Senior Incident Response & Digital Forensic
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
At Q-Tech, we are currently looking for aSenior Incident Response & Digital Forensicsspecialist to join the Technology Hub of one of our key retail clients, with offices located in Barcelona.No espere a enviar su solicitud después de leer esta descripción; se espera un gran volumen de candidaturas para esta oportunidad.This is an opportunity to join an international, highly technical environment with global impact.MISSIONLead advanced incident response activities within a mature SOC.This is a hands-on technical role focused on real investigations, continuous improvement, and end-to-end incident management.RESPONSIBILITIESCoordinate and communicate security incidents across teams and countries.Manage the full Incident Response lifecycle (detection, analysis, containment, and remediation).Reconstruct cyberattacks and perform malware analysis.Develop and enhance detection mechanisms.Conduct IT forensic investigations (timeline reconstruction and artifact analysis).Prepare technical and executive-level incident reports.Advise internal projects on security-related matters.Monitor the global threat landscape and provide actionable recommendations.REQUIREMENTS5+ years of experience in Incident Response handling medium to critical incidents.Hands-on experience in triage, containment, and end-to-end remediation.Experience collaborating with IT, Engineering, Legal, Cloud Operations, and Escalation Management teams.Degree in IT or equivalent education.High level of English (minimum B2).Advanced experience with SIEM (preferably Splunk), SOAR platforms, and EDR solutions.Strong understanding of offensive techniques and defensive technologies.FRAMEWORKS & STANDARDSTECHNOLOGY STACKSOAR / Ticketing:Fortinet FortiSOARMalware Sandbox:VMRay Sandbox, Any.Run, VirusTotalM365 Security:Microsoft Defender (Endpoint, Identity, Cloud Apps, Office)Threat Intelligence:MISP, Recorded Future, DFIR ReportDigital Forensics:Timesketch, Magnet AXIOMSIEM:Splunk (preferred) + enterprise EDRNICE TO HAVEAdvanced digital forensics (Windows, macOS, Linux, cloud).Incident Response experience in cloud environments (native logging, identity investigations).Application security and SaaS threat knowledge.WHAT THEY OFFERIf you are looking for an international, technical environment with real impact in defending a global organization, this role is for you.Flexible compensation:€2,700 annually to allocate between meal vouchers (up to €200/month) and transport (€25/month).Health insurancevalued at €** annually (€**/month).Remote work allowance:€* annually (approx. €/month), added to payroll.Wellbeing:reimbursement for sports activities (gym, swimming pool, etc.) up to €300 annually, added to payroll upon invoice submission.xcskxljWorking Hours: Afternoon shift (13:**:00h), from Monday to Friday (no rotation).#J-***-Ljbffr
Requirements
5+ years of experience in Incident Response handling medium to critical incidents. Hands-on experience in triage, containment, and end-to-end remediation. Experience collaborating with IT, Engineering, Legal, Cloud Operations, and Escalation Management teams. Degree in IT or equivalent education. High level of English (minimum B2). Advanced experience with SIEM (preferably Splunk), SOAR platforms, and EDR solutions. Strong understanding of offensive techniques and defensive technologies. FRAMEWORKS & STANDARDS TECHNOLOGY STACK SOAR / Ticketing:Fortinet FortiSOAR Malware Sandbox:VMRay Sandbox, Any.Run, VirusTotal M365 Security:Microsoft Defender (Endpoint, Identity, Cloud Apps, Office) Threat Intelligence:MISP, Recorded Future, DFIR Report Digital Forensics:Timesketch, Magnet AXIOM SIEM:Splunk (preferred) + enterprise EDR NICE TO HAVE Advanced digital forensics (Windows, macOS, Linux, cloud). Incident Response experience in cloud environments (native logging, identity investigations). Application security and SaaS threat knowledge. WHAT THEY OFFER If you are looking for an international, technical environment with real impact in defending a global organization, this role is for you.
Benefits & conditions
Flexible compensation:€2,700 annually to allocate between meal vouchers (up to €200/month) and transport (€25/month). Health insurancevalued at €** annually (€**/month). Remote work allowance:€* annually (approx. €/month), added to payroll. Wellbeing:reimbursement for sports activities (gym, swimming pool, etc.) up to €300 annually, added to payroll upon invoice submission. xcskxlj Working Hours: Afternoon shift (13:**:00h), from Monday to Friday (no rotation). #J-***-Ljbffr
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Is Software Engineering Over-Saturated?
The Biggest German Tech Companies
Find a Developer Job: 12 Best Job Sites For Developers
Dev Digest 134 - Where pixels sing?