Commit 5d2531e8 authored by AJ Biton's avatar AJ Biton
Browse files

Add SRM to the tier 2 rotation

parent 481e6342
Loading
Loading
Loading
Loading
+23 −1
Original line number Diff line number Diff line
@@ -269,7 +269,29 @@ Escalate when experienced technical judgment is the key need. You should not be

---

### Dev escalation
### Security Risk Management Stage

- Rotation Leader: AJ Biton
- Coverage: 24x5 (Monday-Friday), coverage gap 23:00-07:00 UTC, occassionally low coverage on Fridays for Israeli employees
- Schedule: [schedule](https://app.incident.io/gitlab/on-call/schedules/01KFB5JGPAR7JJ5CXG2BCBGPMF)
- Escalation History Link: [escalations](https://app.incident.io/gitlab/on-call/escalations?escalation_path%5Bone_of%5D=01KFJX8MWG237NPR6HCAH38GJP)
- Primary Slack Channel: #s_srm

**Expertise Areas:**

- Vulnerability Management User-Facing Featureset (Vulnerability Report, Dependency List, Security Dashboard)
- Security Widget in the Merge Request flow
- Security Policies (Scan Execution Policies)
- Security Scan Ingestion Pipeline

**When to Escalate:**

- Incidents affecting availabiliy of any of the vulnerability management pages
- SIRT issues S2 and above that require immediate action from the engineering team to remediate the problem.

**Coverage:** 24x5 (Monday-Friday, 07:00-23:00 UTC)

### Dev Escalation

- This on-call process is designed for GitLab.com operational issues that are escalated by the Infrastructure team.
- Development team currently does NOT use PagerDuty or incident.io for scheduling and paging.