> Markdown version of [/jobs/ext/1960151-senior-threat-detection-incident-response-dfir-engineer](https://www.wearedevelopers.com/jobs/ext/1960151-senior-threat-detection-incident-response-dfir-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Threat Detection & Incident Response (Dfir) Engineer - **Company:** Aspenview Technology Partners, Inc. - **Location:** Zaragoza, Spain - **Contract:** Permanent contract - **Skills:** Data Analysis, Burp Suite, Digital Forensics, Intrusion Detection and Prevention, Python (Programming Language), Network Forensics, Windows PowerShell, Reverse Engineering, Runbook, Security Information and Event Management, Wireshark, Mitre Att&ck, Mttr, QRadar, Malware, Cyber Threat Analysis, IDA Pro, Cybercrime, Microsoft Sentinel, Encase, Splunk - **Published:** August 7, 2026 - **Apply:** https://www.buscojobs.com.es/senior-threat-detection-incident-response-dfir-engineer-en-zaragoza-ID-365145974 ## About the Role SIEM Tools: Advanced proficiency in Splunk (ES), Microsoft Sentinel, QRadar, or Google Chronicle. Forensics: Experience with EnCase, FTK, Volatility, or Velociraptor. Analysis: Tools like IDA Pro, Ghidra, Wireshark, and Burp Suite. Frameworks: Deep mastery of MITRE ATT&CK, Sigma, and YARA rules. Languages: Proficiency in Python or PowerShell for forensic automation and data analysis. What you bring 6-8+ years of experience in SOC Operations, Incident Response, or Threat Intelligence. Investigative Mindset: Proven ability to follow complex attack chains and reconstruct security incidents. Technical Depth: Hands?on experience with memory forensics, network traffic analysis, and host?based artifacts. Automation Drive: A passion for transforming manual investigation steps into automated detection and response flows. Certifications: GCIH, GCFA, GREM, or OSCP are highly valued. ## Description Senior Threat Detection & Incident Response (DFIR) EngineerThe Senior Threat Detection & Incident Response (DFIR) Engineer is a high-impact technical expert responsible for identifying, investigating, and neutralizing sophisticated cyber threats. This role goes beyond standard monitoring; you will actively hunt for adversaries, develop advanced detection logic, and lead forensic investigations to understand the \"how\" and \"why\" behind an intrusion.You will act as the technical authority during critical security events, ensuring that evidence is preserved, threats are contained, and lessons learned are translated into automated detection playbooks.Detection Engineering & Threat HuntingLead proactive threat hunting missions across endpoints, networks, and cloud environments using the MITRE ATT&CK framework.Develop and optimize SIEM content (Splunk, Sentinel, Chronicle, or QRadar) and Sigma rules to identify emerging adversary TTPs.Design and implement custom detection logic to reduce false positives and improve the fidelity of security alerts.Lead the Incident Response lifecycle for high-severity events: from initial containment and eradication to evidence preservation.Perform digital forensics and deep-dive investigations on compromised systems to determine the root cause and scope of breaches.Execute malware analysis and reverse engineering to identify capabilities, C2 infrastructure, and indicators of compromise (IoCs).Collect, enrich, and disseminate Threat Intelligence to proactively block emerging threats.Design and automate Incident Response playbooks to standardize response actions and reduce MTTR.Collaborate with infrastructure and engineering teams to implement defensive hardening based on intelligence findings.Tools & TechnologiesSIEM Tools: Advanced proficiency in Splunk (ES), Microsoft Sentinel, QRadar, or Google Chronicle.Forensics: Experience with EnCase, FTK, Volatility, or Velociraptor.Analysis: Tools like IDA Pro, Ghidra, Wireshark, and Burp Suite.Frameworks: Deep mastery of MITRE ATT&CK, Sigma, and YARA rules.Languages: Proficiency in Python or PowerShell for forensic automation and data analysis.What you bring6-8+ years of experience in SOC Operations, Incident Response, or Threat Intelligence.Investigative Mindset: Proven ability to follow complex attack chains and reconstruct security incidents.Technical Depth: Hands?on experience with memory forensics, network traffic analysis, and host?based artifacts.Automation Drive: A passion for transforming manual investigation steps into automated detection and response flows.Certifications: GCIH, GCFA, GREM, or OSCP are highly valued.Equal Opportunity EmployerAspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.#J-*****-Ljbffr ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)