03 ago
|
Allianz
|
Barcelona
Experteer Overview
Consulte la descripción del puesto a continuación. Si confía en que tiene las habilidades y la experiencia adecuadas, envíe su solicitud hoy mismo.
In this role you transform threat actor behavior into actionable defenses within Allianz’s AI-augmented, intelligence-driven cyber defense. You’ll shape intrusion analysis, automate repetitive intelligence workflows, and deliver detection content that enables fast, confident action across security teams. You’ll translate real-world attacks into forward-looking intelligence and hunting leads at scale, with a direct impact on the organization’s resilience.
You work closely with detection engineers, incident responders, and leadership to harden defenses and drive measurable outcomes.
Compensaciones / Incentivos
- Analyze real-world attacks, post-incident findings, and adversary tradecraft to identify actionable activity and convert retrospective analysis into forward-looking intelligence
- Translate intelligence into detection content by creating rules and guidance for deployment by detection engineering teams
- Map threat actor TTPs to MITRE ATTu0026CK and identify coverage gaps to generate relevant hunting leads
- Build and maintain automation for repetitive intelligence workflows using SOAR, Power Automate, N8N, Python, scripting, and API integrations
- Apply AI to categorize intelligence, enrich indicators, and accelerate decision-making in daily workflows
- Communicate findings via dashboards, intelligence notes, and operational briefings for diverse audiences
- Support IOC lifecycle and provide analytical input, validation, and triage during active incidents (on-call rotations)
Responsabilidades
- Hands-on intrusion analysis experience with real-world attack investigations
- Proven ability to turn intelligence into production-ready xugodme detection rules
- Strong knowledge of MITRE ATTu0026CK at the procedure level
- Coding and automation skills (Python, scripting, APIs)
- Understanding of Threat Intelligence Lifecycle and analytical models (Diamond Model, Kill Chain)
- Experience with tools such as Google SecOps, CrowdStrike Falcon/Intelligence, Google Threat Intelligence/VirusTotal, Recorded Future, MISP or similar
Requisitos principales
- hybrid work model
- up to 25 days abroad
- bonus scheme
- pension
- employee shares program
- employee discounts
📌 Threat Intelligence Engineer (Barcelona)
🏢 Allianz
📍 Barcelona