Threat Intelligence Engineer

Allianz
Madrid
Workplace: HybridFull timeFunction: Administration & Executive AssistanceSkills: ["Python","SOAR","Power Automate","N8N","APIs","MITRE ATT&CK","CrowdStrike","VirusTotal"]

Threat Intelligence Engineer specializing in intrusion analysis and detection within Allianz's AI-augmented cyber defense. Translate threat intel into actionable detections, automate repetitive workflows, track threat actors using MITRE ATT&CK, and collaborate with detection engineers, incident responders, and IT admins to improve speed, quality, and confidence in defense at scale.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Allianz
Allianz
3 months ago

Threat Intelligence Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 12 hours agoStatus: Live

Job Summary

Threat Intelligence Engineer specializing in intrusion analysis and detection within Allianz's AI-augmented cyber defense. Translate threat intel into actionable detections, automate repetitive workflows, track threat actors using MITRE ATT&CK, and collaborate with detection engineers, incident responders, and IT admins to improve speed, quality, and confidence in defense at scale.
Location: Madrid
Workplace: Hybrid
Employment Type: Full time
Job Function: Administration & Executive Assistance

Key Responsibilities

  • •Analyze real-world attacks, post-incident findings, and emerging adversary tradecraft to identify relevant threat activity and convert retrospective analysis into forward-looking intelligence.
  • •Translate threat intelligence into actionable detection content by producing detection rules and analytical guidance for deployment by detection engineering teams across platform-native environments.
  • •Track threat actors and map tactics, techniques, and procedures to MITRE ATT&CK, identifying coverage gaps and generating meaningful hunting leads based on relevance to the Allianz environment.
  • •Build and maintain automation for repetitive intelligence workflows using SOAR platforms, Power Automate, N8N, Python, scripting, and API integrations to improve speed, quality, and consistency.
  • •Apply AI in daily analytical workflows to categorize incoming intelligence, enrich indicators, correlate reporting with tracked topics, and accelerate decision-making.

Pay and Benefits

Equity and Bonus:Equity
Perks:PensionEquityHealth InsuranceRemote WorkLearning Budget

Key Requirements

  • •Hands-on intrusion analysis experience with real-world attack patterns, adversary behavior, and post-incident evidence
  • •Ability to turn intelligence into action via detection engineering, including authoring, tuning, or validating production detection rules
  • •Strong knowledge of MITRE ATT&CK at the procedure level and telemetry required for detection
  • •Practical coding/automation skills (Python, scripting, API-driven workflows) to improve efficiency
  • •Understanding of Threat Intelligence Lifecycle and analytical models (Diamond Model, Kill Chain)
Experience:CybersecurityThreat intelligenceMITRE ATTACKAutomationSOC
Skills:PythonSOARPower AutomateN8NAPIsMITRE ATT&CKCrowdStrikeVirusTotal
Languages:English
Tech Stack:PythonSOARPower AutomateN8NAPIsMITRE ATT&CKCrowdStrikeVirusTotal

Company Brief

Allianz
Global insurance and financial services group offering property-casualty insurance, life and health insurance, asset management, and corporate risk solutions to individuals, businesses, and institutions across more than 70 countries.
Industry: Insurance
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Munich, Germany
Founded: 1890
WebsiteLinkedIn