Powering the agentic revolution in travel. Sabre is an AI-native technology leader, backed by one of the world’s largest travel data clouds. Built on an open, modular, cloud-native architecture, Sabre serves as the backbone for both established leaders and bold, new disruptors, guiding them to the next age of travel retailing through intelligent, connected, and personalized experiences. With AI at its core and operating at unparalleled scale, Sabre transforms insights into innovation, empowering airlines, hoteliers, agencies and other partners to retail, distribute and fulfill travel worldwide.
Cyber Security Engineer – Threat Detection and Incident Response
Location: Flexible / Hybrid
Department: Risk & Security – Cyber Threat Management (CTM)
Reports To: Manager, Cyber Threat Management
Sabre is seeking a self-motivated Cyber Security Engineer with 2-3 yrs’ experience, to join our Cyber Threat Management (CTM) team. This role is responsible for identifying , investigating, responding to, and helping prevent cybersecurity threats across Sabre's global technology environment.
The ideal candidate is enthusiastic about cybersecurity, has experience working in a Security Operations Center (SOC), Incident Response, Threat Hunting, or related security function, and possesses strong analytical and critical thinking skills . This individual will serve as a key contributor to Sabre's Cyber Incident Response Team (CIRT), participate in initiative-taking threat hunting activities, help improve detection capabilities, and support the ongoing evolution of Sabre's security operations program.
Threat Detection & Monitoring
Identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs), and emerging threats.
Participate in cybersecurity incident investigations throughout the incident response lifecycle, including identification, analysis, containment, eradication, recovery, and lessons learned.
Coordinate with infrastructure, cloud, application, and business teams during incident response activities.
Analyze endpoint, network, identity, cloud, and security telemetry to identify anomalous or suspicious behavior.
Detection Engineering & Operational Improvement
Vulnerability & Risk Collaboration
Collaboration & Communication
Build productive working relationships with security, infrastructure, cloud, application development, and business teams.
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent practical experience).
2–3+ years of experience in Cyber Security, Security Operations, Threat Hunting, Incident Response, Vulnerability Management, or a related security discipline.
Familiarity with SIEM technologies, endpoint security platforms, log analysis, and incident response processes.
Fundamental understanding of networking, operating systems, cloud technologies, authentication, and enterprise security concepts.
Candidates with one or more of the following will receive strong consideration:
Soft Skills & Professional Competencies
Success in this role requires both technical capability and strong people skills .
The ideal candidate will demonstrate:
This position participates in the Cyber Threat Management on-call rotation and is expected to provide support during assigned coverage periods, including after-hours investigation and response activities when necessary. Team members work closely with internal stakeholders and external security partners to ensure timely response to identified threats and security incidents.
We will give careful consideration to your application and review your details against the position criteria. You will receive separate notification as your application progresses.
Please note that only candidates who meet the minimum criteria for the role will proceed in the selection process.
#LI-Hybrid#LI-BG1