Ryanair - Europe's Favourite Airline

Information Security Engineer – Cyber Threat Detection & Response

Posted: 1 minutes ago

Job Description

DescriptionRyanair Labs are currently recruiting for a Information Security Engineer – Cyber Threat Detection & Response to join Europe’s Largest Airline Group!This is a very exciting time to join Ryanair as we look to expand our operation to 800 aircraft and 300 million guests within the next 10 years.Ryanair Labs is the technology brand of Ryanair. Labs is a state of-the-art digital & IT innovation hub creating Europe’s Leading Travel Experience for our customers.The RoleWe are seeking an experienced Senior Threat Detection & Response Engineer to join our cybersecurity team supporting a fast-paced, cost-sensitive airline environment. The ideal candidate has a strong technical background in detection engineering, incident response and computer forensics. You will be responsible for developing actionable detections, responding to security incidents, and producing insightful KPI reports to support decision-making and regulatory compliance.Key ResponsibilitiesDevelop and tune threat detection rules across SIEM, EDR, and cloud environments.Lead containment, eradication, and recovery efforts for cyber incidents.Create and maintain dashboards to track KPIs such as MTTD, MTTR, detection coverage, and investigation volume.Perform threat hunting based on current threat intelligence and adversary TTPs.Automate alert enrichment, triage, and response workflows using SOAR or scripting (Python/PowerShell).Collaborate with IT, cloud, and compliance teams to enhance detection quality and response readiness.Contribute to documentation, playbooks, and continuous process improvement.Requirements6+ years in SOC, IR, or threat detection rolesHands-on experience with SIEM (e.g., Microsoft Sentinel, Splunk), EDR (e.g., Defender, CrowdStrike)Experience with Azure/AWS cloud security logs and detection use casesPractical knowledge of MITRE ATT&CKAbility to produce meaningful metrics and dashboards (e.g., Sentinel Workbooks, Power BI, Kibana)Strong scripting skills (Python, PowerShell)Clear communication skills across technical and non-technical stakeholders Nice To HaveExperience in aviation, logistics, or other regulated sectorsFamiliarity with SOAR platformsCertifications such as GCIA, GCIH, OSCP, or cloud security (AZ-500, AWS Security Specialty)Understanding of NIS2 or EASA cybersecurity guidance BenefitsOur offer:Contract of employment (permanent after trial period)Hybrid home office (2 days per week from the office, 3 days remote)Discounted and unlimited travel to over 250 destinationsMultisport cardPrivate health careGroup insurance schemePossibility to take part in conferences, training and courses– – – and – – –Office located in the city center with a view for an Old Market SquareAnnual events (i.e. St. Patrick’s Day 🍀)Regular social meetings 🍻Paid referral systemNew office building surrounded by great dinettes right in the city centre 🌆Apply today to discuss the role in more detail!CompetenciesCloudCoding / ProgrammingCyber Security AwarenessCommunication

Job Application Tips

  • Tailor your resume to highlight relevant experience for this position
  • Write a compelling cover letter that addresses the specific requirements
  • Research the company culture and values before applying
  • Prepare examples of your work that demonstrate your skills
  • Follow up on your application after a reasonable time period

You May Also Be Interested In