Threat Intelligence Engineer (Madrid)

Threat Intelligence Engineer (Madrid)

04 ago
|
Allianz Technology
|
Madrid

04 ago

Allianz Technology

Madrid

ph3About The Job /h3 pYou know adversaries by how they operate — and you know how to turn that knowledge into action. As a bThreat Intelligence Engineer — Intrusion Analysis Detection /b, you will help transform threat actor behavior into concrete defensive value: stronger detections, smarter hunting hypotheses, and intelligence that helps defenders move faster and more effectively. Within the Allianz Cyber Defense Center (ACDC), you will join a team that is evolving toward an AI‑augmented, intelligence‑driven operating model. This is a high‑impact opportunity to shape and mature intrusion analysis capabilities, automate repetitive intelligence workflows, and directly influence how a integral organization defends itself against real‑world threats. /p h3What You Do /h3 ul liAnalyze real‑world attacks, post‑incident findings, and emerging adversary tradecraft to identify relevant threat activity and convert retrospective analysis into forward‑looking intelligence. /li liTranslate threat intelligence into actionable detection content by producing detection rules and analytical guidance for deployment by detection engineering teams across platform‑native environments. /li liTrack threat actors and map tactics, techniques, and procedures to MITRE ATTCK, identifying coverage gaps and generating meaningful hunting leads based on relevance to the Allianz environment. /li liBuild and maintain automation for repetitive intelligence workflows using SOAR platforms, Power Automate, N8N, Python, scripting, and API integrations to improve speed, quality, and consistency. /li liApply AI in daily analytical workflows to categorize incoming intelligence, enrich indicators,



correlate reporting with tracked topics, and accelerate decision‑making. /li liCommunicate findings clearly through dashboards, written intelligence notes, and operational briefings so that detection engineers, incident responders, IT administrators, and leadership can act confidently. /li liSupport the full IOC lifecycle and contribute during active security incidents by providing timely analytical input, validation, and triage support as part of on‑call rotations. /li /ul h3What You Bring /h3 ul liHands‑on experience in intrusion analysis, including the investigation of real‑world attack patterns, adversary behavior, and post‑incident evidence. /li liProven ability to turn intelligence into action through detection engineering, including authoring, tuning, or validating detection rules in production environments. /li liStrong knowledge of MITRE ATTCK, especially at procedure level, and a solid understanding of the telemetry required to detect adversary activity effectively. /li liPractical coding and automation skills, ideally in Python, scripting, and API‑driven workflows, with a builder mindset focused on improving efficiency through automation. /li liGood understanding of the Threat Intelligence Lifecycle and structured analytical techniques,



including models such as the Diamond Model and Kill Chain. /li liExperience working with or exposure to tools such as Google SecOps, CrowdStrike Falcon / Intelligence, Google Threat Intelligence / VirusTotal, Recorded Future, MISP, or similar platforms. /li liA proactive, outcome‑driven mindset with the ability to stay composed under pressure, communicate clearly during incidents, and collaborate effectively across technical teams. /li /ul h3What We Offer /h3 ul liHybrid work model with up to 25 days per year working from abroad. /li liPerformance‑based compensation and benefits, including a company bonus scheme, pension, employee shares program, and employee discounts (details vary by location). /li liLifelong learning and international career mobility through career development and digital learning programs. /li liFlexible working, healthcare, parental leave benefits, and support to balance family and career while returning from career breaks. /li /ul h3Commitment to Integrity, Fairness Inclusion /h3 pAllianz Technology is proud to be an equal opportunity employer dedicated to fostering an inclusive work environment for everyone. We embrace individuals of all gender identities and expressions, sexual orientations, ethnicities, ages, nationalities, religions, disabilities, and philosophies of life. We welcome applications regardless of race, ethnicity or cultural background, age, gender, nationality, religion, social class, disability or sexual orientation, or any other characteristics protected under applicable local laws and regulations. /p /p #J-18808-Ljbffr

📌 Threat Intelligence Engineer (Madrid)
🏢 Allianz Technology
📍 Madrid

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: threat intelligence engineer (madrid) / madrid

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: threat intelligence engineer (madrid) / madrid