Threat Engineering Lead

Posted 6 Days Ago
Be an Early Applicant
Centro, Maripí, Boyacá, COL
In-Office
Senior level
Fintech • Payments • Financial Services
The Role
Senior individual-contributor owning threat hunting, detection engineering and automated response. Build detection-as-code, apply AI/ML for triage/hunting, partner with CTI/SOC/engineering, validate with emulation and metrics, and improve enterprise detection and incident response.
Summary Generated by Built In

Take a step forward and let Edenred surprise you.

Every day, we deliver innovative solutions to improve the life of millions of people, connecting employees, companies, and merchants all around the world. 

We know there are hundred ways for you to grow. With us, you will expand your skills in a multicultural, challenging, and dynamic environment. 

Dare to join Edenred and get ready to thrive in a global company that will offer you endless opportunities.

Edenred is all about meritocracy. You come as you are, and you contribute. Indeed, the Edenred Group recognizes, recruits and develops all talents and singularities.

We are committed to preventing all forms of discrimination and to providing all our candidates with equal opportunities regardless of their gender and gender expression, disability, origin, religious belief and sexual orientation or any other criteria.

ABOUT EDENRED

Edenred is a pioneer, a tech leader and the everyday companion for people at work across 44 countries.

Our 12,000 employees are committed to making the world of work a better place for all, one that is safer, more efficient and more user-friendly. At Edenred, our passion for customers, respect, imagination, simplicity and entrepreneurial spirit are our values. For anyone who needs to vibe in their professional life, we are the best place for you to work and grow.

The Edenred Digital Center (EDC) in Bucharest, Romania is Edenred Group's new Digital hub for strategic IT projects.

Context/ROLE

The Threat Engineer Lead is responsible for transforming internal and external threat intelligence into actionable detection capabilities, threat hunting programs, automated response workflows, and AI-driven security operations improvements.

A senior individual-contributor role owning the evolution of Edenred's threat hunting, detection, and response capabilities. The position focuses on proactively identifying threats, engineering scalable and high-fidelity detections and continuously improving incident response outcomes across Edenred's security ecosystem. By applying AI/ML selectively and pragmatically to detection, triage and investigation workflows, the role drives greater speed, precision and operational effectiveness while ensuring robust validation and governance. This is a highly technical leadership role with enterprise-wide influence and no people management responsibilities. The role serves as the critical bridge between Cyber Threat Intelligence (CTI), CSIRT, detection Engineering and security Automation. The successful candidate will design and implement processes, technologies and operating models that enable proactive identification, detection and response to emerging cyber threats.

Position SCOPE & Key Responsibilities

Threat Engineering Lead - Threat Hunting, Detection & Response will:

  • Identify opportunities to automate threat intelligence processing, triage, investigation, and response activities
  • Own the detection data pipeline and a reference architecture; threat-model current and new systems; evaluate and select tooling; align to MITRE ATT&CK, NIST CSF and ISO 27001 (PCI DSS / DORA where applicable) and report coverage
  • Implement detection engineering, test and maintain detections as code; own the false-positive / false-negative lifecycle; map coverage to ATT&CK; favor behavior-based detections; report detection-quality metrics
  • AI / ML for threat detection & response - accelerate authoring and translation behind an automated validation harness; automate alert triage and enrichment; apply ML to support anomaly-driven threat hunting and behavioral baselining; always human-in-the-loop, never an unchecked decision-maker
  • Partner closely with CTI providers, SOC analysts, incident managers and security engineering teams to transform threat intelligence, incident learnings and emerging threat indicators into enterprise detection and response capabilities
  • Lead the development of threat hunting campaigns, detection use cases, behavioral analytics, automated response workflows and security architecture improvements
  • Validate outcomes through threat emulation, coverage assessment, detection quality metrics and operational response effectiveness.

Required skills & profile

Experience

  • 8+ years across detection engineering, threat hunting and incident response, owning detection content end-to-end
  • Splunk experience, EDR experience (CrowdStrike, Defender, TrendMicro), Zscaler experience, Azure experience, AWS experience
  • Detection-as-code practice: version control, testing and CI; able to defend detection quality with metrics
  • Strong automation in Python (a plus); production security tooling and API integrations
  • Demonstrated application of AI/ML to security workflows, with a discipline of validating outputs before production
  • MITRE ATT&CK fluency; Windows / Linux / macOS and M365 / Azure / AWS security; security architecture and threat-modelling ability
  • Engineering discipline applied to detection, code review, testing, measurable outcomes; AI as an accelerator under human oversight
  • Collaborative mindset with the ability to work effectively across SOC, engineering, infrastructure, cloud and business teams
  • Demonstrated ability to communicate security risks, detection gaps and architectural recommendations to both technical and non-technical stakeholders
  • Ability to effectively communicate investigation findings, threat assessments and response recommendations during active incidents
  • Proven ability to facilitate discussions, challenge assumptions constructively and build consensus on security decisions
  • Excellent written communication skills, including architecture documentation, technical standards, detection specifications and executive-ready reporting
  • Strong mentoring and knowledge-sharing mindset, helping elevate the technical capabilities of analysts, engineers and security practitioners
  • Calm, structured and decisive approach during security incidents and crisis situations

Nice to have:

  • GIAC/CISSP/Azure Security; purple teaming (Atomic Red Team, Caldera); email security (DMARC/BEC); ZTNA/SASE/DLP; payments-reg exposure (PCI DSS/DORA)
  • Experience implementing AI-assisted SOC capabilities
  • Experience with Detection-as-Code frameworks
  • Experience with security telemetry engineering
  • Experience building enterprise-wide threat hunting programs
  • Experience in global enterprise environments

Languages:

  • Mandatory: Proficient level of English (spoken and written)

VIBE WITH US

Joining us means:

  • Becoming part of a team that embraced the digitalization challenge and enjoys this transformation every day
  • Living our values every day: passions for customers, respect, imagination, simplicity, entrepreneurial spirit.

Because:

  • You will get exposure to various global cultures and teams
  • You will be working with the newest technologies to build a new platform from scratch
  • We offer you a very pleasant working environment, close to Bucharest city center
  • We also have for you: meal tickets, holiday vouchers, health subscription, flexible hours, work from home, flexible benefits system, on-the-job training & e-learning platforms.

And we do not stop here!

Apply now and Vibe with Us!

Skills Required

  • 8+ years experience in detection engineering, threat hunting and incident response, owning detection content end-to-end
  • Splunk experience
  • EDR experience (CrowdStrike, Microsoft Defender, Trend Micro)
  • Zscaler experience
  • Azure experience
  • AWS experience
  • Detection-as-code practice: version control, testing and CI
  • Demonstrated application of AI/ML to security workflows with disciplined validation
  • MITRE ATT&CK fluency
  • Windows, Linux, macOS and M365/Azure/AWS security knowledge
  • Security architecture and threat modelling ability
  • Ability to communicate investigation findings and risk to technical and non-technical stakeholders during incidents
  • Excellent written communication, documentation and executive-ready reporting
  • Mentoring and knowledge-sharing mindset to elevate analysts and engineers
  • Calm, structured and decisive approach during security incidents
  • Strong automation in Python
  • GIAC/CISSP/Azure Security, purple teaming, email security (DMARC/BEC), ZTNA/SASE/DLP, PCI DSS/DORA exposure
  • Experience with Detection-as-Code frameworks, security telemetry engineering, AI-assisted SOC capabilities and building enterprise threat hunting programs
  • Proficient English (spoken and written)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Issy-les-Moulineaux
7,105 Employees

What We Do

Edenred is a leading digital platform for services and payments and the everyday companion for people at work, connecting 60 million users and 2 million partner merchants in 45 countries via close to 1 million corporate clients. Edenred offers specific-purpose payment solutions for food (such as meal benefits), incentives (such as gift cards, employee engagement platforms), mobility (such as multi-energy, maintenance, toll, parking and commuter solutions) and corporate payments (such as virtual cards). True to the Group’s purpose, “Enrich connections. For good.”, these solutions enhance users’ well-being and purchasing power. They improve companies’ attractiveness and efficiency, and vitalize the employment market and the local economy. They also foster access to healthier food, more environmentally friendly products and softer mobility. Edenred’s 12,000 employees are committed to making the world of work a connected ecosystem that is safer, more efficient and more responsible every day. In 2022, thanks to its global technology assets, the Group managed some €38 billion in business volume, primarily carried out via mobile applications, online platforms and cards. Edenred is listed on the Euronext Paris stock exchange and included in the following indices: CAC 40, CAC 40 ESG, CAC Large 60, Euronext 100, Euronext Tech Leaders, FTSE4Good and MSCI Europe. Our employees vibe with a passion for customer service, respect, imagination, simplicity and the entrepreneurial spirit that are Edenred’s values. For everyone who wants to experience that vibe, who needs it in their professional life, we want to be the best company to come and work and develop each person who takes part in the Edenred adventure

Similar Jobs

Luxury Presence Logo Luxury Presence

Senior Devops Engineer

Marketing Tech • Real Estate • Software • PropTech • SEO
Easy Apply
Remote or Hybrid
12 Locations
500 Employees

UL Solutions Logo UL Solutions

Engineering Project Handler

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Remote or Hybrid
Colombia
15000 Employees

UL Solutions Logo UL Solutions

Project Engineer

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Remote or Hybrid
Colombia
15000 Employees

Cloudflare Logo Cloudflare

Senior Account Executive

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
Colombia
4400 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account