Information Security – Senior Threat Detection & Response Engineer

Ryanair - Europe's Favourite Airline

Wrocław

Hybrid

PLN 180,000 - 240,000

Full time

12 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Staff travel benefits from day one
Multisport card
Private health care
Group insurance scheme

Job summary

Ryanair Labs is hiring a Senior Information Security Engineer focused on Threat Detection & Response. You will proactively identify gaps in telemetry and detections across on-prem, endpoints and multicloud environments (AWS, GCP, Azure), closing them with evidence-backed fixes.

You’ll participate in incident response, lead containment and recovery, and automate detection and response using code and CI/CD practices. Hybrid work options apply.

Qualifications

  • 6+ years hands-on in detection engineering, senior SOC analyst or incident response.
  • Hands-on SIEM skills: Microsoft Sentinel, Splunk, Elastic/OpenSearch.
  • Multicloud security across AWS, GCP and Azure with telemetry and IAM considerations.
  • Practical MITRE ATT&CK usage for coverage assessment and threat mapping.

Responsibilities

  • Own detection and visibility across AWS, GCP and Azure control planes and identity." audit-log ingestion, native security-service alerts, and misconfiguration findings feeding the gap backlog.
  • Run purple-team exercises with red-team/pentest partners and convert findings into detections and mitigations.
  • Hunt proactively for techniques the coverage map shows as uncovered.
  • Lead containment, eradication and recovery during incidents; perform forensic analysis; feed lessons back into the backlog.
  • Automate enrichment, triage and response (SOAR, Python, PowerShell) to remove manual toil.
  • Use LLM assistants and agentic coding tools to speed up rule authoring and testing, with validation before production.
  • Produce coverage and performance metrics (ATT&CK coverage, gap closure, MTTD/MTTR) for leadership.

Skills

Threat detection
Incident response
MITRE ATT&CK
Cloud security
Threat hunting
Python/PowerShell

Tools

Microsoft Sentinel
Splunk
Elastic/OpenSearch
Sigma
Microsoft Defender
CrowdStrike
SentinelOne

Job description

Ryanair Labs are currently recruiting for an Information Security - Senior Threat Detection & Response Engineers to join Europe’s Largest Airline Group!

This is a very exciting time to join Ryanair as we look to expand our operation to 800 aircraft and 300 million guests within the next 10 years.

Ryanair Labs is the technology brand of Ryanair. Labs is a state of-the-art digital & IT innovation hub creating Europe’s Leading Travel Experience for our customers.

About The Role

A hands-on, individual-contributor role in a lean airline security team. Your core job is to proactively find where we are blind or exposed missing telemetry, missing detections, weak or unvalidated controls across on-prem, endpoint and multicloud (AWS, GCP, Azure) environments, and to close those gaps methodically, with evidence that each one is closed. You also take part in incident response: the gaps you find come from real incidents, and the fixes you build get tested by them.

How you’ll work: find - define - fix
  • Find. Map current telemetry and detections against MITRE ATT&CK (Navigator/DeTT&CT), including the cloud matrices (IaaS, SaaS, Identity Provider) for AWS, GCP and Azure; run adversary emulation and breach-and-attack-simulation tests; mine incidents, hunts, pentests and threat intel for techniques we couldn’t see or stop; audit log-source health and asset coverage.
  • Define. Turn each gap into a written item: technique, affected assets, risk, required telemetry, detection logic, mitigation, owner and acceptance test. Prioritise into a single backlog against the threats most relevant to aviation.
  • Fix. Onboard and normalise log sources; build detections as code (Sigma as the source of truth, converted to KQL, SPL or Elastic/OpenSearch queries; version-controlled and tested in CI); tune to an agreed false-positive budget; work with platform owners to implement and verify preventive controls (hardening, EDR policy, identity and conditional access, cloud guardrails); re-test to prove closure; update the coverage map.
What You’ll Do
  • Own detection and visibility across AWS, GCP and Azure control planes and identity: audit-log ingestion, native security-service alerts, and misconfiguration/exposure findings feeding the gap backlog.
  • Run purple-team exercises with red-team/pentest partners and convert findings into detections and mitigations.
  • Hunt proactively for techniques the coverage map shows as uncovered.
  • Lead containment, eradication and recovery during incidents; perform forensic analysis; feed lessons straight back into the gap backlog.
  • Automate enrichment, triage and response (SOAR, Python, PowerShell) where it removes manual toil.
  • Use LLM assistants and agentic coding tools (Claude Code, OpenCode) to speed up rule authoring, backend conversion, test-case generation, parser/automation code and triage, validating outputs before anything reaches production.
  • Produce coverage and performance metrics directly from the work (ATT&CK coverage %, gap closure rate, validation pass rate, MTTD/MTTR) for leadership.
Must have
  • 6+ years hands-on in detection engineering, senior SOC analyst or incident response.
  • Deep hands-on SIEM skills: Microsoft Sentinel, Splunk, Elastic (ELK) or OpenSearch, including their query languages (KQL, SPL, ES|QL/Lucene).
  • Hands-on EDR: Microsoft Defender, SentinelOne or CrowdStrike, including their hunting query interfaces and custom detection rules.
  • Sigma, including converting and testing rules against each backend.
  • Multicloud security across AWS, GCP and Azure: audit and security telemetry (CloudTrail/GuardDuty, Cloud Audit Logs/Security Command Center, Azure Activity + Entra ID logs/Defender for Cloud), IAM and identity attack paths, and cloud-specific detection use cases.
  • Proven track record of finding and closing detection or visibility gaps, with examples of your methodology.
  • Practical MITRE ATT&CK use for coverage assessment, not just tagging.
  • Adversary emulation / breach-and-attack-simulation experience.
  • Strong Python or PowerShell; comfortable with Git and CI for detection-as-code.
  • Effective daily use of LLM assistants and agentic coding tools (e.g., Claude Code, OpenCode) for detection-as-code, automation and analysis, with critical validation of output and within approved data-handling boundaries.
  • Clear communication under incident pressure.
Nice to have
  • Aviation, logistics or other regulated-sector experience; NIS2 / EASA Part-IS.
  • SOAR platform experience.
  • Elastic Security detection rules and OpenSearch Security Analytics (Sigma-native).
  • Container/Kubernetes telemetry (EKS, GKE, AKS) and CSPM/CNAPP tooling.
  • Certifications: GDAT, GCIH, GCFA, GCIA, AZ-500, AWS Security Specialty, Google Professional Cloud Security Engineer.
  • Threat modelling / adversary profiling; exposure-management or attack-path tooling.
  • AI security: MITRE ATLAS, OWASP Top 10 for LLM Applications; agentic security automation with LLM agents.
Benefits & Form Of Employment
Contract of employment (permanent contract after trial period)
  • Possible hybrid model (2 days from the office weekly)
  • Staff travel benefits from day one
  • Multisport card
  • Private health care
  • Group insurance scheme
Other Benefits
  • Possibility of taking part in trainings and certifications
  • Great chance to meet your colleagues in other offices
  • Annual events (i.e. St. Patrick's Day)
  • Regular social meetings
  • Paid referral system
  • New office building surrounded by great dinettes right in the city centre
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security - Senior Threat Detection & Response Engineer
Information Security - Senior Threat Detection & Response Engineer

Ryanair Group Holdings • Wrocław

On-site
PLN 260,000 - 420,000
Staff travel benefits
Multisport card
Training and certifications
+1
Information Security – Senior Threat Detection & Response Engineer
Information Security – Senior Threat Detection & Response Engineer

Ryanair Group Holdings • Wrocław

On-site
PLN 180,000 - 300,000
Staff travel benefits
Multisport card
Training & certifications
+2
Information Security – Senior Threat Detection & Response Engineer
Information Security – Senior Threat Detection & Response Engineer

Ryanair Ltd. • Wrocław

Hybrid
PLN 180,000 - 280,000
Hybrid model
Staff travel benefits
Multisport card
+2
Information Security Architect – AI & Strategic Initiatives
Information Security Architect – AI & Strategic Initiatives

Ryanair - Europe's Favourite Airline • Wrocław

On-site
PLN 260,000 - 420,000
Staff travel benefits from day one
Multisport card
Private health care
+1
Information Security Engineer – Senior Penetration Tester
Information Security Engineer – Senior Penetration Tester

Ryanair - Europe's Favourite Airline • Wrocław

Hybrid
PLN 180,000 - 300,000
Staff travel benefits from day one
Multisport card
Private health care
+1
Information Security Engineer – Senior Penetration Tester
Information Security Engineer – Senior Penetration Tester

Ryanair Group Holdings • Wrocław

On-site
PLN 200,000 - 320,000
Staff travel benefits
Multisport card
Information Security Architect – AI & Strategic Initiatives
Information Security Architect – AI & Strategic Initiatives

Ryanair Ltd. • Wrocław

Hybrid
PLN 260,000 - 420,000
Staff travel benefits from day one
Multisport card
Training and certifications
Information Security Engineer – Senior Penetration Tester
Information Security Engineer – Senior Penetration Tester

Ryanair Ltd. • Wrocław

Hybrid
PLN 120,000 - 180,000
Staff travel benefits
Multisport card
Training & certifications
+1
Information Security Architect - AI & Strategic Initiatives
Information Security Architect - AI & Strategic Initiatives

Ryanair Group Holdings • Wrocław

On-site
PLN 394,000 - 657,000
Staff travel benefits from day one
Multisport card
Training and certifications
Information Security Analyst SOC Tier 1
Information Security Analyst SOC Tier 1

Ryanair - Europe's Favourite Airline • Wrocław

On-site
PLN 100,000 - 150,000
Staff travel benefits from day one
Multisport card
Private health care
+1