Threat Engineering Lead

Edenred
Bucharest
Workplace: OnsiteFull timeFunction: Administration & Executive AssistanceExperience: 8+ yearsSkills: ["Collaboration","Communication","Documentation","Decision-making","Knowledge sharing"]

Own the evolution of threat hunting, detection, and response capabilities by turning internal and external threat intelligence into actionable detections, threat-hunting programs, and automated response workflows. Drive detection engineering using detections-as-code, align coverage to MITRE ATT&CK, NIST CSF, and ISO 27001, and improve incident outcomes across the security ecosystem. Apply AI/ML pragmatically with human oversight and validate results through emulation and quality metrics.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Edenred
Edenred
4 hours ago

Threat Engineering Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Own the evolution of threat hunting, detection, and response capabilities by turning internal and external threat intelligence into actionable detections, threat-hunting programs, and automated response workflows. Drive detection engineering using detections-as-code, align coverage to MITRE ATT&CK, NIST CSF, and ISO 27001, and improve incident outcomes across the security ecosystem. Apply AI/ML pragmatically with human oversight and validate results through emulation and quality metrics.
Location: Bucharest
Workplace: Onsite
Employment Type: Full time
Job Function: Administration & Executive Assistance
Seniority: Mid level

Key Responsibilities

  • •Automate threat intelligence processing, triage, investigation, and response workflows to improve operational speed and precision.
  • •Own the detection data pipeline and reference architecture, perform threat modeling, select tooling, and align coverage to MITRE ATT&CK, NIST CSF, and ISO 27001.
  • •Build, test, and maintain detections as code, manage false-positive/false-negative lifecycles, and track detection-quality metrics.
  • •Use AI/ML to accelerate validation harnesses and support anomaly-driven threat hunting and behavioral baselining with human oversight.
  • •Partner with CTI providers, SOC analysts, incident managers, and security engineering teams to deliver threat hunting campaigns and validate outcomes via emulation and coverage assessment.

Pay and Benefits

Perks:Meal AllowanceHealth InsuranceRemote WorkLearning Budget

Key Requirements

  • •8+ years owning detection engineering, threat hunting, and incident response end-to-end, including detection content.
  • •Experience with Splunk and EDR platforms such as CrowdStrike, Microsoft Defender, and Trend Micro, plus Zscaler.
  • •Hands-on experience with Azure and AWS security, including Windows/Linux/macOS and M365 environments.
  • •Detection-as-code practices with version control, testing, and CI, and the ability to defend detection quality using metrics.
  • •Applied AI/ML in security workflows with strong validation discipline before production use.
Experience:8+ yearsCybersecurity
Skills:CollaborationCommunicationDocumentationDecision-makingKnowledge sharing
Languages:English
Tech Stack:SplunkCrowdStrikeMicrosoft DefenderTrend MicroZscalerAzureAWSPythonMITRE ATT&CKNIST CSFISO 27001PCI DSSDORAM365WindowsLinuxMacOSDetection-as-CodeAtomic Red TeamCaldera

Company Brief

Edenred
Provides prepaid corporate services and solutions including employee benefits, meal vouchers, expense management, and fleet & mobility solutions to businesses worldwide, enabling workplace services and digitized payment solutions.
Industry: Payments
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Paris, France
Founded: 2010
WebsiteLinkedIn