> Markdown version of [/jobs/ext/1939551-privileged-access-management-pam-engineer](https://www.wearedevelopers.com/jobs/ext/1939551-privileged-access-management-pam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Privileged Access Management (Pam) Engineer - **Company:** Boehringer Ingelheim - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software System Penetration Testing, Cloud Computing, Cyber Security, Linux, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Red Team (Cyber Security), Scripting, Mitre Att&ck, Cyber Threat Analysis, Cybercrime, Purple Team (Cyber Security) - **Published:** August 5, 2026 - **Apply:** https://www.buscojobs.com.es/privileged-access-management-pam-engineer-en-madrid-ID-365508785 ## About the Role Minimum 5 years of experience in threat detection, threat hunting, detection engineering, red team, or penetration testing Strong experience designing and tuning detection rules in enterprise environments Advanced expertise in EDR/XDR platforms (e.g. Microsoft Defender / Microsoft XDR) Solid knowledge of MITRE ATT&CK and adversary?driven detection Hands?on understanding of advanced attack techniques across Windows, Linux, and cloud Strong scripting skills (Python, PowerShell, or similar) Experience collaborating with red, purple, or penetration testing teams Ability to translate offensive tradecraft into high?fidelity detections OSEP and CARTE (or equivalent) certifications required Fluent English; experience in global, cross?functional teams preferred ## Description The Senior Threat Detection Analyst is a cybersecurity expert responsible for advancing the organization's ability to detect sophisticated and emerging cyber threats across on?premises, cloud, and hybrid environments.This role focuses on advanced detection engineering, proactive threat hunting, and adversary?driven detection, working closely with Threat Intelligence, Security Operations, Incident Response, and Red/Purple Teams.The position plays a strategic role in strengthening the security posture by improving detection maturity, closing visibility gaps, and reducing false positives through high?fidelity detection logic.Tasks and ResponsibilitiesDesign, implement, and continuously improve advanced threat detection capabilitiesDevelop, tune, and maintain high?quality detection rules and behavioral analyticsConduct proactive, hypothesis?driven threat hunting activitiesTranslate adversary TTPs and attack techniques into actionable detectionsCollaborate with Threat Intelligence, SOC, Incident Response, and Red/Purple TeamsAnalyze complex attack chains, kill chains, and post?exploitation activityIdentify detection gaps and contribute to continuous detection maturity improvementsReduce false positives while maintaining effective threat visibilitySupport purple team activities by leveraging red team and penetration test outputsRequirementsMinimum 5 years of experience in threat detection, threat hunting, detection engineering, red team, or penetration testingStrong experience designing and tuning detection rules in enterprise environmentsAdvanced expertise in EDR/XDR platforms (e.g. Microsoft Defender / Microsoft XDR)Solid knowledge of MITRE ATT&CK and adversary?driven detectionHands?on understanding of advanced attack techniques across Windows, Linux, and cloudStrong scripting skills (Python, PowerShell, or similar)Experience collaborating with red, purple, or penetration testing teamsAbility to translate offensive tradecraft into high?fidelity detectionsOSEP and CARTE (or equivalent) certifications requiredFluent English; experience in global, cross?functional teams preferredBenefitsFlexible working conditionsLife and accident insuranceHealth insurance at a competitive priceInvestment in your learning and developmentGym membership discounts#J-*****-Ljbffr ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)