04 ago
|
Allianz
|
Barcelona
Experteer Overview
Consulte la descripción del puesto a continuación. Si confía en que tiene las habilidades y la experiencia adecuadas, envíe su solicitud hoy mismo.
In this role you transform threat actor behavior into actionable defenses within Allianz’s AI-augmented, intelligence-driven cyber defense. You’ll shape intrusion analysis, automate repetitive intelligence workflows, and deliver detection content that enables fast, confident action across security teams. You’ll translate real-world attacks into forward-looking intelligence and hunting leads at scale, with a direct impact on the organization’s resilience. You work closely with detection engineers, incident responders, and leadership to harden defenses and drive measurable outcomes.
Compensaciones / Ventajas
• Analyze real-world attacks, post-incident findings, and adversary tradecraft to identify actionable activity and convert retrospective analysis into forward-looking intelligence
• Translate intelligence into detection content by creating rules and guidance for deployment by detection engineering teams
• Map threat actor TTPs to MITRE ATTu0026CK and identify coverage gaps to generate relevant hunting leads
• Build and maintain automation for repetitive intelligence workflows using SOAR, Power Automate, N8N, Python, scripting, and API integrations
• Apply AI to categorize intelligence, enrich indicators, and accelerate decision-making in daily workflows
• Communicate findings via dashboards, intelligence notes, and operational briefings for diverse audiences
• Support IOC lifecycle and provide analytical input, validation, and triage during active incidents (on-call rotations)
Responsabilidades
• Hands-on intrusion analysis experience with real-world attack investigations
• Proven ability to turn intelligence into production-ready xqbhyrx detection rules
• Strong knowledge of MITRE ATTu0026CK at the procedure level
• Coding and automation skills (Python, scripting, APIs)
• Understanding of Threat Intelligence Lifecycle and analytical models (Diamond Model, Kill Chain)
• Experience with tools such as Google SecOps, CrowdStrike Falcon/Intelligence, Google Threat Intelligence/VirusTotal, Recorded Future, MISP or similar
Requisitos principales
• hybrid work model
• up to 25 days abroad
• bonus scheme
• pension
• employee shares program
• employee discounts
📌 Threat Intelligence Engineer (Barcelona)
🏢 Allianz
📍 Barcelona