CyberSecurity Engineer 1

Global Business Travel Group, Inc.
Santa Fe, NM, United States
15 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
1 year minimum
Compensation
$84,700.0 - $157,300.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Security Cyber Security Python (Programming Language) Open Source Intelligence Windows PowerShell Red Team (Cyber Security) Scripting Data Server Interface
+3 more
Mitre Att&ck Cyber Threat Analysis Enterprise Integration

Job description

The Cybersecurity Analyst, Threat Intelligence & Red Team is a hybrid role supporting our Counter Adversary Operations function. This position splits its time between working as a Threat Intelligence Analyst ingesting, enriching, and actioning threat intel from multiple sources and fulfilling intel requests from partner teams and supporting our Red Team as a contributor to hands-on offensive security testing.

This role is well suited to an analyst early in their offensive security career who wants to build technical red team skills while developing strong threat intelligence fundamentals. The candidate will work closely with senior red teamers, threat hunters, detection engineers, and IR to help mature our security posture across a global, highly distributed travel and hospitality technology enterprise.

What You’ll Do

Threat Intelligence

  • Monitor, triage, and ingest threat intel from OSINT, ISACs, and vendor feeds into the TIP

  • Enrich IOCs/TTPs and correlate with internal telemetry

  • Respond to RFIs from IR, DSI, and leadership

  • Produce threat briefs, IOC packages, and actor profiles for travel/hospitality

  • Map threat actor TTPs to MITRE ATT&CK

  • Translate intel into hunt leads and detection opportunities

Red Team Support

  • Assist with scoped engagements (recon, scanning, exploitation, lateral movement) under supervision

Requirements

  • 1-3 years in cybersecurity with exposure to threat intel and/or offensive security

  • Foundational knowledge of MITRE ATT&CK

  • Familiarity with IOCs, TTPs, Diamond Model, kill chain analysis

  • Basic scripting (Python, PowerShell, or Bash)

  • Ability to learn and support SOAR/CAO workflows

  • Strong written communication for reports and documentation

  • Interest in offensive security and willingness to learn

  • Understanding of APIs and workflow integration

Preferred Qualifications

  • Experience with a TIP (e.g., Cyber6Gill/Bitsight, ISACs, CrowdStrike CAO Elite)

  • Exposure to AD attacks (BloodHound, Kerberoasting) or cloud security (AWS/Azure)

  • CTF, home lab, or self-directed offensive security practice

  • Certifications/coursework (Security+, GCTI, eJPT, OSCP progress)

  • Experience with Atomic Red Team or similar frameworks

Benefits & conditions

$84,700.00 - $157,300.00

The national range provided includes the base salary that Amex GBT expects to pay for the role. Actual base salary will be based on factors including the scope and complexity of the role and the successful candidate’s relevant experience, skills, knowledge, and work location.

For information about our comprehensive US benefits programs and eligibility, please review our Benefits-at-a-Glance document.

Benefits at a glance (https://experience100.ehr.com/LinkClick.aspx?fileticket=CjACTXO3wMk%3d&portalid=66)

The #TeamGBT Experience

Work and life: Find your happy medium at Amex GBT.

  • Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family.

  • Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals.

  • Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first.

  • We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all