{"id":1588437,"url":"https://alion.io/job/allianz-threat-intelligence-engineer","title":"Threat Intelligence Engineer","company":{"id":1757325,"name":"Allianz","domain":"allianz.com","url":"https://alion.io/company/allianz-com","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SuccessFactors","truth_index":null},"role":"Security","role_family":"Security","seniority":null,"employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Barcelona, Spain"],"countries":["ES"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":48000,"max_usd":121000,"period":"year","method":"role_country_seniority_unknown","sample_n":10},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Crowdstrike","optional":false},{"name":"Cyber Kill Chain","optional":false},{"name":"Diamond Model","optional":false},{"name":"Google SecOps","optional":false},{"name":"MISP","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"n8n","optional":false},{"name":"Power Automate","optional":false},{"name":"Python","optional":false},{"name":"Recorded Future","optional":false},{"name":"VirusTotal","optional":false}],"status":"live","first_seen_at":"2026-09-10T02:00:00Z","employer_posted_date":"2026-09-10","last_verified_at":"2026-10-01T15:28:30Z","board_verified":true,"closed_at":null,"days_open":22,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":22},"description":"About the Job\nYou know adversaries by how they operate - and you know how to turn that knowledge into action. As a Threat Intelligence Engineer - Intrusion Analysis & Detection, you will help transform threat actor behavior into concrete defensive value: stronger detections, smarter hunting hypotheses, and intelligence that helps defenders move faster and more effectively.\nWithin the Allianz Cyber Defense Center (ACDC), you will join a team that is evolving towards an AI-augmented, intelligence-driven operating model. This is a high-impact opportunity to shape and mature intrusion analysis capabilities, automate repetitive intelligence workflows, and directly influence how a global organization defends itself against real-world threats. If you enjoy combining technical depth, analytical thinking, and practical execution, this role will give you the platform to make a visible difference at scale.\nWhat you do\nAnalyze real-world attacks, post-incident findings, and emerging adversary tradecraft to identify relevant threat activity and convert retrospective analysis into forward-looking intelligence.\nTranslate threat intelligence into actionable detection content by producing detection rules and analytical guidance for deployment by detection engineering teams across platform-native environments.\nTrack threat actors and map tactics, techniques, and procedures to MITRE ATT&CK, identifying coverage gaps and generating meaningful hunting leads based on relevance to the Allianz environment.\nBuild and maintain automation for repetitive intelligence workflows using SOAR platforms, Power Automate, N8N, Python, scripting, and API integrations to improve speed, quality, and consistency.\nApply AI in daily analytical workflows to categorize incoming intelligence, enrich indicators, correlate reporting with tracked topics, and accelerate decision-making.\nCommunicate findings clearly through dashboards, written intelligence notes, and operational briefings so that detection engineers, incident responders, IT administrators, and leadership can act confidently.\nSupport the full IOC lifecycle and contribute during active security incidents by providing timely analytical input, validation, and triage support as part of on-call rotations.\nWhat you bring\nHands-on experience in intrusion analysis, including the investigation of real-world attack patterns, adversary behavior, and post-incident evidence.\nProven ability to turn intelligence into action through detection engineering, including authoring, tuning, or validating detection rules in production environments.\nStrong knowledge of MITRE ATT&CK, especially at procedure level, and a solid understanding of the telemetry required to detect adversary activity effectively.\nPractical coding and automation skills, ideally in Python, scripting, and API-driven workflows, with a builder mindset focused on improving efficiency through automation.\nGood understanding of the Threat Intelligence Lifecycle and structured analytical techniques, including models such as the Diamond Model and Kill Chain.\nExperience working with or exposure to tools such as Google SecOps, CrowdStrike Falcon / Intelligence, Google Threat Intelligence / VirusTotal, Recorded Future, MISP, or similar platforms.\nA proactive, outcome-driven mindset with the ability to stay composed under pressure, communicate clearly during incidents, and collaborate effectively across technical teams.\nWhat we offer\nWe offer a hybrid work model which recognizes the value of striking a balance between in-person collaboration and remote working incl. up to 25 days per year working from abroad.\nWe believe in rewarding performance and our compensation and benefits package includes a company bonus scheme, pension, employee shares program and multiple employee discounts (details vary by location).\nFrom career development and digital learning programs to international career mobility, we offer lifelong learning for our employees worldwide and an environment where innovation, delivery and empowerment are fostered.\nFlexible working, health and wellbeing offers (including healthcare and parental leave benefits) support to balance family and career and help our people return from career breaks with experience that nothing else can teach.\nAbout Allianz Technology\nWith its headquarters in Munich, Germany, Allianz Technology is Allianz's global IT service provider and delivers IT solutions that drive the group's digitalization. With more than 11,000 employees in over 20 countries around the world, Allianz Technology is tasked to run, optimize, transform, and innovate the infrastructure, applications, and services together with Allianz companies to co-create the best customer experience.\nWe service the entire spectrum of digitalization - from one of the industry's largest IT infrastructure projects that spans data centres, networks, and security, to application platforms ranging from workplace services to digital interaction.\nIn short: We deliver comprehensive end-to-end IT solutions for Allianz in the digital age. We are the backbone of Allianz.\nFind us at: www.linkedin.com/company/allianz-technology.\nCommitment to Integrity, Fairness & Inclusion\nAllianz Technology is proud to be an equal opportunity employer dedicated to fostering an inclusive work environment for everyone. We embrace individuals of all gender identities and expressions, sexual orientations, ethnicities, ages, nationalities, religions, disabilities, and philosophies of life. Ultimately, our greatest strength as a company lies in the unique skills, experiences, and backgrounds our employees contribute.\nWe therefore welcome applications regardless of race, ethnicity or cultural background, age, gender, nationality, religion, social class, disability or sexual orientation, or any other characteristics protected under applicable local laws and regulations.\nTo Recruitment Agencies:\nAllianz Technology has an in-house recruitment team that sources great candidates directly. Therefore, Allianz Technology does not accept unsolicited resumes from agencies or search firm recruiters.\nWhen we do work with recruitment agencies, that engagement is formalized by a contract. Fees will only be paid when there is a contract in place. Without a contract in place, we will not accept invoices on unsolicited resumes, even if the candidate was ultimately employed by Allianz.\n100801 | Ingeniería informática y tecnológica | Profesional / Senior | Non-Executive | Allianz Technology | Jornada completa | Indefinido","description_format":"text","description_chars":6534,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Flexible schedule","Hybrid work","Parental leave"],"hiring_locations":[{"name":"Spain","iso":"ES","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Threat Intelligence","Information Security"],"lifecycle":[{"event":"open","at":"2026-10-01T15:26:34Z"}],"liveness":{"score":31,"band":"fade","label":"Fading","p_open":1,"p_active":0.57,"p_room":0.55,"age_days":22,"expected_fill_days":21,"reasons":["conf:11","win:tail","comp:brand"],"computed_at":"2026-10-02T03:24:02Z"},"pay":null,"html_url":"https://alion.io/job/allianz-threat-intelligence-engineer","json_url":"https://alion.io/job/allianz-threat-intelligence-engineer.json","meta":{"generated_at":"2026-10-02T03:24:02Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4677,"day_limit":5000,"remaining_today":323,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}