Cyber Defense & Incident Response

Delivery Hero SE
Málaga, Spain
13 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Amazon Web Services Cloud Computing Cloud Engineering Digital Forensics Intrusion Detection and Prevention Python (Programming Language) Security Log Security Information and Event Management Mitre Att&ck Cyber Threat Analysis Cybercrime Software Coding
+3 more
Cyber Warfare Security Orchestration, Automation & Response Golang

Job description

Job DescriptionIf you’re here, it’s because you’re looking for an exciting ride.A ride that will fuel up your ambitions to take on a new challenge and stretch yourself beyond your comfort zone. We’ll deliver a non-vanilla culture built on talent, where we work to amplify the impact on millions of people, paving the way forward together.MissionGlovo’s success and constant growth introduce complex challenges in defending our ecosystem. We are looking for a CSIRT Engineer to join our Cyber Defense team. Your mission is to be the shield of Glovo, ensuring we are not just ready to respond to threats, but proactive enough to hunt them down before they arrive. You will be a key player in building a “SOCless” future through high-level automation and sophisticated detection engineering.The JourneyBe the First Responder: Support Digital Forensics and Incident Response (DFIR) efforts, conducting deep-dive investigations into security breaches and anomalies following the Cyber Incident Response Cycle.Architect Readiness: Design and maintain the playbooks and investigation methodologies that ensure Glovo is prepared for any security incident.Precision Monitoring: Create, validate, and fine-tune alerts to ensure high fidelity and low noise, turning raw logs into actionable intelligence.Automate & Orchestrate: Contribute our “SOCless” ambition by building tooling and automation for incident response, reducing manual toil through smart orchestration.Hunt the Threat: Proactively “play the bad guy” by researching emerging threats and conducting threat-hunting exercises across our infrastructure.Manage the Pipeline: Cooperate with the management of our security log ingestion tools and SIEM to ensure full visibility across Glovo.QualificationsThe Responder’s Mindset: Experience in Incident Response and Digital Forensics it’s a plus.Cloud Proficiency: Desirable operational experience with AWS; you know how to track an adversary through cloud-native logs.Coding Skills: Experience in Python (or Golang) to automate responses and build custom security tooling.Detection Engineering: A knack for threat monitoring and fine-tuning alerts to find the needle in the haystack.Proactivity: Curiosity to learn about Threat Hunting with understanding of the MITRE ATT&CK framework, among other security topics.Communication: Good written and communication skills to support post-mortem discussions and document complex incidents clearly.Nice-to-havesRelevant certifications (GCIH, GCFA, GNFA, or AWS Certified Security - Specialty).Experience with SOAR (Security Orchestration, Automation, and Response) platforms.Knowledge of data privacy regulations and security protocols related to data breaches.BenefitsTop-notch private health insurance to keep you at your peak.Monthly Glovo credit to satisfy your cravings.Discounts on transportation, food, and even kindergarten expenses.Discounted gym memberships to keep you energized.Extra time off, the freedom to work from home two days a week, and the opportunity to work from anywhere for up to three weeks a year.Enhanced parental leave, and office-based nursery.Online therapy and wellbeing benefits to ensure your mental well-being.Equal Opportunity EmployerHere at Glovo, we thrive on diversity, we believe it enhances our teams, products, and culture. We know that the best ideas come from a mashup of brilliant diverse minds. This is why we are committed to providing equal opportunities to talent from all backgrounds - all genders, racial/diverse backgrounds, abilities, ages, sexual orientations and all other unique characteristics that make you YOU. We will encourage you to bring your authentic self to work, fostering an inclusive environment where everyone feels heard.#J-*****-Ljbffr

Requirements

The Responder’s Mindset: Experience in Incident Response and Digital Forensics it’s a plus. Cloud Proficiency: Desirable operational experience with AWS; you know how to track an adversary through cloud-native logs. Coding Skills: Experience in Python (or Golang) to automate responses and build custom security tooling. Detection Engineering: A knack for threat monitoring and fine-tuning alerts to find the needle in the haystack. Proactivity: Curiosity to learn about Threat Hunting with understanding of the MITRE ATT&CK framework, among other security topics. Communication: Good written and communication skills to support post-mortem discussions and document complex incidents clearly. Nice-to-haves Relevant certifications (GCIH, GCFA, GNFA, or AWS Certified Security - Specialty). Experience with SOAR (Security Orchestration, Automation, and Response) platforms. Knowledge of data privacy regulations and security protocols related to data breaches.

Benefits & conditions

Top-notch private health insurance to keep you at your peak. Monthly Glovo credit to satisfy your cravings. Discounts on transportation, food, and even kindergarten expenses. Discounted gym memberships to keep you energized. Extra time off, the freedom to work from home two days a week, and the opportunity to work from anywhere for up to three weeks a year. Enhanced parental leave, and office-based nursery. Online therapy and wellbeing benefits to ensure your mental well-being. Equal Opportunity Employer Here at Glovo, we thrive on diversity, we believe it enhances our teams, products, and culture. We know that the best ideas come from a mashup of brilliant diverse minds. This is why we are committed to providing equal opportunities to talent from all backgrounds - all genders, racial/diverse backgrounds, abilities, ages, sexual orientations and all other unique characteristics that make you YOU. We will encourage you to bring your authentic self to work, fostering an inclusive environment where everyone feels heard. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

6:16 min

Event-driven Golang backend architecture and cloud deployment

Irina Branovic Irina Branovic · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all