Back to board
Early applicant
edenpeople·5 hours ago

Threat Engineering Lead

Edenred Digital Center, RomaniaSenior · 6-10 yearsH1B likely

About this role

Take a step forward and let Edenred surprise you.

Every day, we deliver innovative solutions to improve the life of millions of people, connecting employees, companies, and merchants all around the world. 

We know there are hundred ways for you to grow. With us, you will expand your skills in a multicultural, challenging, and dynamic environment. 

Dare to join Edenred and get ready to thrive in a global company that will offer you endless opportunities.

Edenred is all about meritocracy. You come as you are, and you contribute. Indeed, the Edenred Group recognizes, recruits and develops all talents and singularities.

We are committed to preventing all forms of discrimination and to providing all our candidates with equal opportunities regardless of their gender and gender expression, disability, origin, religious belief and sexual orientation or any other criteria.

ABOUT EDENRED

Edenred is a pioneer, a tech leader and the everyday companion for people at work across 44 countries.

Our 12,000 employees are committed to making the world of work a better place for all, one that is safer, more efficient and more user-friendly. At Edenred, our passion for customers, respect, imagination, simplicity and entrepreneurial spirit are our values. For anyone who needs to vibe in their professional life, we are the best place for you to work and grow.

The Edenred Digital Center (EDC) in Bucharest, Romania is Edenred Group's new Digital hub for strategic IT projects.

Context/ROLE

The Threat Engineer Lead is responsible for transforming internal and external threat intelligence into actionable detection capabilities, threat hunting programs, automated response workflows, and AI-driven security operations improvements.

A senior individual-contributor role owning the evolution of Edenred's threat hunting, detection, and response capabilities. The position focuses on proactively identifying threats, engineering scalable and high-fidelity detections and continuously improving incident response outcomes across Edenred's security ecosystem. By applying AI/ML selectively and pragmatically to detection, triage and investigation workflows, the role drives greater speed, precision and operational effectiveness while ensuring robust validation and governance. This is a highly technical leadership role with enterprise-wide influence and no people management responsibilities. The role serves as the critical bridge between Cyber Threat Intelligence (CTI), CSIRT, detection Engineering and security Automation. The successful candidate will design and implement processes, technologies and operating models that enable proactive identification, detection and response to emerging cyber threats.

Position SCOPE & Key Responsibilities

Threat Engineering Lead - Threat Hunting, Detection & Response will:

  • Identify opportunities to automate threat intelligence processing, triage, investigation, and response activities
  • Own the detection data pipeline and a reference architecture; threat-model current and new systems; evaluate and select tooling; align to MITRE ATT&CK, NIST CSF and ISO 27001 (PCI DSS / DORA where applicable) and report coverage
  • Implement detection engineering, test and maintain detections as code; own the false-positive / false-negative lifecycle; map coverage to ATT&CK; favor behavior-based detections; report detection-quality metrics
  • AI / ML for threat detection & response - accelerate authoring and translation behind an automated validation harness; automate alert triage and enrichment; apply ML to support anomaly-driven threat hunting and behavioral baselining; always human-in-the-loop, never an unchecked decision-maker
  • Partner closely with CTI providers, SOC analysts, incident managers and security engineering teams to transform threat intelligence, incident learnings and emerging threat indicators into enterprise detection and response capabilities
  • Lead the development of threat hunting campaigns, detection use cases, behavioral analytics, automated response workflows and security architecture improvements
  • Validate outcomes through threat emulation, coverage assessment, detection quality metrics and operational response effectiveness.

Required skills & profile

Experience

  • 8+ years across detection engineering, threat hunting and incident response, owning detection content end-to-end
  • Splunk experience, EDR experience (CrowdStrike, Defender, TrendMicro), Zscaler experience, Azure experience, AWS experience
  • Detection-as-code practice: version control, testing and CI; able to defend detection quality with metrics
  • Strong automation in Python (a plus); production security tooling and API integrations
  • Demonstrated application of AI/ML to security workflows, with a discipline of validating outputs before production
  • MITRE ATT&CK fluency; Windows / Linux / macOS and M365 / Azure / AWS security; security architecture and threat-modelling ability
  • Engineering discipline applied to detection, code review, testing, measurable outcomes; AI as an accelerator under human oversight
  • Collaborative mindset with the ability to work effectively across SOC, engineering, infrastructure, cloud and business teams
  • Demonstrated ability to communicate security risks, detection gaps and architectural recommendations to both technical and non-technical stakeholders
  • Ability to effectively communicate investigation findings, threat assessments and response recommendations during active incidents
  • Proven ability to facilitate discussions, challenge assumptions constructively and build consensus on security decisions
  • Excellent written communication skills, including architecture documentation, technical standards, detection specifications and executive-ready reporting
  • Strong mentoring and knowledge-sharing mindset, helping elevate the technical capabilities of analysts, engineers and security practitioners
  • Calm, structured and decisive approach during security incidents and crisis situations

Nice to have:

  • GIAC/CISSP/Azure Security; purple teaming (Atomic Red Team, Caldera); email security (DMARC/BEC); ZTNA/SASE/DLP; payments-reg exposure (PCI DSS/DORA)
  • Experience implementing AI-assisted SOC capabilities
  • Experience with Detection-as-Code frameworks
  • Experience with security telemetry engineering
  • Experience building enterprise-wide threat hunting programs
  • Experience in global enterprise environments

Languages:

  • Mandatory: Proficient level of English (spoken and written)

VIBE WITH US

Joining us means:

  • Becoming part of a team that embraced the digitalization challenge and enjoys this transformation every day
  • Living our values every day: passions for customers, respect, imagination, simplicity, entrepreneurial spirit.

Because:

  • You will get exposure to various global cultures and teams
  • You will be working with the newest technologies to build a new platform from scratch
  • We offer you a very pleasant working environment, close to Bucharest city center
  • We also have for you: meal tickets, holiday vouchers, health subscription, flexible hours, work from home, flexible benefits system, on-the-job training & e-learning platforms.

And we do not stop here!

Apply now and Vibe with Us!