Zalando
Senior Cyber Threat Intelligence Engineer (all genders)
Zalando, Berlin, New Hampshire, us, 03570
Senior Cyber Threat Intelligence Engineer (all genders)
As a Senior Threat Intelligence Engineer, you will play a critical role in driving our security operations team’s efforts to specialize in proactive threat detection, threat intelligence integration, and enhancing our cybersecurity response capabilities. Your primary responsibility will be to lead our threat hunting efforts, identify emerging threats, and integrate actionable threat intelligence into our detection and response strategies. In this role, you will create advanced detection use cases, develop automated responses, and contribute to both tactical and strategic threat defense measures.INCLUSIVE BY DESIGN
At Zalando, our vision is to be inclusive by design. We do not discriminate on the basis of gender identity, sexual orientation, personal expression, ethnicity, religious belief, or disability status. You are welcome to leave out your picture, age, or marital status from your application. We only assess candidates on their qualifications and merit.We want to provide you with a great candidate experience. Feel free to inform us of any accommodations you may need, so we can best support you throughout the hiring process.WHAT WE’D LOVE YOU TO DO (AND LOVE DOING)
Lead proactive threat-hunting activities by developing hypotheses, methodologies, and tools to uncover sophisticated threats that evade traditional detection.Integrate and validate threat intelligence from multiple sources into security monitoring tools, ensuring detection rules are continuously updated and optimized for accuracy.Create, maintain, and automate advanced SIEM detection use cases, focusing on advanced persistent threats (APTs), insider threats, and nation-state actors, while continuously fine-tuning them for operational efficiency.Collaborate closely with Incident Response teams during the entire Security Incident Lifecycle to ensure rapid containment, mitigation, and recovery of security incidents.Detect and prevent fraudulent behaviors as per the OWASP Automated Threats methodology, particularly in areas like Account Takeovers, multi-account misuse, and bot-driven scalping, ensuring legitimate users are protected from automated abuse.MINIMUM REQUIREMENTS
You have 5+ years of experience in threat hunting or Cyber Security Incident response in a CSIRT or SOC.You have deep expertise in security monitoring, detection, and analysis methodologies, including XDR, network-based intrusion detection, web application firewalls, and SIEM solutions.You have a strong understanding of the MITRE ATT&CK Framework, the Cyber Kill Chain, and NIST, and can apply these to improve threat detection capabilities.You have experience with threat intelligence platforms, indicator management, and the integration of intelligence into detection platforms.You gained coding skills, mainly in Python (or another main programming language).You possess excellent communication skills, both verbal and written, with a proven track record of engaging senior stakeholders during crisis situations.Experience in AWS/GCP/Azure and Kubernetes security topics would be a plus.If you think you have what it takes, we encourage you to apply even if you don't meet every single requirement. You may just be the right candidate for this or other roles!OUR OFFER
Zalando provides a range of benefits, here’s an overview of what you can expect. Ask your Talent Acquisition Partner to learn more about what we offer.Employee shares program40% off fashion and beauty products sold and shipped by Zalando, 30% off Zalando Lounge, discounts from external partners2 paid volunteering days a yearHybrid working model with 60% (or more) remote per week, actual practice is up to each team to best support their collaborationWork from abroad for up to 30 working days a year27 days of vacation a year to startRelocation assistance available (subject to prior agreement)Family services, including counseling and supportHealth and wellbeing options (including Gympass)Mental health support and coaching available
#J-18808-Ljbffr
As a Senior Threat Intelligence Engineer, you will play a critical role in driving our security operations team’s efforts to specialize in proactive threat detection, threat intelligence integration, and enhancing our cybersecurity response capabilities. Your primary responsibility will be to lead our threat hunting efforts, identify emerging threats, and integrate actionable threat intelligence into our detection and response strategies. In this role, you will create advanced detection use cases, develop automated responses, and contribute to both tactical and strategic threat defense measures.INCLUSIVE BY DESIGN
At Zalando, our vision is to be inclusive by design. We do not discriminate on the basis of gender identity, sexual orientation, personal expression, ethnicity, religious belief, or disability status. You are welcome to leave out your picture, age, or marital status from your application. We only assess candidates on their qualifications and merit.We want to provide you with a great candidate experience. Feel free to inform us of any accommodations you may need, so we can best support you throughout the hiring process.WHAT WE’D LOVE YOU TO DO (AND LOVE DOING)
Lead proactive threat-hunting activities by developing hypotheses, methodologies, and tools to uncover sophisticated threats that evade traditional detection.Integrate and validate threat intelligence from multiple sources into security monitoring tools, ensuring detection rules are continuously updated and optimized for accuracy.Create, maintain, and automate advanced SIEM detection use cases, focusing on advanced persistent threats (APTs), insider threats, and nation-state actors, while continuously fine-tuning them for operational efficiency.Collaborate closely with Incident Response teams during the entire Security Incident Lifecycle to ensure rapid containment, mitigation, and recovery of security incidents.Detect and prevent fraudulent behaviors as per the OWASP Automated Threats methodology, particularly in areas like Account Takeovers, multi-account misuse, and bot-driven scalping, ensuring legitimate users are protected from automated abuse.MINIMUM REQUIREMENTS
You have 5+ years of experience in threat hunting or Cyber Security Incident response in a CSIRT or SOC.You have deep expertise in security monitoring, detection, and analysis methodologies, including XDR, network-based intrusion detection, web application firewalls, and SIEM solutions.You have a strong understanding of the MITRE ATT&CK Framework, the Cyber Kill Chain, and NIST, and can apply these to improve threat detection capabilities.You have experience with threat intelligence platforms, indicator management, and the integration of intelligence into detection platforms.You gained coding skills, mainly in Python (or another main programming language).You possess excellent communication skills, both verbal and written, with a proven track record of engaging senior stakeholders during crisis situations.Experience in AWS/GCP/Azure and Kubernetes security topics would be a plus.If you think you have what it takes, we encourage you to apply even if you don't meet every single requirement. You may just be the right candidate for this or other roles!OUR OFFER
Zalando provides a range of benefits, here’s an overview of what you can expect. Ask your Talent Acquisition Partner to learn more about what we offer.Employee shares program40% off fashion and beauty products sold and shipped by Zalando, 30% off Zalando Lounge, discounts from external partners2 paid volunteering days a yearHybrid working model with 60% (or more) remote per week, actual practice is up to each team to best support their collaborationWork from abroad for up to 30 working days a year27 days of vacation a year to startRelocation assistance available (subject to prior agreement)Family services, including counseling and supportHealth and wellbeing options (including Gympass)Mental health support and coaching available
#J-18808-Ljbffr