08 oct
|
Ryanair Group Holdings
|
Madrid
08 oct
Ryanair Group Holdings
Madrid
Job Description
About the role
A hands-on, individual-contributor role in a lean airline security team. Your core job is to proactively find where we are blind or exposed missing telemetry, missing detections, weak or unvalidated controls across on-prem, endpoint and multicloud (AWS, GCP, Azure) environments, and to close those gaps methodically, with evidence that each one is closed. You also take part in incident response: the gaps you find come from real incidents, and the fixes you build get tested by them.
How you'll work: find → define → fix
- Find. Map current telemetry and detections against MITRE ATT&CK; (Navigator/DeTT&CT;), including the cloud matrices (IaaS, SaaS, Identity Provider) for AWS, GCP and Azure; run adversary emulation and breach-and-attack-simulation tests; mine incidents, hunts, pentests and threat intel for techniques we couldn't see or stop; audit log-source health and asset coverage.
- Define. Turn each gap into a written item: technique, affected assets, risk, required telemetry, detection logic, mitigation, owner and acceptance test. Prioritise into a single backlog against the threats most relevant to aviation.
- Fix. Onboard and normalise log sources; build detections as code (Sigma as the source of truth, converted to KQL,
SPL or Elastic/OpenSearch queries; version-controlled and tested in CI); tune to an agreed false-positive budget; work with platform owners to implement and verify preventive controls (hardening, EDR policy, identity and conditional access, cloud guardrails); re-test to prove closure; update the coverage map.
What you'll do
- Own detection and visibility across AWS, GCP and Azure control planes and identity: audit-log ingestion, native security-service alerts, and misconfiguration/exposure findings feeding the gap backlog.
- Run purple-team exercises with red-team/pentest partners and convert findings into detections and mitigations.
- Hunt proactively for techniques the coverage map shows as uncovered.
- Lead containment, eradication and recovery during incidents; perform forensic analysis; feed lessons straight back into the gap backlog.
- Automate enrichment, triage and response (SOAR, Python, PowerShell) where it removes manual toil.
- Use LLM assistants and agentic coding tools (Claude Code, OpenCode) to speed up rule authoring, backend conversion, test-case generation, parser/automation code and triage, validating outputs before anything reaches production.
- Produce coverage and performance metrics directly from the work (ATT&CK; coverage %, gap closure rate, validation pass rate, MTTD/MTTR) for leadership.
📌 Information Security - Senior Threat Detection & Response Engineer (Madrid)
🏢 Ryanair Group Holdings
📍 Madrid