> Markdown version of [/jobs/ext/2442789-cybersecurity-engineer-1](https://www.wearedevelopers.com/jobs/ext/2442789-cybersecurity-engineer-1). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CyberSecurity Engineer 1 - **Company:** Global Business Travel Group, Inc. - **Location:** Providence, RI, United States - **Experience:** Starter - **Salary:** $84,700.0 - $157,300.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing Security, Cyber Security, Python (Programming Language), Open Source Intelligence, Windows PowerShell, Red Team (Cyber Security), Scripting, Data Server Interface, Mitre Att&ck, Cyber Threat Analysis, Enterprise Integration - **Published:** August 19, 2026 - **Apply:** https://www.juju.com/job/00000000gnsamb ## About the Role + 1-3 years in cybersecurity with exposure to threat intel and/or offensive security + Foundational knowledge of MITRE ATT&CK + Familiarity with IOCs, TTPs, Diamond Model, kill chain analysis + Basic scripting (Python, PowerShell, or Bash) + Ability to learn and support SOAR/CAO workflows + Strong written communication for reports and documentation + Interest in offensive security and willingness to learn + Understanding of APIs and workflow integration Preferred Qualifications + Experience with a TIP (e.g., Cyber6Gill/Bitsight, ISACs, CrowdStrike CAO Elite) + Exposure to AD attacks (BloodHound, Kerberoasting) or cloud security (AWS/Azure) + CTF, home lab, or self-directed offensive security practice + Certifications/coursework (Security+, GCTI, eJPT, OSCP progress) + Experience with Atomic Red Team or similar frameworks ## Description The Cybersecurity Analyst, Threat Intelligence & Red Team is a hybrid role supporting our Counter Adversary Operations function. This position splits its time between working as a Threat Intelligence Analyst ingesting, enriching, and actioning threat intel from multiple sources and fulfilling intel requests from partner teams and supporting our Red Team as a contributor to hands-on offensive security testing. This role is well suited to an analyst early in their offensive security career who wants to build technical red team skills while developing strong threat intelligence fundamentals. The candidate will work closely with senior red teamers, threat hunters, detection engineers, and IR to help mature our security posture across a global, highly distributed travel and hospitality technology enterprise. What You'll Do Threat Intelligence + Monitor, triage, and ingest threat intel from OSINT, ISACs, and vendor feeds into the TIP + Enrich IOCs/TTPs and correlate with internal telemetry + Respond to RFIs from IR, DSI, and leadership + Produce threat briefs, IOC packages, and actor profiles for travel/hospitality + Map threat actor TTPs to MITRE ATT&CK + Translate intel into hunt leads and detection opportunities Red Team Support + Assist with scoped engagements (recon, scanning, exploitation, lateral movement) under supervision ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)