Cyber Threat Hunter
Role details
Job location
Tech stack
Job description
Are you driven by curiosity and motivated to stay ahead of cyber adversaries? As a Cyber Threat Hunter, you will proactively uncover advanced and hidden threats before they become incidents. You will think like an attacker, challenge assumptions, and help strengthen ING's resilience against evolving cyber risks.
The team
You will join ING's Global Threat Management (GTM) team, a central capability within the CISO domain that focuses on intelligence-driven, proactive defence. The team works across geographies and disciplines to anticipate emerging threats, investigate advanced attack scenarios, and continuously improve ING's detection and defensive posture. Collaboration, communication, ownership, and impact are core to how we work.
Your key responsibilities: As a Cyber Threat Hunter, you will:
- Proactively conduct intelligence-led threat hunting based on emerging threats, adversary activity, and major external cyber incidents.
- Develop and test hypothesis-driven investigations to identify unknown or evasive malicious activity.
- Analyse adversary behaviour across the full attack chain, identifying detection and control gaps.
- Translate hunt outcomes into actionable improvements for detection, prevention, and defensive architecture.
- Map findings to MITRE ATT&CK to clearly articulate threats, gaps, and priorities.
- Communicate investigation outcomes in clear, executive-ready reports that supportrisk-based decision-making.
- Leverage automation, AI-assisted analytics, and Breach & Attack Simulation (BAS) to continuously validate threat hypotheses, test adversary techniques, and prioritise high-risk attack paths.
Requirements
- Several years of hands-on experience in threat hunting activities.
- Ability to translate threat intelligence into concrete, high-impact investigations.
- Skill in identifying meaningful security gaps rather than chasing alerts or noise.
- Capacity to think and reason like an adversary while acting as a defender.
- Ability to deliver investigation outcomes that improve detection, controls, or resilience.
- Clear communication of complex threats to both technical and non-technical stakeholders.
- Ability to work effectively in an environment with ambiguity, autonomy, and high trust.
You'll get extra points for:
- Experience or relevant certifications in cyber threat hunting, detection engineering, or adversary simulation (e.g., GIAC, MITRE ATT&CK, cloud security, or BAS-related certifications) are considered an advantage.
Benefits & conditions
The time you spend at work, the challenges you face or the lessons you get are very important, but… What about your personal life? At ING we want your work to fulfill you in every way, and that is why we take care of even the smallest details.
Check out what is waiting for you!
Be flexible my friend.
Our model is all about flexibility and accountability. Keeping both our customers and our colleagues needs in mind, you determine together which days you work at home and which you come to ING MAD to offer your best self. Do your thing.
Restaurant card.
So that thinking about what to have for lunch doesn't take up your time or your cravings.
Our house will be your home.
In our offices you can find electric mobility solutions, doctor, hairdresser, gym, The Good Service (to help you with your errands) and much more!
Health insurance.
For you and all your family (spouse/partner and children).
Life insurance.
We help you protect what matters most to you.
Flexible remuneration.
In addition, you will enjoy our flexible remuneration model, through a more tax-advantaged way, you will be able to access other services such as nursery, transport card, training aids…
Transport allowance.
It doesn't matter where you live, we'll help you get to the office.
Pension plan.
You can benefit from our pension plan after 1 month with us!
Discover ING Hubs Spain
We're building something exciting-and we want you to be part of it.