The Security Incident Response Team - SIRT is on the forefront of security events that impact both GitLab.com and GitLab the company.
To detect security incidents before they happen and to respond promptly when they do happen.
Ensure maximum operational uptime of mission critical infrastructure and informational assets in its daily operations. This mission is achieved by providing effective crisis response, timely distribution of security notifications, continuous monitoring of potential issues, postmortem of major incidents for training and environmental awareness.
The following people are permanent members of the SIRT
|Joaquin Fuentes||Director, Security Operations|
|Valentine Mairet||Security Manager, SIRT|
|Lance Callaghan||Security Manager, SIRT|
|Matt Coons||Security Manager, SIRT|
|Mitra Jozenazemian||Staff Security Engineer, SIRT|
|Harjeet Sharma||Staff Security Engineer, SIRT|
|Corey McCarty||Senior Security Engineer, SIRT|
|Tuan Lam||Senior Security Engineer, SIRT|
|Janina Roppelt||Senior Security Engineer, SIRT|
|Laurens Van Dijk||Senior Security Engineer, SIRT|
|Andy Lockhart||Senior Security Engineer, SIRT|
|Chathura Kuruwita||Senior Security Engineer, SIRT|
|Bala Allam||Security Engineer, SIRT|
|Leslie Anzures||Security Engineer, SIRT|
The SIRT is on-call 24/7/365 to assist with any security incidents. If an urgent security incident has been identified or you suspect an incident may have occurred, please refer to Engaging the Security Engineer On-Call.
Information about SIRT responsibilities and incident ownership is available in the SIRT On-Call Guide.
As part of the incident management and review process the SIRT maintains a recurring meeting that takes place on Monday of each week. During this meeting all of the previous weeks incidents, and any incidents that are currently open are reviewed. The review process covers the incident's scope, impact, the work performed to mitigate and remediate the incident, next steps, blockers, and current status. These meetings are also an opportunity to discuss mishandled incidents and process improvements.
Information about security incidents or investigations is considered limited access and is not shared with all team members. After being resolved, a determination will be made as to whether or not the incident or investigation issue contains Materially Non-Public Information (MNPI). Only incidents or investigation issues that do not contain MNPI will be made visible to GitLab team members. More information about how this aligns with GitLab's value of Transparency can be found on the Transparency by Default page. The workflow for this is:
*A pre-defined list of team members are automatically added when the incident is