> Markdown version of [/jobs/ext/2943574-digital-forensic-and-cybersecurity-incident-responder](https://www.wearedevelopers.com/jobs/ext/2943574-digital-forensic-and-cybersecurity-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Digital Forensic And Cybersecurity Incident Responder - **Company:** Boehringer Ingelheim - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Bash Shell, Cloud Computing Security, Cloud Engineering, Cyber Security, Computer Programming, Computer Networks, Linux, Digital Forensics, Intrusion Detection Systems, Python (Programming Language), Network Protocols, Windows PowerShell, Phishing, Red Team (Cyber Security), Runbook, Security Information and Event Management, Software Vulnerability Management, Scripting, Large Language Models, Malware, Firewalls (Computer Science) - **Published:** September 16, 2026 - **Apply:** https://www.buscojobs.com.es/digital-forensic-and-cybersecurity-incident-responder-en-madrid-ID-370572675 ## About the Role 5+ years of experience hands?on incident response Hands?on experience in digital forensics, including the collection, triage, and analysis of evidence from endpoints using artifact extraction tools Demonstrable experience in at least two of the following areas: Malware Analysis, Cloud Security, Vulnerability Management or Operational Technology Programming experience in scripting languages like (Python, PowerShell or Bash) Solid understanding of Linux and Windows architecture, common networking protocols, and packet inspection concepts Experience with security technologies such as firewalls, IDS/IPS, anti?malware, SIEM, and endpoint detection and response (EDR) tools Excellent problem?solving skills and the ability to perform effectively under pressure during high?severity incidents Strong written and verbal communication skills, including the ability to document findings and present recommendations Advanced knowledge of common attack techniques (system exploits, network attacks, web protocols, phishing, and malware) Knowledge of how to integrate AI/LLM capabilities into Incident Response, such as automated evidence summarization, SOC/IR playbook automation, or detection?rule generation, is considered a plus Hands?on experience in Red Team is considered a plus Knowledge of cloud architecture, particularly AWS, is considered a plus Security certifications like CRTO, OSCP, GCIH, GCFA, GEIR... are considered a plus ## Description Tasks And ResponsibilitiesMonitor and analyze the security infrastructure, playing a key role in identifying and addressing threats and incidents to maintain the integrity, confidentiality, and availability of critical data and systemsContribute to security incident response processes and best practicesBe the leader of critical security incident investigationsCarry out comprehensive security investigations by analyzing logs, network traffic... and other data sources to find root causesContinuously improve and monitor our security incident detection and response workflowsCollaborate with cross-functional teams to implement and improve use cases, runbooks, and procedures to properly handle occurring security incidentsAct as a point of escalation for analysts on the teamLeverage your expertise to identify, evaluate, and recommend new tools and technologies that can enhance the incident response capabilities of the teamProvide expertise on Incident Response Activities and Digital Forensics, including the capture and preservation of system logs, volatile memory captures, image captures...Requirements5+ years of experience hands?on incident responseHands?on experience in digital forensics, including the collection, triage, and analysis of evidence from endpoints using artifact extraction toolsDemonstrable experience in at least two of the following areas: Malware Analysis, Cloud Security, Vulnerability Management or Operational TechnologyProgramming experience in scripting languages like (Python, PowerShell or Bash)Solid understanding of Linux and Windows architecture, common networking protocols, and packet inspection conceptsExperience with security technologies such as firewalls, IDS/IPS, anti?malware, SIEM, and endpoint detection and response (EDR) toolsExcellent problem?solving skills and the ability to perform effectively under pressure during high?severity incidentsStrong written and verbal communication skills, including the ability to document findings and present recommendationsAdvanced knowledge of common attack techniques (system exploits, network attacks, web protocols, phishing, and malware)Knowledge of how to integrate AI/LLM capabilities into Incident Response, such as automated evidence summarization, SOC/IR playbook automation, or detection?rule generation, is considered a plusHands?on experience in Red Team is considered a plusKnowledge of cloud architecture, particularly AWS, is considered a plusSecurity certifications like CRTO, OSCP, GCIH, GCFA, GEIR... are considered a plusPlease note: The job title used in this advertisement may differ from the official contractual title.#IamBoehringerIngelheim because...We are continuously working to design the best experience for you.Here are some examples of how we will take care of you:Flexible working conditionsLife and accident insuranceHealth insurance at a competitive priceInvestment in your learning and developmentGym membership discountsOur Company Why Boehringer Ingelheim?With us, you can develop your own path in a company with a culture that knows our differences are our strengths - and break new ground in the drive to make millions of lives better.Here, your development is our priority.Supporting you to build a career as part of a workplace that is independent, authentic and bold, while tackling challenging work in a respectful and friendly environment where everyone is valued and welcomed.Alongside, you have access to programs and groups that ensure your health and wellbeing are looked after - as we make major investments to drive global accessibility to healthcare.By being part of a team that is constantly innovating, you'll be helping to transform lives for generations.Want to learn more?Visit #J-*****-Ljbffr ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)