> Markdown version of [/jobs/ext/2876149-senior-security-incident-responder](https://www.wearedevelopers.com/jobs/ext/2876149-senior-security-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Incident Responder - **Company:** Montash - **Location:** Sevilla, Spain - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Data Analysis, Build Automation, Business Software, CompTIA Security+, Cyber Security, Databases, Continuous Integration, Linux, DevOps, Python (Programming Language), Windows PowerShell, Elearning, Shell Script, Systems Architecture, Software Vulnerability Management, Scripting, DevOps Tools - Open-source, Malware, Cyber Threat Analysis, Information Technology, Web Technologies, Cyber Warfare, Golang - **Published:** September 13, 2026 - **Apply:** https://www.buscojobs.com.es/senior-security-incident-responder-en-sevilla-ID-371181660 ## About the Role A university degree (Master's preferred) in Computer Science, Cyber Security, or a related field. Solid hands-on experience in incident response, including complex environments; background in IT forensics, malware analysis, or vulnerability management is a plus. Strong technical grounding in system architecture and core security technologies, including Linux and Windows, Active Directory / Entra ID, web technologies, email, networking, cryptography, and common DevOps tooling. Software and scripting skills in Python, Golang, shell scripting, PowerShell, CI/CD, and database management. A solid grasp of the technical and organizational sides of information security, backed by prior defensive or offensive experience. Good working knowledge of core attack concepts, terminology, tools, tactics, techniques, and procedures. Strong analytical and problem-solving skills, with the ability to gather, structure, and communicate large volumes of information precisely. Excellent communication skills in English, both written and spoken, including security terminology; additional languages are a plus. Willingness to join on-call shifts. Relevant certifications (e.g. SANS/GIAC, GCIH, GNFA, GCFA, GREM, GCFE, GIME, CompTIA Security+, CISSP, CISA, or CISM) are a plus but not required. ## Description Senior Security Incident ResponderBarcelona or MadridFull-timeHybrid working modelThe Incident Response team within our organizations Cyber Defense Center is a group of dedicated incident responders working to limit the impact of security incidents across our global infrastructure.We coordinate the response to cybersecurity incidents, run investigations across the organization, and contribute to strategic security initiatives.As aSenior Security Incident Responder, youll take on a central role on this team, leading complex response efforts, bringing deep technical expertise, and helping continuously strengthen our security posture and internal capabilities.What youll doOwn and coordinate security incident response activities across a diverse, distributed environment, engaging technical and non-technical stakeholders throughout every phase of an incident.Acquire and analyze data from multiple sources during investigations and report findings clearly and actionably.Lead incident reviews, spot areas for improvement, and help implement them, including updates to guidelines, runbooks, and internal processes.Contribute ideas and build automation scripts or custom tooling to enhance the team's internal toolset.Analyze complex attack patterns and threat actors, draw out technical insights, and recommend ways to improve detection and defense capabilities.Work closely with internal teams such as Threat Intelligence, Vulnerability Management, and Business Applications, as well as external partners, to keep incident response coordinated end to end.Take part in on-call rotations supporting the team's round-the-clock availability for critical incidents.What youll bringA university degree (Master's preferred) in Computer Science, Cyber Security, or a related field.Solid hands-on experience in incident response, including complex environments; background in IT forensics, malware analysis, or vulnerability management is a plus.Strong technical grounding in system architecture and core security technologies, including Linux and Windows, Active Directory / Entra ID, web technologies, email, networking, cryptography, and common DevOps tooling.Software and scripting skills in Python, Golang, shell scripting, PowerShell, CI/CD, and database management.A solid grasp of the technical and organizational sides of information security, backed by prior defensive or offensive experience.Good working knowledge of core attack concepts, terminology, tools, tactics, techniques, and procedures.Strong analytical and problem-solving skills, with the ability to gather, structure, and communicate large volumes of information precisely.Excellent communication skills in English, both written and spoken, including security terminology; additional languages are a plus.Willingness to join on-call shifts.Relevant certifications (e.g. SANS/GIAC, GCIH, GNFA, GCFA, GREM, GCFE, GIME, CompTIA Security+, CISSP, CISA, or CISM) are a plus but not required.Whats on offerA hybrid work model balancing in-person collaboration with remote flexibility, including limited days working from abroad each year.A competitive compensation and benefits package with a bonus scheme, pension contributions, an employee share program, and various discounts (specifics vary by location).Ongoing career development through digital learning programs and international mobility opportunities, in a culture that values innovation and ownership.Flexible working arrangements and health and wellbeing support, including parental leave benefits and help returning from career breaks. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)