Senior Threat Intelligence Engineer

Higlobe, Inc.

United States

On-site

CAD 196,933 - 281,334

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible Paid Time Off
Equity Compensation
Growth and Development Fund
Parental Leave

Job summary

GitLab is seeking a seasoned Threat Intelligence Engineer to join as a Senior Security Engineer, TI. You will monitor threats, automate intel workflows with Python, and manage our Threat Intelligence Platform.

As the sole TI resource on the team, you’ll build an intel-sharing program and collaborate across Security Operations to protect GitLab and customers. You’ll work with AI-driven tooling, contribute to incident response, and help mature threat intelligence practices.

Qualifications

  • Proven track record delivering actionable intelligence.
  • Experience with a Threat Intelligence Platform (TIP).
  • Experience researching adversaries using OSINT techniques.
  • Ability to automate tasks with Python or scripts.
  • Excellent written and verbal communication skills.

Responsibilities

  • Monitor threat landscape and raise awareness with concise reports.
  • Administer the Threat Intelligence Platform and data pipelines.
  • Support incident response with malware analysis and threat actor tracking.
  • Collaborate on Purple Team exercises to validate defenses.
  • Build relationships with industry peers to share intelligence.
  • Write code and build automation to improve team efficiency.

Skills

Threat intelligence
Python
Automation
OSINT
Communication

Tools

Threat Intelligence Platform (TIP)

Job description

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.

The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our valuesand continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software.

*Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.

Overview of the role

We're looking for a seasoned Threat Intelligence Engineer to join us as a dedicated Senior Security Engineer, TI. You'll be joining a program established a couple of years ago, with a solid foundation already in place: reporting templates, tooling, feeds, and industry connections built out by the Security Operations team over that time.

Your mission will be to provide actionable intelligence that empowers GitLab to make informed, proactive decisions about security. We want to get in front of threats before they materialize - using intelligence to see around corners and anticipate the next attack.

We'll rely on your strong hands‑on technical skills to monitor our unique threat landscape, focusing on credible threats to GitLab and the software supply chain. You'll leverage your Python expertise as a force multiplier, expanding our capabilities through automation and AI and maintaining our Threat Intelligence Platform. Additionally, you'll build meaningful relationships with industry peers, sharing intelligence and contributing to the industry as a whole.

As the sole dedicated member of this team, you'll help us refine our processes and iterate towards a more mature threat intelligence program. We've laid the groundwork with reporting templates, metrics for success, tooling, feeds, and industry connections. Now we need you to put this framework into action - uncovering real‑world attacks, making attributions, and building a thriving intel‑sharing community.

You'll be supported by Security Operations engineers who dedicate a portion of their time to threat intelligence. We'll encourage you to collaborate across security, infrastructure, and product teams to help keep our customers, platform, and organization secure.

If you're excited about shaping the future of threat intelligence at GitLab, we want to hear from you!

What you’ll do
  • Monitor the threat landscape, identifying and analyzing the risks most relevant to GitLab and raising awareness through ad‑hoc Flash Reports.
  • Administer our Threat Intelligence Platform and continue building out our open source, proprietary and internal intelligence collection pipeline.
  • Support incident response through malware analysis and threat actor tracking helping us stay one step ahead of our top threats.
  • Collaborate on Purple Team Flash Operations, where emerging threats are turned into collaborative exercises to validate and improve our defensive capabilities.
  • Build meaningful relationships with industry peers, sharing intelligence and collaborating on emerging threats.
  • Write code, leverage AI, and build automation to improve process efficiencies on the team.
What you’ll bring
  • Proven track record of delivering actionable intelligence that has had a meaningful impact on the security of an organization.
  • Experience working with a Threat Intelligence Platform (TIP) and managing ingested and exported threat feeds.
  • Experience researching adversaries using OSINT and structured analytical techniques.
  • Ability to automate tasks by writing basic scripts/programs, preferably with Python.
  • Excellent and professional communication skills (written and verbal) with an ability to articulate complex topics in a clear and concise manner.
  • Optional but valuable: experience reverse engineering malware, particularly macOS and Linux malware and malware delivered via code repositories.
  • Optional but valuable: public examples of blogs or open‑source work related to threat intelligence.
About the team

This role will be the sole dedicated member of a team within the Security Operations department. You will report to a Security Manager based out of Australia, who also runs our SIRT APAC Team. Security Operations includes SIRT, Trust & Safety, Signal Engineering, Red Team, and Security Logging.

The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.

United States Salary Range

$140,000 — $200,000 USD

How GitLab Supports Full‑Time Employees
  • Benefits to support your health, finances, and well‑being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.

Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location‑based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.

Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us.

GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Intermediate Software Engineer, Security Factory: Vulnerability Management
Intermediate Software Engineer, Security Factory: Vulnerability Management

GitLab • United States

On-site
GBP 85,000 - 128,000
Flexible Paid Time Off
Equity Compensation & Employee Stock-P
Growth and Development Fund
+3
Intermediate Software Engineer, Security Factory: Vulnerability Management
Intermediate Software Engineer, Security Factory: Vulnerability Management

Nerdleveltech • Northern (KY)

Hybrid
USD 115,000 - 173,000
Flexible PTO
Equity compensation
Employee stock purchase plan
+2
Intermediate Software Engineer, Security Factory: Vulnerability Management
Intermediate Software Engineer, Security Factory: Vulnerability Management

Jackalope Digital LLC • Northern (KY)

Hybrid
USD 115,000 - 173,000
Health benefits
Flexible PTO
Employee resource groups
+3
Senior Product Manager, Secret Detection and Vulnerability Research New Remote, United States
Senior Product Manager, Secret Detection and Vulnerability Research New Remote, United States

GitLab Inc. • Northern (KY)

Hybrid
USD 140,000 - 180,000
Senior Manager, Product Security Engineering (Security Posture and Supply Chain)
Senior Manager, Product Security Engineering (Security Posture and Supply Chain)

Jackalope Digital LLC • Northern (KY)

Hybrid
USD 168,000 - 245,000
Health benefits
Flexible PTO
Employee Resource Groups
+3
Field CTO - US West
Field CTO - US West

GitLab • United States

On-site
USD 150,000 - 200,000
Flexible Paid Time Off
Equity Compensation
Home office support
Senior AI Engineer
Senior AI Engineer

GitLab • United States

Remote
USD 139,000 - 219,000
Flexible Paid Time Off
Equity Compensation & Employee Stock Purchase Plan
Growth and Development Fund
+1
Tech Operations Specialist
Tech Operations Specialist

Socket.dev • United States

Remote
USD 95,200 - 160,800
Flexible PTO
Equity + ESPP
Growth & Development Fund
+2
Tech Operations Specialist
Tech Operations Specialist

Socket.dev • United States

On-site
USD 95,000 - 161,000
Benefits to support health, finances,
Flexible Paid Time Off
Team Member Resource Groups
+4
Senior Team Member Relations Partner
Senior Team Member Relations Partner

Triwill Group • United States

On-site
CAD 146,000 - 246,000
Flexible Paid Time Off
Team Member Resource Groups
Equity & ESPP
+3