Cyber Defence & Incident Response Engineer (They/She/He)

Delivery Hero
Barcelona
Workplace: OnsiteFull timeFunction: CybersecuritySkills: ["Communication","Proactivity","Documentation","Curiosity","Continuous learning"]

Join Glovo’s CSIRT team as a first responder and threat-hunting engineer. You’ll support DFIR investigations, maintain incident playbooks, and build high-fidelity detection by tuning alerts from logs. The role also focuses on automation and orchestration to move toward a “SOCless” future, while partnering with security log ingestion tools and SIEM for full visibility. You’ll investigate emerging threats and document incident outcomes clearly.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Delivery Hero
Delivery Hero
4 days ago

Cyber Defence & Incident Response Engineer (They/She/He)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live
Reposted: similar role first listed 1 week ago

Job Summary

Join Glovo’s CSIRT team as a first responder and threat-hunting engineer. You’ll support DFIR investigations, maintain incident playbooks, and build high-fidelity detection by tuning alerts from logs. The role also focuses on automation and orchestration to move toward a “SOCless” future, while partnering with security log ingestion tools and SIEM for full visibility. You’ll investigate emerging threats and document incident outcomes clearly.
Location: Barcelona
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Support digital forensics and incident response investigations into breaches and security anomalies using the cyber incident response cycle.
  • •Design and maintain playbooks and investigation methodologies to keep Glovo ready for security incidents.
  • •Create, validate, and fine-tune alerts to turn raw logs into actionable intelligence with high fidelity and low noise.
  • •Build tooling and automation for incident response to reduce manual toil and support a “SOCless” approach.
  • •Conduct threat-hunting exercises, manage log ingestion and SIEM visibility, and participate in post-mortem discussions.

Pay and Benefits

Perks:Health InsuranceGym MembershipRemote WorkParental LeaveChildcare

Key Requirements

  • •Experience in incident response and digital forensics (digital forensics is a plus).
  • •Operational experience with AWS, including tracking adversaries through cloud-native logs.
  • •Experience with Python (or Golang) to automate responses and build custom security tooling.
  • •Strong threat monitoring skills, including tuning alerts to reduce noise and improve detection fidelity.
  • •Curiosity for threat hunting with understanding of the MITRE ATT&CK framework and related security topics.
Experience:Incident responseDigital forensicsCloud securityThreat hunting
Skills:CommunicationProactivityDocumentationCuriosityContinuous learning
Certifications:GCIHGCFAGNFAAWS Certified Security - Specialty
Languages:English
Tech Stack:AWSPythonGolangMITRE ATT&CKSOARSIEMCloud-native logsSecurity log ingestion

Company Brief

Delivery Hero
Global online food-ordering and local delivery platform operating multiple regional brands (e.g., Foodpanda, Glovo, Talabat) across 50–70+ countries, supplying food and quick-commerce deliveries via marketplace and logistics services.
Industry: Online Marketplaces
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Berlin, Germany
Founded: 2011
Glassdoor
Glassdoor: 3.4
WebsiteLinkedInGlassdoor