protection of integrity and...  ...and resolution of high impact or critical cyber security incidents. Provides insight and influence in determining the strategic... 
    Principal
    Work experience placement

    Kaiser Permanente

    Renton, WA
    2 days ago
  • $75 per hour

    A technology services firm in Seattle is seeking a skilled Information Security Manager to oversee the Information Security Management System (ISMS) and ensure compliance with regional and federal standards. The role involves guiding security policy, developing training... 
    Hourly pay

    Triplenet Technologies

    Seattle, WA
    2 days ago
  • Core4ce is hiring a Cybersecurity Policy and Operations Analyst in Washington to provide support for cybersecurity policy development, monitoring, and incident response documentation. The role requires active TS/SCI clearance, organizational skills, and the ability to work... 
    3 days per week

    Core4ce

    Seattle, WA
    4 days ago
  • $110k - $220k

    (USA) Staff, Software Engineer, Information Security Multiple locations Regular/...  ...provisioning, patching, and configuration management for all domain controllers. Implement...  ..., engineering, information systems, cybersecurity, or related area and 4years' experience... 
    Permanent employment
    Full time
    Temporary work
    Part time

    Walmart

    Bellevue, WA
    2 days ago
  • $150k - $215k

    Nscale is seeking a Principal Network Engineer in Seattle to lead technical strategies for AI interconnect networks. This role demands...  ...include guiding technical investigations for complex network incidents, improving performance predictability, and mentoring engineers... 
    Principal
    Remote job

    Nscale

    Seattle, WA
    3 days ago
  •  ...,human communication. Job Summary The Manager, Cyber Security is responsible for designing...  ..., leading, and implementing robust cybersecurity strategies that protect the...  ..., NIST CSF, ISO 27001, SOX, PCI DSS). Incident Response, Business Continuity & Disaster... 
    Full time
    For contractors
    Local area
    Remote work
    Flexible hours
    Weekend work
    Afternoon shift

    Ziply Fiber

    Kirkland, WA
    3 days ago
  • $178.4k - $226.7k

     ...services that enable customers to manage access and governance across...  ..., Computer Engineering, Cybersecurity, or other related discipline...  ...Experience with Security Operations, Incident Response, Threat Hunting and...  ...about our benefits at USA, WA, Seattle - 178,400.00 - 2... 
    Flexible hours

    Amazon

    Seattle, WA
    2 days ago
  •  ...Senior Principal Software Engineer We're looking for a tech leader ready to take their...  ...strategies for end-to-end model lifecycle management, including training, versioning,...  ...for AI workloads, including monitoring, incident response, security, and compliance, with... 
    Principal

    Chase

    Seattle, WA
    2 days ago
  •  ...Senior Principal AI Agent / ML Software Engineer The Senior Principal AI Agent / ML Software...  ...design, code, reviews, operations, and incident follow-up. The ideal candidate combines...  ...for tool calling, agent memory, context management, Model Context Protocol (MCP)... 
    Principal

    Oracle

    Seattle, WA
    4 days ago
  • $142k - $205k

    Associate Principal Analyst, Scams and Verification, Trust...  ...Google Seattle, WA, USA ; Kirkland, WA, USA...  ...Trust and Safety, policy, cybersecurity, or related fields....  ...engineers and product managers to identify and fight...  ...-severity adversarial incidents, conduct thorough root... 
    Principal
    Full time
    Temporary work

    Google Inc.

    Seattle, WA
    10 hours ago
  • $178.4k - $226.7k

     ...design, vulnerability analysis, incident response, and defensive...  ...degree in Computer Science, Cybersecurity, or a related field (or equivalent...  ..., SageMaker, or similar managed AI/ML services for production...  ...more about our benefits at USA, WA, BELLEVUE - 178,400.00 -... 
    Flexible hours

    Amazon

    Bellevue, WA
    5 hours ago
  • A global technology company is seeking a candidate to join its Incident Response Services team in Bellevue, WA. The successful applicant will manage tooling around incident lifecycle automation, evaluating logging stacks, and enhancing internal developer portals. Key qualifications... 

    The Trade Desk, Inc.

    Bellevue, WA
    4 days ago
  •  ...Sr./Principal Software Engineer San Francisco OR Seattle | USA SingleStore engineers build the real-time data platform powering some of the world's most demanding...  ...across networking, control plane, and managed service infrastructure, with main focus on our billing... 
    Principal

    SingleStore

    Seattle, WA
    12 days ago
  • $181.1k - $245k

     ...leadership community needs for its next phase of growth. As Principal Researcher, you will establish the cross-org Voice of the Customer...  ...paid time off, and parental leave. Learn more about our benefits at . USA, WA, Seattle - 181,100.00 - 245,000.00 USD annually... 
    Principal
    Flexible hours

    Amazon

    Seattle, WA
    3 days ago
  • $215.9k - $292.1k

     ...various systems including Product Life Management, Inventory, Planning, fulfillment, infrastructure...  ...We are seeking a Sr. Principal Product Manager to drive the technical vision...  ...Learn more about our benefits at . USA, WA, Seattle - 215,900.00 - 292,100.00 USD... 
    Principal
    Flexible hours

    Amazon

    Seattle, WA
    2 days ago
  •  ...A leading technology company is seeking a Principal Backend Engineer to direct the technical hierarchy of its AI tools and infrastructure. This remote role requires 12+ years of backend engineering experience, with a focus on distributed systems and technical leadership... 
    Principal
    Remote work

    Docker

    Seattle, WA
    10 hours ago
  •  ...communication skills. You will be responsible for analyzing security incidents, creating automations for security operations tools, and...  ...with industry standards. If you're passionate about cybersecurity and eager to tackle complex challenges in a fast-paced environment... 

    TechDigital Group

    Bellevue, WA
    1 day ago
  •  ...care delivery. Position Overview The Principal Cloud Engineer serves as the technical...  ...deployment pipelines, and configuration management Drive consistency and efficiency...  ...monitoring Partner with teams to improve incident response and system performance Platform... 
    Principal
    Remote work

    Comagine Health

    Seattle, WA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Cybersecurity Incident Manager (USA). Be the first to apply!