Senior Incident Response & Digital Forensic

Q Tech
Barcelona, Spain
14 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Tech stack

Microsoft Windows Apple Mac Systems Software as a Service Cloud Computing Cyber Security Linux Digital Forensics Microsoft Office Open Web Application Security Security Information and Event Management Data Logging Cloud Platform System
+4 more
Software Security Cyber Threat Analysis Fortinet Splunk

Job description

At Q-Tech, we are currently looking for a Senior Incident Response & Digital Forensics specialist to join the Technology Hub of one of our key retail clients, with offices located in Barcelona.Presente su candidatura después de leer los siguientes requisitos de habilidades y cualificaciones para este puesto.This is an opportunity to join an international, highly technical environment with global impact.MISSIONLead advanced incident response activities within a mature SOC.This is a hands-on technical role focused on real investigations, continuous improvement, and end-to-end incident management.RESPONSIBILITIESCoordinate and communicate security incidents across teams and countries.Manage the full Incident Response lifecycle (detection, analysis, containment, and remediation).Reconstruct cyberattacks and perform malware analysis.Develop and enhance detection mechanisms.Conduct IT forensic investigations (timeline reconstruction and artifact analysis).Prepare technical and executive-level incident reports.Advise internal projects on security-related matters.Monitor the global threat landscape and provide actionable recommendations.REQUIREMENTS5+ years of experience in Incident Response handling medium to critical incidents.Hands-on experience in triage, containment, and end-to-end remediation.Experience collaborating with IT, Engineering, Legal, Cloud Operations, and Escalation Management teams.Degree in IT or equivalent education.High level of English (minimum B2).Advanced experience with SIEM (preferably Splunk), SOAR platforms, and EDR solutions.Strong understanding of offensive techniques and defensive technologies.FRAMEWORKS & STANDARDSISO *** · NIST Cybersecurity Framework · BSI Grundschutz · ITIL · OWASP · MITRE ATT&CKTECHNOLOGY STACKSOAR / Ticketing: Fortinet FortiSOARMalware Sandbox: VMRay Sandbox, Any.Run, VirusTotalM365 Security: Microsoft Defender (Endpoint, Identity, Cloud Apps, Office)Threat Intelligence: MISP, Recorded Future, DFIR ReportDigital Forensics: Timesketch, Magnet AXIOMSIEM: Splunk (preferred) + enterprise EDRNICE TO HAVEAdvanced digital forensics (Windows, macOS, Linux, cloud).Incident Response experience in cloud environments (native logging, identity investigations).Application security and SaaS threat knowledge.WHAT THEY OFFERIf you are looking for an international, technical environment with real impact in defending a global organization, this role is for you.Flexible compensation: €2,700 annually to allocate between meal vouchers (up to €200/month) and transport (€25/month).Health insurance valued at €** annually (€/month).Remote work allowance: €* annually (approx. €/month), added to payroll.Wellbeing: reimbursement for sports activities (gym, swimming pool, etc.) up to €300 annually, added to payroll upon invoice submission.xqysrnhWorking Hours: Afternoon shift (13:**:00h), from Monday to Friday (no rotation).

Requirements

Prepare technical and executive-level incident reports.Advise internal projects on security-related matters.Monitor the global threat landscape and provide actionable recommendations.REQUIREMENTS5+ years of experience in Incident Response handling medium to critical incidents.Hands-on experience in triage, containment, and end-to-end remediation.Experience collaborating with IT, Engineering, Legal, Cloud Operations, and Escalation Management teams.Degree in IT or equivalent education.High level of English (minimum B2). Advanced experience with SIEM (preferably Splunk), SOAR platforms, and EDR solutions.Strong understanding of offensive techniques and defensive technologies.FRAMEWORKS & STANDARDSISO ***** · NIST Cybersecurity Framework · BSI Grundschutz · ITIL · OWASP · MITRE ATT&CKTECHNOLOGY STACKSOAR / Ticketing: Fortinet FortiSOARMalware Sandbox: VMRay Sandbox, Any.Run, VirusTotalM365 Security: Microsoft Defender (Endpoint, Identity, Cloud Apps, Office)Threat Intelligence: MISP, Recorded Future, DFIR ReportDigital Forensics: Timesketch, Magnet AXIOMSIEM: Splunk (preferred) + enterprise EDRNICE TO HAVEAdvanced digital forensics (Windows, macOS, Linux, cloud). Incident Response experience in cloud environments (native logging, identity investigations). Application security and SaaS threat knowledge.WHAT THEY OFFERIf you are looking for an international, technical environment with real impact in defending a global organization, this role is for you.Flexible compensation: €2,700 annually to allocate between meal vouchers (up to €200/month) and transport (€25/month).

Benefits & conditions

Remote work allowance: €** annually (approx. €**/month), added to payroll.Wellbeing: reimbursement for sports activities (gym, swimming pool, etc.) up to €300 annually, added to payroll upon invoice submission. xqysrnhWorking Hours: Afternoon shift (13:**:00h), from Monday to Friday (no rotation).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Fortinet firewall administrative passwords leaked on the dark net

Chris Heilmann +1 · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all