Senior Incident Response & Digital Forensic

Q Tech
Barcelona, Spain
5 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Tech stack

Microsoft Windows Apple Mac Systems Software as a Service Cloud Computing Linux Digital Forensics Microsoft Office Security Information and Event Management Data Logging Cloud Platform System Malware Fortinet
+1 more
Splunk

Job description

ppAt Q-Tech, we are currently looking for a bSenior Incident Response Digital Forensics /b specialist to join the Technology Hub of one of our key retail clients, with offices located in Barcelona./p pThis is an opportunity to join an international, highly technical environment with global impact./p h3MISSION /h3 pLead advanced incident response activities within a mature SOC.This is a hands-on technical role focused on real investigations, continuous improvement, and end-to-end incident management./p h3RESPONSIBILITIES /h3 ul liCoordinate and communicate security incidents across teams and countries./li liManage the full Incident Response lifecycle (detection, analysis, containment, and remediation)./li liReconstruct cyberattacks and perform malware analysis./li liDevelop and enhance detection mechanisms./li liConduct IT forensic investigations (timeline reconstruction and artifact analysis)./li liPrepare technical and executive-level incident reports./li liAdvise internal projects on security-related matters./li liMonitor the global threat landscape and provide actionable recommendations./li /ul h3REQUIREMENTS /h3 ul li5+ years of experience in Incident Response handling medium to critical incidents./li liHands-on experience in triage, containment, and end-to-end remediation./li liExperience collaborating with IT, Engineering, Legal, Cloud Operations, and Escalation Management teams./li liDegree in IT or equivalent education./li liHigh level of English (minimum B2)./li liAdvanced experience with SIEM (preferably Splunk), SOAR platforms, and EDR solutions./li liStrong understanding of offensive techniques and defensive technologies./li /ul h3FRAMEWORKS STANDARDS /h3 h3TECHNOLOGY STACK /h3 ul libSOAR / Ticketing: /b Fortinet FortiSOAR /li libMalware Sandbox: /b VMRay Sandbox, Any.Run, VirusTotal /li libM365 Security: /b Microsoft Defender (Endpoint, Identity, Cloud Apps, Office) /li libThreat Intelligence: /b MISP, Recorded Future, DFIR Report /li libDigital Forensics: /b Timesketch, Magnet AXIOM /li libSIEM: /b Splunk (preferred) + enterprise EDR /li /ul h3NICE TO HAVE /h3 ul liAdvanced digital forensics (Windows, macOS, Linux, cloud)./li liIncident Response experience in cloud environments (native logging, identity investigations)./li liApplication security and SaaS threat knowledge./li /ul h3WHAT THEY OFFER /h3 pIf you are looking for an international, technical environment with real impact in defending a global organization, this role is for you./p ul libFlexible compensation: /b €2,700 annually to allocate between meal vouchers (up to €200/month) and transport (€25/month)./li libHealth insurance /b valued at €** annually (€**/month)./li libRemote work allowance: /b €* annually (approx. €/month), added to payroll./li libWellbeing: /b reimbursement for sports activities (gym, swimming pool, etc.) up to €300 annually, added to payroll upon invoice submission./li libWorking Hours: Afternoon shift (13:**:00h), from Monday to Friday (no rotation)./b /li /ul /p #J-***-Ljbffr

Requirements

li /ul h3REQUIREMENTS /h3 ul li5+ years of experience in Incident Response handling medium to critical incidents. /li liHands-on experience in triage, containment, and end-to-end remediation. /li liExperience collaborating with IT, Engineering, Legal, Cloud Operations, and Escalation Management teams. /li liDegree in IT or equivalent education. /li liHigh level of English (minimum B2). /li liAdvanced experience with SIEM (preferably Splunk), SOAR platforms, and EDR solutions. /li liStrong understanding of offensive techniques and defensive technologies. /li /ul h3FRAMEWORKS STANDARDS /h3 h3TECHNOLOGY STACK /h3 ul libSOAR / Ticketing: /b Fortinet FortiSOAR /li libMalware Sandbox: /b VMRay Sandbox, Any.Run, VirusTotal /li libM365 Security: /b Microsoft Defender (Endpoint, Identity, Cloud Apps, Office) /li libThreat Intelligence: /b MISP, Recorded Future, DFIR Report /li libDigital Forensics: /b Timesketch, Magnet AXIOM /li libSIEM: /b Splunk (preferred) + enterprise EDR /li /ul h3NICE TO HAVE /h3 ul liAdvanced digital forensics (Windows, macOS, Linux, cloud). /li liIncident Response experience in cloud environments (native logging, identity investigations). /li liApplication security and SaaS threat knowledge. /li /ul h3WHAT THEY OFFER /h3 pIf you are looking for an international, technical environment with real impact in defending a global organization, this role is for you.

Benefits & conditions

p ul libFlexible compensation: /b €2,700 annually to allocate between meal vouchers (up to €200/month) and transport (€25/month). /li libHealth insurance /b valued at €** annually (€**/month). /li libRemote work allowance: /b €* annually (approx. €/month), added to payroll. /li libWellbeing: /b reimbursement for sports activities (gym, swimming pool, etc.) up to €300 annually, added to payroll upon invoice submission. /li libWorking Hours: Afternoon shift (13:**:00h), from Monday to Friday (no rotation). /b /li /ul /p #J-***-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all