14 sep
|
Boehringer Ingelheim
|
San Cugat del Vallés
14 sep
Boehringer Ingelheim
San Cugat del Vallés
Overview
In this role you will advance the organization’s ability to detect sophisticated cyber threats across on‑premises, cloud, and hybrid environments. You will design and continuously improve high‑fidelity detections, drive proactive threat hunting, and translate adversary techniques into concrete detections. You will collaborate with Threat Intelligence, SOC, Incident Response, and Red/Purple Teams to strengthen detection maturity, reduce false positives, and support adversary‑driven detection initiatives. This is a strategic, hands‑on role for shaping threat visibility and security posture.
Compensaciones / Ventajas
- Flexible working conditions
- Life and accident insurance
- Health insurance at a competitive price
- Investment in your learning and development
- Gym membership discounts
Responsabilidades
- Design, implement, and continuously improve advanced threat detection capabilities
- Develop, tune, and maintain high‑quality detection rules and behavioral analytics
- Conduct proactive, hypothesis‑driven threat hunting activities
- Translate adversary TTPs and attack techniques into actionable detections
- Collaborate with Threat Intelligence, SOC, Incident Response, and Red/Purple Teams
- Analyze complex attack chains, kill chains, and post‑exploitation activity
- Identify detection gaps and contribute to continuous detection maturity improvements
- Reduce false positives while maintaining effective threat visibility
- Support purple team activities by leveraging red team and penetration test outputs
Requisitos principales
- Minimum 5 years of experience in threat detection, threat hunting, detection engineering, red team, or penetration testing
- Strong experience designing and tuning detection rules in enterprise environments
- Advanced expertise in EDR/XDR platforms (e.g. Microsoft Defender / Microsoft XDR)
- Solid knowledge of MITRE ATT&CK; and adversary‑driven detection
- Hands‑on understanding of advanced attack techniques across Windows, Linux, and cloud
- Strong scripting skills (Python, PowerShell, or similar)
- Experience collaborating with red, purple, or penetration testing teams
- Ability to translate offensive tradecraft into high‑fidelity detections
- OSEP and CARTE (or equivalent) certifications required
- Fluent English; experience in global, cross‑functional teams preferred
- collaboration
- communication
- analytical thinking
- EDR/XDR platforms
- MITRE ATT&CK; knowledge
- Windows/Linux/cloud attack techniques
📌 Privileged Access Management (PAM) Engineer (San Cugat del Vallés)
🏢 Boehringer Ingelheim
📍 San Cugat del Vallés