> Markdown version of [/jobs/ext/1997902-senior-incident-response-digital-forensic](https://www.wearedevelopers.com/jobs/ext/1997902-senior-incident-response-digital-forensic). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Incident Response & Digital Forensic - **Company:** Q Tech - **Location:** Barcelona, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, Software as a Service, Cloud Computing, Linux, Digital Forensics, Microsoft Office, Security Information and Event Management, Data Logging, Cloud Platform System, Malware, Fortinet, Splunk - **Published:** August 9, 2026 - **Apply:** https://www.buscojobs.com.es/senior-incident-response-digital-forensic-en-barcelona-ID-366265116 ## About the Role li /ul h3REQUIREMENTS /h3 ul li5+ years of experience in Incident Response handling medium to critical incidents. /li liHands-on experience in triage, containment, and end-to-end remediation. /li liExperience collaborating with IT, Engineering, Legal, Cloud Operations, and Escalation Management teams. /li liDegree in IT or equivalent education. /li liHigh level of English (minimum B2). /li liAdvanced experience with SIEM (preferably Splunk), SOAR platforms, and EDR solutions. /li liStrong understanding of offensive techniques and defensive technologies. /li /ul h3FRAMEWORKS STANDARDS /h3 h3TECHNOLOGY STACK /h3 ul libSOAR / Ticketing: /b Fortinet FortiSOAR /li libMalware Sandbox: /b VMRay Sandbox, Any.Run, VirusTotal /li libM365 Security: /b Microsoft Defender (Endpoint, Identity, Cloud Apps, Office) /li libThreat Intelligence: /b MISP, Recorded Future, DFIR Report /li libDigital Forensics: /b Timesketch, Magnet AXIOM /li libSIEM: /b Splunk (preferred) + enterprise EDR /li /ul h3NICE TO HAVE /h3 ul liAdvanced digital forensics (Windows, macOS, Linux, cloud). /li liIncident Response experience in cloud environments (native logging, identity investigations). /li liApplication security and SaaS threat knowledge. /li /ul h3WHAT THEY OFFER /h3 pIf you are looking for an international, technical environment with real impact in defending a global organization, this role is for you. ## Description ppAt Q-Tech, we are currently looking for a bSenior Incident Response Digital Forensics /b specialist to join the Technology Hub of one of our key retail clients, with offices located in Barcelona./p pThis is an opportunity to join an international, highly technical environment with global impact./p h3MISSION /h3 pLead advanced incident response activities within a mature SOC.This is a hands-on technical role focused on real investigations, continuous improvement, and end-to-end incident management./p h3RESPONSIBILITIES /h3 ul liCoordinate and communicate security incidents across teams and countries./li liManage the full Incident Response lifecycle (detection, analysis, containment, and remediation)./li liReconstruct cyberattacks and perform malware analysis./li liDevelop and enhance detection mechanisms./li liConduct IT forensic investigations (timeline reconstruction and artifact analysis)./li liPrepare technical and executive-level incident reports./li liAdvise internal projects on security-related matters./li liMonitor the global threat landscape and provide actionable recommendations./li /ul h3REQUIREMENTS /h3 ul li5+ years of experience in Incident Response handling medium to critical incidents./li liHands-on experience in triage, containment, and end-to-end remediation./li liExperience collaborating with IT, Engineering, Legal, Cloud Operations, and Escalation Management teams./li liDegree in IT or equivalent education./li liHigh level of English (minimum B2)./li liAdvanced experience with SIEM (preferably Splunk), SOAR platforms, and EDR solutions./li liStrong understanding of offensive techniques and defensive technologies./li /ul h3FRAMEWORKS STANDARDS /h3 h3TECHNOLOGY STACK /h3 ul libSOAR / Ticketing: /b Fortinet FortiSOAR /li libMalware Sandbox: /b VMRay Sandbox, Any.Run, VirusTotal /li libM365 Security: /b Microsoft Defender (Endpoint, Identity, Cloud Apps, Office) /li libThreat Intelligence: /b MISP, Recorded Future, DFIR Report /li libDigital Forensics: /b Timesketch, Magnet AXIOM /li libSIEM: /b Splunk (preferred) + enterprise EDR /li /ul h3NICE TO HAVE /h3 ul liAdvanced digital forensics (Windows, macOS, Linux, cloud)./li liIncident Response experience in cloud environments (native logging, identity investigations)./li liApplication security and SaaS threat knowledge./li /ul h3WHAT THEY OFFER /h3 pIf you are looking for an international, technical environment with real impact in defending a global organization, this role is for you./p ul libFlexible compensation: /b €2,700 annually to allocate between meal vouchers (up to €200/month) and transport (€25/month)./li libHealth insurance /b valued at €****** annually (€*****/month)./li libRemote work allowance: /b €****** annually (approx. €*****/month), added to payroll./li libWellbeing: /b reimbursement for sports activities (gym, swimming pool, etc.) up to €300 annually, added to payroll upon invoice submission./li libWorking Hours: Afternoon shift (13:*******:00h), from Monday to Friday (no rotation)./b /li /ul /p #J-*****-Ljbffr ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Handling incidents collaboratively is like solving a rubix cube](https://www.wearedevelopers.com/videos/680-handling-incidents-collaboratively-is-like-solving-a-rubix-cube) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [The Best Job Search Websites of 2025](https://www.wearedevelopers.com/magazine/368-the-best-job-search-websites-of-2025) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [How Many Jobs Are Available in Technology?](https://www.wearedevelopers.com/magazine/450-how-many-jobs-are-available-in-technology)