Job Search and Career Advice Platform

Enable job alerts via email!

Information Security Engineer - Cyber Threat Detection & Response

Ryanair

Polska

Hybrid

PLN 180,000 - 240,000

Full time

10 days ago

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading airline technology brand is looking for an experienced Information Security Engineer in Poland to enhance their cybersecurity operations. The role involves developing threat detection rules, responding to incidents, and creating meaningful metrics. Ideal candidates should have over six years in threat detection and hands-on knowledge of SIEM tools. This position offers a hybrid work model and various employee benefits including travel discounts and private health care.

Benefits

Discounted and unlimited travel
Private health care
Multisport card
Participation in conferences and training

Qualifications

  • 6+ years in SOC, IR, or threat detection roles.
  • Hands-on experience with SIEM and EDR.
  • Experience with Azure/AWS cloud security logs.
  • Practical knowledge of MITRE ATT&CK.

Responsibilities

  • Develop and tune threat detection rules across environments.
  • Lead containment and recovery efforts for incidents.
  • Create dashboards to track relevant KPIs.
  • Perform threat hunting based on current intelligence.

Skills

Cyber Security Awareness
Scripting (Python, PowerShell)
Cloud security
Communication

Tools

SIEM (Microsoft Sentinel, Splunk)
EDR (Defender, CrowdStrike)
Power BI
Kibana
Job description
Information Security Engineer – Cyber Threat Detection & Response

Ryanair Labs are currently recruiting for a Information Security Engineer - Cyber Threat Detection & Response to join Europe's Largest Airline Group! This is a very exciting time to join Ryanair as we look to expand our operation to 800 aircraft and 300 million guests within the next 10 years. Ryanair Labs is the technology brand of Ryanair. Labs is a state of-the-art digital & IT innovation hub creating Europe's Leading Travel Experience for our customers.

The Role

We are seeking an experienced Senior Threat Detection & Response Engineer to join our cybersecurity team supporting a fast‑paced, cost‑sensitive airline environment. The ideal candidate has a strong technical background in detection engineering, incident response and computer forensics. You will be responsible for developing actionable detections, responding to security incidents, and producing insightful KPI reports to support decision‑making and regulatory compliance.

Key Responsibilities
  • Develop and tune threat detection rules across SIEM, EDR, and cloud environments.
  • Lead containment, eradication, and recovery efforts for cyber incidents.
  • Create and maintain dashboards to track KPIs such as MTTD, MTTR, detection coverage, and investigation volume.
  • Perform threat hunting based on current threat intelligence and adversary TTPs.
  • Automate alert enrichment, triage, and response workflows using SOAR or scripting (Python/PowerShell).
  • Collaborate with IT, cloud, and compliance teams to enhance detection quality and response readiness.
  • Contribute to documentation, playbooks, and continuous process improvement.
Requirements
  • 6+ years in SOC, IR, or threat detection roles
  • Hands‑on experience with SIEM (e.g., Microsoft Sentinel, Splunk), EDR (e.g., Defender, CrowdStrike)
  • Experience with Azure/AWS cloud security logs and detection use cases
  • Practical knowledge of MITRE ATT&CK
  • Ability to produce meaningful metrics and dashboards (e.g., Sentinel Workbooks, Power BI, Kibana)
  • Strong scripting skills (Python, PowerShell)
  • Clear communication skills across technical and non‑technical stakeholders
Nice to have
  • Experience in aviation, logistics, or other regulated sectors
  • Familiarity with SOAR platforms
  • Certifications such as GCIA, GCIH, OSCP, or cloud security (AZ-500, AWS Security Specialty)
  • Understanding of NIS2 or EASA cybersecurity guidance
Benefits – Our Offer
  • Contract of employment (permanent after trial period)
  • Hybrid home office (2 days per week from the office, 3 days remote)
  • Discounted and unlimited travel to over 250 destinations
  • Multisport card
  • Private health care
  • Group insurance scheme
  • Possibility to take part in conferences, training and courses
Additional Office Perks
  • Office located in the city centre with a view for an Old Market Square
  • Annual events (i.e. St. Patrick's Day)
  • Regular social meetings
  • Paid referral system
  • New office building surrounded by great dinettes right in the city centre
Apply today to discuss the role in more detail!
Competencies
  • Cloud
  • Coding / Programming
  • Cyber Security Awareness
  • Communication
General Information

Business unit: Office
Division: Labs
Employment Type: Permanent

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.