03 ago
|
Allianz
|
Barcelona
Experteer Overview In this role you transform threat actor behavior into actionable defenses within Allianz’s AI-augmented, intelligence-driven cyber defense. You’ll shape intrusion analysis, automate repetitive intelligence workflows, and deliver detection content that enables fast, confident action across security teams. You’ll translate real-world attacks into forward-looking intelligence and hunting leads at scale, with a direct impact on the organization’s resilience. You work closely with detection engineers, incident responders, and leadership to harden defenses and drive measurable outcomes.Compensaciones / Incentivos
- Analyze real-world attacks, post-incident findings, and adversary tradecraft to identify actionable activity and convert retrospective analysis into forward-looking intelligence
- Translate intelligence into detection content by creating rules and guidance for deployment by detection engineering teams
- Map threat actor TTPs to MITRE ATTu0026CK and identify coverage gaps to generate relevant hunting leads
- Build and maintain automation for repetitive intelligence workflows using SOAR, Power Automate, N8N, Python, scripting, and API integrations
- Apply AI to categorize intelligence, enrich indicators, and accelerate decision-making in daily workflows
- Communicate findings via dashboards, intelligence notes, and operational briefings for diverse audiences
- Support IOC lifecycle and provide analytical input, validation, and triage during active incidents (on-call rotations)Responsabilidades
- Hands-on intrusion analysis experience with real-world attack investigations
- Proven ability to turn intelligence into production-ready detection rules
- Strong knowledge of MITRE ATTu0026CK at the procedure level
- Coding and automation skills (Python, scripting, APIs)
- Understanding of Threat Intelligence Lifecycle and analytical models (Diamond Model, Kill Chain)
- Experience with tools such as Google SecOps, CrowdStrike Falcon/Intelligence, Google Threat Intelligence/VirusTotal, Recorded Future, MISP or similarRequisitos principales
- hybrid work model
- up to 25 days abroad
- bonus scheme
- pension
- employee shares program
- employee discounts
📌 Threat Intelligence Engineer (Barcelona)
🏢 Allianz
📍 Barcelona