Jobs and Careers
DE
Senior - Threat Intelligence Engineering
DeloitteSpainfull_timeVerifiedPosted 3 Jul 2024
About the role
<p> </p>
<p> </p>
<p> </p>
<p><span><span>¿Can you imagine participating in the transformation of leading national and international organizations?</span></span></p>
<p><span><span>At Deloitte, we are committed to making an impact on society, our clients, and you.</span></span></p>
<p> </p>
<p><span><span>As part of the global Centralized Cybersecurity Threat Intel team, the Threat Intelligence Engineer reports to the Signatures & Tools Manager. Intelligence Engineering lives within the collection function of the Threat Intelligence group. </span></span></p>
<p> </p>
<p><span><span>As a Threat Intelligence Engineer, you will enable the automated collection, processing, storage, and dissemination of cyber threat data to/from a central Threat Intelligence Platform (TIP), a link analysis tool, open source indicator sharing platform, and other tools and databases that facilitate research and analysis. The Threat Intelligence Engineer is responsible for streamlining collection of threat indicators, designing applications that process data from disparate sources, and integrating intelligence outputs with cyber defense technologies. </span></span></p>
<p> </p>
<p> </p>
<p><span><span><b><span>What is the challenge?</span></b></span></span></p>
<p> </p>
<ul>
<li><span><span>Create<b> workflows and playbooks</b> to parse, format, and tag imported threat data, to include creating new data objects, defining data object values, and defining metadata.</span></span></li>
<li><span><span>Enable TIP to <b>automatically disseminate select threat data</b> to Deloitte security appliances, to include writing custom scripts as well as working with off-the-shelf integrations/apps.</span></span></li>
<li><span><span><b>Implement solutions </b>through our existing DevOps maturity model, primarily utilizing languages such as <b>Python</b> and accessing data via restful <b>APIs.</b></span></span></li>
<li><span><span>Perform <b>administration</b> and <b>maintenance </b>activities <b>for tools and databases</b> owned and maintained by the Threat Intelligence Service.</span></span></li>
<li><span><span><b>Relay updates and roadmaps</b> from vendors to development stakeholders.</span></span></li>
<li><span><span>Involve yourself in <b>agile documentation practices</b>.</span></span></li>
<li><span><span>Follow the Definition of Done for both developments and integrations,<b> conduct implementation and development testing</b>, adhering to standards.</span></span></li>
<li><span><span><b>Support </b>Secure Systems Development Lifecycle (<b>SSDLC</b>), including functional and non-functional cybersecurity requirements for all new application developments.</span></span></li>
<li><span><span>Partner with other cyber security and information technology teams to create and document processes and technologies, define requirements/use cases for integrations, and collaborate on user acceptance and systems integration testing.</span></span></li>
</ul>
<p> </p>
<p> </p>
<p><span><span><b><span>How do we imagine you?</span></b></span></span></p>
<p> </p>
<ul>
<li><span><span><b>Required:</b></span></span>
<ul>
<li><span><span>Bachelor’s Degree preferably in a technology-related field, or equivalent education-related experience.</span></span></li>
<li><span><span>Minimum of <b>3 years of experience in Security Engineering.</b></span></span></li>
<li><span><span><b>Understanding</b> of<b> OSI Layer</b>, <b>network</b> fundamentals and <b>protocols.</b></span></span></li>
<li><span><span><b>Knowledge on authentication </b>and authorization concepts &<b> User Account Management.</b></span></span></li>
<li><span><span>Experience in <b>understanding</b> Application Resource Management and <b>troubleshooting.</b></span></span></li>
<li><span><span>Experience in <b>development/writing API connectors </b>and scalable <b>applications.</b></span></span></li>
<li><span><span>Thorough understanding of technology infrastructures using<b> Firewalls, VPN, Data Loss Prevention, IDS/IPS, and Web-Proxy.</b></span></span></li>
<li><span><span>Ability to <b>automate </b>manual processes in<b> Python and/or PowerShell.</b></span></span></li>
<li><span><span>Experience defining customer requirements/use cases for scripts or application integrations.</span></span></li>
</ul>
</li>
</ul>
<p> </p>
<ul>
<li><span><span><b>Preferred:</b></span></span>
<ul>
<li><span><span>Understanding of host and network forensic artifacts and indicators of compromise.</span></span></li>
<li><span><span>Experience orchestrating processing of information with Threat Intel Platforms, Link Analysis tools, MISP, Azure DevOps, or any Orchestration tools.</span></span></li>
<li><span><span>Experience working with Splunk, to include integrating external data via Splunk Apps or the Splunk API.</span></span></li>
<li><span><span>Experience managing threat data feeds from commercial threat intelligence vendors.</span></span></li>
<li><span><span>Understanding of Splunk Enterprise Security, to
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s