06 ago
|
Allianz
|
Barcelona
Experteer Overview Consulte la descripción del puesto a continuación. Si confía en que tiene las habilidades y la experiencia adecuadas, envíe su solicitud hoy mismo. In this role you transform threat actor behavior into actionable defenses within Allianz’s AI-augmented, intelligence-driven cyber defense. You’ll shape intrusion analysis, automate repetitive intelligence workflows, and deliver detection content that enables fast, confident action across security teams. You’ll translate real-world attacks into forward-looking intelligence and hunting leads at scale, with a direct impact on the organization’s resilience. You work closely with detection engineers, incident responders, and leadership to harden defenses and drive measurable outcomes.Compensaciones / Ventajas• Analyze real-world attacks, post-incident findings, and adversary tradecraft to identify actionable activity and convert retrospective analysis into forward-looking intelligence• Translate intelligence into detection content by creating rules and guidance for deployment by detection engineering teams• Map threat actor TTPs to MITRE ATTu0026CK and identify coverage gaps to generate relevant hunting leads• Build and maintain automation for repetitive intelligence workflows using SOAR, Power Automate, N8N, Python, scripting, and API integrations• Apply AI to categorize intelligence, enrich indicators, and accelerate decision-making in daily workflows• Communicate findings via dashboards, intelligence notes, and operational briefings for diverse audiences• Support IOC lifecycle and provide analytical input, validation, and triage during active incidents (on-call rotations)Responsabilidades• Hands-on intrusion analysis experience with real-world attack investigations• Proven ability to turn intelligence into production-ready xcskxlj detection rules• Strong knowledge of MITRE ATTu0026CK at the procedure level• Coding and automation skills (Python, scripting, APIs)• Understanding of Threat Intelligence Lifecycle and analytical models (Diamond Model, Kill Chain)• Experience with tools such as Google SecOps, CrowdStrike Falcon/Intelligence, Google Threat Intelligence/VirusTotal, Recorded Future, MISP or similarRequisitos principales• hybrid work model• up to 25 days abroad• bonus scheme• pension• employee shares program• employee discounts
📌 Threat Intelligence Engineer (Barcelona)
🏢 Allianz
📍 Barcelona