> Markdown version of [/jobs/ext/2686166-professional-services-principal-consultant-incident-response](https://www.wearedevelopers.com/jobs/ext/2686166-professional-services-principal-consultant-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Professional Services Principal Consultant - Incident Response - **Company:** CrowdStrike - **Location:** Madrid, Spain (Remote available) - **Salary:** €61,000.0 - €94,600.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Macintosh Computers, Microsoft Azure, Network Analysis, Cloud Computing, Computer Forensics, Linux, Information Systems Security Architecture Professional, Network Security, Network Forensics, Network Protocols, Reverse Engineering, Computer Network Operations, Malware, Microsoft FrontPage - **Published:** September 3, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We're always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you. **About the Role:** CrowdStrike is looking for highly motivated, self-driven, technical consultants dedicated to making a difference in global security by protecting organizations against the most advanced attackers in the world. Our CrowdStrike Services team offers opportunities to expand your skill set through a wide variety of engagements including front page incident response investigations for organizations you'll find on the annual Fortune 100 list. **Additional Locations:** This is a Remote position open to candidates in France, the UK, Ireland, Spain or Italy **What You'll Do:** + Serve as technical lead on incident response engagements + Develop and use new methods to hunt for bad actors across large sets of data. + Work under the direction of outside counsel to conduct intrusion investigations + Perform host and/or network-based forensics across Windows, Mac, and Linux platforms. + Produce high-quality written and verbal reports, presentations, recommendations, and findings to key stakeholders including customer management, regulators, and legal counsel . + Demonstrate industry thought leadership through blog posts, CrowdCasts, and other public speaking events. **What You'll Need:** + Fluency in English and French + Successful candidates will have experience in one or more of the following areas: + Successful candidates will have experience in one or more of the following areas: + Incident Response: experience conducting or managing incident response investigations for organizations, investigating targeted threats such as the Advanced Persistent Threat, Organized Crime, and Hacktivists. + Computer Forensic Analysis: a background using a variety of forensic analysis tools in incident response investigations to determine the extent and scope of compromise. + Network Forensic Analysis: strong knowledge of network protocols, network analysis tools like Bro/Zeek or Suricata, and ability to perform analysis of associated network logs. + Reverse Engineering: ability to understand the capabilities of static and dynamic malware analysis. + Incident Remediation: strong understanding of targeted attacks and able to create customized tactical and strategic remediation plans for compromised organizations. + Network Operations and Architecture/Engineering: strong understanding of secure network architecture and strong background in performing network operations. + Cloud Incident Response: knowledge in AWS, Azure, or GCP incident response methodologies. + Communications: strong ability to communicate executive and/or detailed level findings to clients; ability to effectively communicate tasks, guidance, and methodology with internal teams + Capable of completing technical tasks without supervision. + Desire to grow and expand both technical and soft skills. + Strong project management skills. + Contributing thought leader within the incident response industry. + Ability to foster a positive work environment and attitude. + Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes. **Bonus Points:** + GIAC Certified Incident Handler (GCIH) + GIAC Certified Forensic Analyst (GCFA) or GCFE + Certified Information Systems Security Professional (CISSP) + Certified Ethical Hacker (CEH) + OSCP / OSCE (Offensive Security certifications for more offensive/technical IR work) + Cloud incident response (AWS, Azure ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers)