Information Security - Senior Threat Detection & Response Engineer
- Hiring from
- Spain
- Work type
- Hybrid
- Posted
508,497 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
Ryanair Labs are currently recruiting for two Information Security - Senior Threat Detection & Response Engineers to join Europe’s Largest Airline Group!
This is a very exciting time to join Ryanair as we look to expand our operation to 800 aircraft and 300 million guests within the next 10 years.
Ryanair Labs is the technology brand of Ryanair. Labs is a state of-the-art digital & IT innovation hub creating Europe's Leading Travel Experience for our customers.
About the role
A hands-on, individual-contributor role in a lean airline security team. Your core job is to proactively find where we are blind or exposed missing telemetry, missing detections, weak or unvalidated controls across on-prem, endpoint and multicloud (AWS, GCP, Azure) environments, and to close those gaps methodically, with evidence that each one is closed. You also take part in incident response: the gaps you find come from real incidents, and the fixes you build get tested by them.
How you'll work: find → define → fix
- Find. Map current telemetry and detections against MITRE ATT&CK (Navigator/DeTT&CT), including the cloud matrices (IaaS, SaaS, Identity Provider) for AWS, GCP and Azure; run adversary emulation and breach-and-attack-simulation tests; mine incidents, hunts, pentests and threat intel for techniques we couldn't see or stop; audit log-source health and asset coverage.
- Define. Turn each gap into a written item: technique, affected assets, risk, required telemetry, detection logic, mitigation, owner and acceptance test. Prioritise into a single backlog against the threats most relevant to aviation.
- Fix. Onboard and normalise log sources; build detections as code (Sigma as the source of truth, converted to KQL, SPL or Elastic/OpenSearch queries; version-controlled and tested in CI); tune to an agreed false-positive budget; work with platform owners to implement and verify preventive controls (hardening, EDR policy, identity and conditional access, cloud guardrails); re-test to prove closure; update the coverage map.
What you'll do
- Own detection and visibility across AWS, GCP and Azure control planes and identity: audit-log ingestion, native security-service alerts, and misconfiguration/exposure findings feeding the gap backlog.
- Run purple-team exercises with red-team/pentest partners and convert findings into detections and mitigations.
- Hunt proactively for techniques the coverage map shows as uncovered.
- Lead containment, eradication and recovery during incidents; perform forensic analysis; feed lessons straight back into the gap backlog.
- Automate enrichment, triage and response (SOAR, Python, PowerShell) where it removes manual toil.
- Use LLM assistants and agentic coding tools (Claude Code, OpenCode) to speed up rule authoring, backend conversion, test-case generation, parser/automation code and triage, validating outputs before anything reaches production.
- Produce coverage and performance metrics directly from the work (ATT&CK coverage %, gap closure rate, validation pass rate, MTTD/MTTR) for leadership.
Must have
- 6+ years hands-on in detection engineering, senior SOC analyst or incident response.
- Deep hands-on SIEM skills: Microsoft Sentinel, Splunk, Elastic (ELK) or OpenSearch, including their query languages (KQL, SPL, ES|QL/Lucene).
- Hands-on EDR: Microsoft Defender, SentinelOne or CrowdStrike, including their hunting query interfaces and custom detection rules.
- Sigma, including converting and testing rules against each backend.
- Multicloud security across AWS, GCP and Azure: audit and security telemetry (CloudTrail/GuardDuty, Cloud Audit Logs/Security Command Center, Azure Activity + Entra ID logs/Defender for Cloud), IAM and identity attack paths, and cloud-specific detection use cases.
- Proven track record of finding and closing detection or visibility gaps, with examples of your methodology.
- Practical MITRE ATT&CK use for coverage assessment, not just tagging.
- Adversary emulation / breach-and-attack-simulation experience.
- Strong Python or PowerShell; comfortable with Git and CI for detection-as-code.
- Effective daily use of LLM assistants and agentic coding tools (e.g., Claude Code, OpenCode) for detection-as-code, automation and analysis, with critical validation of output and within approved data-handling boundaries.
- Clear communication under incident pressure.
Nice to have
- Aviation, logistics or other regulated-sector experience; NIS2 / EASA Part-IS.
- SOAR platform experience.
- Elastic Security detection rules and OpenSearch Security Analytics (Sigma-native).
- Container/Kubernetes telemetry (EKS, GKE, AKS) and CSPM/CNAPP tooling.
- Certifications: GDAT, GCIH, GCFA, GCIA, AZ-500, AWS Security Specialty, Google Professional Cloud Security Engineer.
- Threat modelling / adversary profiling; exposure-management or attack-path tooling.
- AI security: MITRE ATLAS, OWASP Top 10 for LLM Applications; agentic security automation with LLM agents.
- A competitive but flexible technical career plan.
- Possibility for career growth in a continuously growing team.
- We believe in a hybrid working model, you can work up to three days per week remote, but you are also going to enjoy the excellent work environment at our modern offices in the heart of Madrid
- Optional discounts on health insurances (various companies).
- Travel discounts, of course!