Information Security - Senior Threat Detection & Response Engineer

Ryanair Group Holdings

Wrocław

On-site

PLN 260,000 - 420,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Staff travel benefits
Multisport card
Training and certifications
Office events

Job summary

Ryanair Labs, the technology arm of Ryanair, seeks an Information Security – Senior Threat Detection & Response Engineer to strengthen detection, incident response, and threat-hunting capabilities across AWS, GCP and Azure. You will implement detections as code, validate with adversary emulation, and drive continuous improvement in telemetry coverage and security controls.

You will collaborate with cross-functional teams to map MITRE ATT&CK against cloud environments, onboard log sources, tune

Qualifications

  • 6+ years hands-on in detection engineering, senior SOC analyst or incident response.
  • Deep hands-on SIEM skills: Microsoft Sentinel, Splunk, Elastic (ELK) or OpenSearch with their query languages (KQL, SPL, ES|QL/Lucene).
  • Hands-on EDR: Microsoft Defender, SentinelOne or CrowdStrike.
  • Sigma, including converting and testing rules against each backend.
  • Multicloud security across AWS, GCP and Azure: audit and security telemetry.
  • Proven track record of finding and closing detection or visibility gaps, with examples.
  • Adversary emulation / breach-and-attack-simulation experience.
  • Strong Python or PowerShell; Git and CI for detection-as-code.
  • LLM-assisted tooling in detection and automation with validation.

Responsibilities

  • Own detection and visibility across AWS, GCP and Azure control planes and identity.
  • Run purple-team exercises and convert findings into detections and mitigations.
  • Hunt for uncovered techniques and extend coverage maps.
  • Lead containment, eradication and recovery during incidents; perform forensic analysis.
  • Automate enrichment, triage and response using scripting and automation tools.
  • Leverage LLM assistants and agentic coding tools to speed up rule authoring and testing.
  • Produce coverage and performance metrics for leadership.

Skills

Detection engineering
Incident response
Python / PowerShell
Git & CI
Communication under pressure
MITRE ATT&CK
Threat hunting
Multicloud security

Tools

Microsoft Sentinel
Splunk
Elastic/OpenSearch
Sigma
KQL
SPL
OpenSearch

Job description

Information Security – Senior Threat Detection & Response Engineer
  • Full-time

Ryanair Labs are currently recruiting for Information Security – Senior Threat Detection & Response Engineers to join Europe’s Largest Airline Group!

This is a very exciting time to join Ryanair as we look to expand our operation to 800 aircraft and 300 million guests within the next 10 years.

Ryanair Labs is the technology brand of Ryanair. Labs is a state of-the-art digital & IT innovation hub creating Europe's Leading Travel Experience for our customers.

About the role

A hands-on, individual-contributor role in a lean airline security team. Your core job is to proactively find where we are blind or exposed missing telemetry, missing detections, weak or unvalidated controls across on-prem, endpoint and multicloud (AWS, GCP, Azure) environments, and to close those gaps methodically, with evidence that each one is closed. You also take part in incident response: the gaps you find come from real incidents, and the fixes you build get tested by them.

  • Find. Map current telemetry and detections against MITRE ATT&CK (Navigator/DeTT&CT), including the cloud matrices (IaaS, SaaS, Identity Provider) for AWS, GCP and Azure; run adversary emulation and breach-and-attack-simulation tests; mine incidents, hunts, pentests and threat intel for techniques we couldn't see or stop; audit log-source health and asset coverage.
  • Define. Turn each gap into a written item: technique, affected assets, risk, required telemetry, detection logic, mitigation, owner and acceptance test. Prioritise into a single backlog against the threats most relevant to aviation.
  • Fix. Onboard and normalise log sources; build detections as code (Sigma as the source of truth, converted to KQL, SPL or Elastic/OpenSearch queries; version-controlled and tested in CI); tune to an agreed false-positive budget; work with platform owners to implement and verify preventive controls (hardening, EDR policy, identity and conditional access, cloud guardrails); re-test to prove closure; update the coverage map.
What you'll do
  • Own detection and visibility across AWS, GCP and Azure control planes and identity: audit-log ingestion, native security-service alerts, and misconfiguration/exposure findings feeding the gap backlog.
  • Run purple-team exercises with red-team/pentest partners and convert findings into detections and mitigations.
  • Hunt proactively for techniques the coverage map shows as uncovered.
  • Lead containment, eradication and recovery during incidents; perform forensic analysis; feed lessons straight back into the gap backlog.
  • Automate enrichment, triage and response (SOAR, Python, PowerShell) where it removes manual toil.
  • Use LLM assistants and agentic coding tools (Claude Code, OpenCode) to speed up rule authoring, backend conversion, test-case generation, parser/automation code and triage, validating outputs before anything reaches production.
  • Produce coverage and performance metrics directly from the work (ATT&CK coverage %, gap closure rate, validation pass rate, MTTD/MTTR) for leadership.
Must have
  • 6+ years hands-on in detection engineering, senior SOC analyst or incident response.
  • Deep hands-on SIEM skills: Microsoft Sentinel, Splunk, Elastic (ELK) or OpenSearch, including their query languages (KQL, SPL, ES|QL/Lucene).
  • Hands-on EDR: Microsoft Defender, SentinelOne or CrowdStrike, including their hunting query interfaces and custom detection rules.
  • Sigma, including converting and testing rules against each backend.
  • Multicloud security across AWS, GCP and Azure: audit and security telemetry (CloudTrail/GuardDuty, Cloud Audit Logs/Security Command Center, Azure Activity + Entra ID logs/Defender for Cloud), IAM and identity attack paths, and cloud-specific detection use cases.
  • Proven track record of finding and closing detection or visibility gaps, with examples of your methodology.
  • Practical MITRE ATT&CK use for coverage assessment, not just tagging.
  • Adversary emulation / breach-and-attack-simulation experience.
  • Strong Python or PowerShell; comfortable with Git and CI for detection-as-code.
  • Effective daily use of LLM assistants and agentic coding tools (e.g., Claude Code, OpenCode) for detection-as-code, automation and analysis, with critical validation of output and within approved data-handling boundaries.
  • Clear communication under incident pressure.
Nice to have
  • Aviation, logistics or other regulated-sector experience; NIS2 / EASA Part-IS.
  • SOAR platform experience.
  • Elastic Security detection rules and OpenSearch Security Analytics (Sigma-native).
  • Container/Kubernetes telemetry (EKS, GKE, AKS) and CSPM/CNAPP tooling.
  • Certifications: GDAT, GCIH, GCFA, GCIA, AZ-500, AWS Security Specialty, Google Professional Cloud Security Engineer.
  • Threat modelling / adversary profiling; exposure-management or attack-path tooling.
  • AI security: MITRE ATLAS, OWASP Top 10 for LLM Applications; agentic security automation with LLM agents.
Benefits & form of employment
Contract of employment

(permanent contract after trial period)

  • Staff travel benefits from day one
  • Multisport card
Other benefits:
  • Possibility of taking part in trainings and certifications
  • Great chance to meet your colleagues in other offices
  • Annual events (i.e. St. Patrick’s Day )
  • Regular social meetings
  • Paid referral system
  • New office building surrounded by great dinettes right in the city centre
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security – Senior Threat Detection & Response Engineer
Information Security – Senior Threat Detection & Response Engineer

Ryanair Group Holdings • Wrocław

On-site
PLN 180,000 - 300,000
Staff travel benefits
Multisport card
Training & certifications
+2
Information Security – Senior Threat Detection & Response Engineer
Information Security – Senior Threat Detection & Response Engineer

Ryanair - Europe's Favourite Airline • Wrocław

Hybrid
PLN 180,000 - 240,000
Staff travel benefits from day one
Multisport card
Private health care
+1
Information Security – Senior Threat Detection & Response Engineer
Information Security – Senior Threat Detection & Response Engineer

Ryanair Ltd. • Wrocław

Hybrid
PLN 180,000 - 280,000
Hybrid model
Staff travel benefits
Multisport card
+2
Information Security Engineer – Senior Penetration Tester
Information Security Engineer – Senior Penetration Tester

Ryanair Group Holdings • Wrocław

On-site
PLN 200,000 - 320,000
Staff travel benefits
Multisport card
Information Security Architect – AI & Strategic Initiatives
Information Security Architect – AI & Strategic Initiatives

Ryanair Ltd. • Wrocław

Hybrid
PLN 260,000 - 420,000
Staff travel benefits from day one
Multisport card
Training and certifications
Information Security Architect – AI & Strategic Initiatives
Information Security Architect – AI & Strategic Initiatives

Ryanair - Europe's Favourite Airline • Wrocław

On-site
PLN 260,000 - 420,000
Staff travel benefits from day one
Multisport card
Private health care
+1
Information Security Engineer – Senior Penetration Tester
Information Security Engineer – Senior Penetration Tester

Ryanair - Europe's Favourite Airline • Wrocław

Hybrid
PLN 180,000 - 300,000
Staff travel benefits from day one
Multisport card
Private health care
+1
Information Security Engineer – Senior Penetration Tester
Information Security Engineer – Senior Penetration Tester

Ryanair Ltd. • Wrocław

Hybrid
PLN 120,000 - 180,000
Staff travel benefits
Multisport card
Training & certifications
+1
Information Security Architect - AI & Strategic Initiatives
Information Security Architect - AI & Strategic Initiatives

Ryanair Group Holdings • Wrocław

On-site
PLN 394,000 - 657,000
Staff travel benefits from day one
Multisport card
Training and certifications
Information Security Analyst SOC Tier 1
Information Security Analyst SOC Tier 1

Ryanair - Europe's Favourite Airline • Wrocław

On-site
PLN 100,000 - 150,000
Staff travel benefits from day one
Multisport card
Private health care
+1