> Markdown version of [/jobs/ext/2018605-incident-response-analyst-expert](https://www.wearedevelopers.com/jobs/ext/2018605-incident-response-analyst-expert). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Analyst Expert - **Company:** Schwarz Digits - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, Software as a Service, Cloud Computing, Cyber Security, Linux, Digital Forensics, Open Web Application Security, Security Information and Event Management, Data Logging, Cloud Platform System, Software Security, Mitre Att&ck, Information Technology, Cyber Warfare, Splunk - **Published:** August 11, 2026 - **Apply:** https://es.trabajo.org/oferta-5001-0010a9b0b26fac8323e707fb0b9a3f7d ## About the Role You will join a large Cyber Security organization with excellent opportunities for growth, development, and promotion based on performance and training. Continuous learning is essential in this field, and the company supports this with a wide range of education and training options to enhance both soft and hard skills. - 5+ years of professional experience in Incident Response, leading medium to critical security incident response. - Hands-on experience in incident response, including triage, containment, remediation, and end-to-end security investigations. - Experience partnering with Escalation Management, Product Development/Engineering, IT, Legal, Cloud Ops, and wider cybersecurity teams to lead remediation. - University degree in Information Technology or comparable education. - Strong English skills, fluent business English (speaking and writing) at advanced level (B2+). - Further education in IT forensics and security incident management. - Expert knowledge in SIEM systems (preferably Splunk), SOAR tools, and EDR solutions. - Strong technical expertise in deployed technologies and cyber attack techniques. - Knowledge of national and international IT standards and frameworks (ISO 27001, NIST Cyber Security Framework, BSI Grundschutz, ITIL, OWASP, MITRE ATT&CK). - High communicative and analytical skills, ability to work independently, and strong team spirit. - Confidence and persuasiveness with communication skills in English. German will be well considered but it is not mandatory. - Commitment to continuous education and professional development. - Would be a plus: Strong digital forensics skills, including analysis, timeline reconstruction, and interpreting artefacts across Windows, macOS, Linux, and cloud environments. - Would be a plus: Experience in cloud incident response including familiarity with cloud-native logging, identity systems, and investigation techniques. - Would be a plus: Knowledge of application security, including investigating application-layer attacks, abuse cases, and SaaS-specific threats. - Working Hours: Morning shift (05:45 - 14:00h), from Monday to Friday (no rotation). ## Description Your tasks - Coordinate and communicate IT security incidents across teams and countries, managing the incident response process. - Detect and analyze potential security incidents, ensuring effective containment. - Reconstruct cyber-attacks and malware, analyze sensitive data, and derive remediation actions. - Develop mechanisms to detect anomalies and attacks, initiating preventive measures to alert in time. - Monitor the general threat landscape on the Internet and provide actionable recommendations. - Advise internal projects on security-related issues. - Conduct IT forensic investigations. - Create meaningful reports on IT security incidents. Your Profile - Our Cyber Defense Center is fully built and up and running. We are now looking to strengthen the team with an Incident Response expert to cover the weekday afternoon shift. This is a hands-on, experienced technical role focused on advanced incident, and continuous improvement rather than tier-one alert triage. - ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)