> Markdown version of [/jobs/ext/2126589-senior-incident-response-digital-forensic](https://www.wearedevelopers.com/jobs/ext/2126589-senior-incident-response-digital-forensic). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Incident Response & Digital Forensic - **Company:** Q Tech - **Location:** Barcelona, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, Software as a Service, Cloud Computing, Cyber Security, Linux, Digital Forensics, Microsoft Office, Open Web Application Security, Security Information and Event Management, Data Logging, Cloud Platform System, Software Security, Cyber Threat Analysis, Fortinet, Splunk - **Published:** August 19, 2026 - **Apply:** https://www.buscojobs.com.es/senior-incident-response-digital-forensic-en-badalona-ID-367801935 ## About the Role Prepare technical and executive-level incident reports.Advise internal projects on security-related matters.Monitor the global threat landscape and provide actionable recommendations.REQUIREMENTS5+ years of experience in Incident Response handling medium to critical incidents.Hands-on experience in triage, containment, and end-to-end remediation.Experience collaborating with IT, Engineering, Legal, Cloud Operations, and Escalation Management teams.Degree in IT or equivalent education.High level of English (minimum B2). Advanced experience with SIEM (preferably Splunk), SOAR platforms, and EDR solutions.Strong understanding of offensive techniques and defensive technologies.FRAMEWORKS & STANDARDSISO ***** · NIST Cybersecurity Framework · BSI Grundschutz · ITIL · OWASP · MITRE ATT&CKTECHNOLOGY STACKSOAR / Ticketing: Fortinet FortiSOARMalware Sandbox: VMRay Sandbox, Any.Run, VirusTotalM365 Security: Microsoft Defender (Endpoint, Identity, Cloud Apps, Office)Threat Intelligence: MISP, Recorded Future, DFIR ReportDigital Forensics: Timesketch, Magnet AXIOMSIEM: Splunk (preferred) + enterprise EDRNICE TO HAVEAdvanced digital forensics (Windows, macOS, Linux, cloud). Incident Response experience in cloud environments (native logging, identity investigations). Application security and SaaS threat knowledge.WHAT THEY OFFERIf you are looking for an international, technical environment with real impact in defending a global organization, this role is for you.Flexible compensation: €2,700 annually to allocate between meal vouchers (up to €200/month) and transport (€25/month). ## Description At Q-Tech, we are currently looking for a Senior Incident Response & Digital Forensics specialist to join the Technology Hub of one of our key retail clients, with offices located in Barcelona.Presente su candidatura después de leer los siguientes requisitos de habilidades y cualificaciones para este puesto.This is an opportunity to join an international, highly technical environment with global impact.MISSIONLead advanced incident response activities within a mature SOC.This is a hands-on technical role focused on real investigations, continuous improvement, and end-to-end incident management.RESPONSIBILITIESCoordinate and communicate security incidents across teams and countries.Manage the full Incident Response lifecycle (detection, analysis, containment, and remediation).Reconstruct cyberattacks and perform malware analysis.Develop and enhance detection mechanisms.Conduct IT forensic investigations (timeline reconstruction and artifact analysis).Prepare technical and executive-level incident reports.Advise internal projects on security-related matters.Monitor the global threat landscape and provide actionable recommendations.REQUIREMENTS5+ years of experience in Incident Response handling medium to critical incidents.Hands-on experience in triage, containment, and end-to-end remediation.Experience collaborating with IT, Engineering, Legal, Cloud Operations, and Escalation Management teams.Degree in IT or equivalent education.High level of English (minimum B2).Advanced experience with SIEM (preferably Splunk), SOAR platforms, and EDR solutions.Strong understanding of offensive techniques and defensive technologies.FRAMEWORKS & STANDARDSISO ***** · NIST Cybersecurity Framework · BSI Grundschutz · ITIL · OWASP · MITRE ATT&CKTECHNOLOGY STACKSOAR / Ticketing: Fortinet FortiSOARMalware Sandbox: VMRay Sandbox, Any.Run, VirusTotalM365 Security: Microsoft Defender (Endpoint, Identity, Cloud Apps, Office)Threat Intelligence: MISP, Recorded Future, DFIR ReportDigital Forensics: Timesketch, Magnet AXIOMSIEM: Splunk (preferred) + enterprise EDRNICE TO HAVEAdvanced digital forensics (Windows, macOS, Linux, cloud).Incident Response experience in cloud environments (native logging, identity investigations).Application security and SaaS threat knowledge.WHAT THEY OFFERIf you are looking for an international, technical environment with real impact in defending a global organization, this role is for you.Flexible compensation: €2,700 annually to allocate between meal vouchers (up to €200/month) and transport (€25/month).Health insurance valued at €****** annually (€*****/month).Remote work allowance: €****** annually (approx. €*****/month), added to payroll.Wellbeing: reimbursement for sports activities (gym, swimming pool, etc.) up to €300 annually, added to payroll upon invoice submission.xqysrnhWorking Hours: Afternoon shift (13:*******:00h), from Monday to Friday (no rotation). ## Related Videos - [WeAreDevelopers LIVE - Back to CODE100](https://www.wearedevelopers.com/videos/1909-wearedevelopers-live-back-to-code100) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies)