Threat Detection & Response Engineer — Cross-Cloud Lead

Ryanair Group Holdings

Wrocław

On-site

PLN 260,000 - 420,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Staff travel benefits
Multisport card
Training and certifications
Office events

Job summary

Ryanair Labs, the technology arm of Ryanair, seeks an Information Security – Senior Threat Detection & Response Engineer to strengthen detection, incident response, and threat-hunting capabilities across AWS, GCP and Azure. You will implement detections as code, validate with adversary emulation, and drive continuous improvement in telemetry coverage and security controls.

You will collaborate with cross-functional teams to map MITRE ATT&CK against cloud environments, onboard log sources, tune

Qualifications

  • 6+ years hands-on in detection engineering, senior SOC analyst or incident response.
  • Deep hands-on SIEM skills: Microsoft Sentinel, Splunk, Elastic (ELK) or OpenSearch with their query languages (KQL, SPL, ES|QL/Lucene).
  • Hands-on EDR: Microsoft Defender, SentinelOne or CrowdStrike.
  • Sigma, including converting and testing rules against each backend.
  • Multicloud security across AWS, GCP and Azure: audit and security telemetry.
  • Proven track record of finding and closing detection or visibility gaps, with examples.
  • Adversary emulation / breach-and-attack-simulation experience.
  • Strong Python or PowerShell; Git and CI for detection-as-code.
  • LLM-assisted tooling in detection and automation with validation.

Responsibilities

  • Own detection and visibility across AWS, GCP and Azure control planes and identity.
  • Run purple-team exercises and convert findings into detections and mitigations.
  • Hunt for uncovered techniques and extend coverage maps.
  • Lead containment, eradication and recovery during incidents; perform forensic analysis.
  • Automate enrichment, triage and response using scripting and automation tools.
  • Leverage LLM assistants and agentic coding tools to speed up rule authoring and testing.
  • Produce coverage and performance metrics for leadership.

Skills

Detection engineering
Incident response
Python / PowerShell
Git & CI
Communication under pressure
MITRE ATT&CK
Threat hunting
Multicloud security

Tools

Microsoft Sentinel
Splunk
Elastic/OpenSearch
Sigma
KQL
SPL
OpenSearch

Job description

Ryanair Labs, the technology arm of Ryanair, seeks an Information Security – Senior Threat Detection & Response Engineer to strengthen detection, incident response, and threat-hunting capabilities across AWS, GCP and Azure. You will implement detections as code, validate with adversary emulation, and drive continuous improvement in telemetry coverage and security controls.

You will collaborate with cross-functional teams to map MITRE ATT&CK against cloud environments, onboard log sources, tune

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Multicloud Threat Detection & Response Engineer
Senior Multicloud Threat Detection & Response Engineer

Ryanair Ltd. • Wrocław

Hybrid
PLN 180,000 - 280,000
Hybrid model
Staff travel benefits
Multisport card
+2
Senior Threat Detection & Response Engineer - Cloud & IR
Senior Threat Detection & Response Engineer - Cloud & IR

Ryanair - Europe's Favourite Airline • Wrocław

Hybrid
PLN 180,000 - 240,000
Staff travel benefits from day one
Multisport card
Private health care
+1
Senior Threat Detection & Response Engineer – Multicloud Security
Senior Threat Detection & Response Engineer – Multicloud Security

Ryanair Group Holdings • Wrocław

On-site
PLN 180,000 - 300,000
Staff travel benefits
Multisport card
Training & certifications
+2
Senior Penetration Tester: Cloud, AI & App Security
Senior Penetration Tester: Cloud, AI & App Security

Ryanair Ltd. • Wrocław

Hybrid
PLN 120,000 - 180,000
Staff travel benefits
Multisport card
Training & certifications
+1
Senior Penetration Tester: Cloud, AI & App Security
Senior Penetration Tester: Cloud, AI & App Security

Ryanair Group Holdings • Wrocław

On-site
PLN 200,000 - 320,000
Staff travel benefits
Multisport card
Senior AI Security Architect: Multicloud & Strategy
Senior AI Security Architect: Multicloud & Strategy

Ryanair Ltd. • Wrocław

Hybrid
PLN 260,000 - 420,000
Staff travel benefits from day one
Multisport card
Training and certifications
AI Security Architect: Automate & Secure Multicloud
AI Security Architect: Automate & Secure Multicloud

Ryanair - Europe's Favourite Airline • Wrocław

On-site
PLN 260,000 - 420,000
Staff travel benefits from day one
Multisport card
Private health care
+1
AI Security Architect: Strategic Initiatives & Multicloud
AI Security Architect: Strategic Initiatives & Multicloud

Ryanair Group Holdings • Wrocław

On-site
PLN 394,000 - 657,000
Staff travel benefits from day one
Multisport card
Training and certifications
Information Security – Senior Threat Detection & Response Engineer
Information Security – Senior Threat Detection & Response Engineer

Ryanair - Europe's Favourite Airline • Wrocław

Hybrid
PLN 180,000 - 240,000
Staff travel benefits from day one
Multisport card
Private health care
+1
Information Security – Senior Threat Detection & Response Engineer
Information Security – Senior Threat Detection & Response Engineer

Ryanair Group Holdings • Wrocław

On-site
PLN 180,000 - 300,000
Staff travel benefits
Multisport card
Training & certifications
+2