> Markdown version of [/jobs/ext/3124429-senior-security-incident-responder](https://www.wearedevelopers.com/jobs/ext/3124429-senior-security-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Incident Responder - **Company:** Montash - **Location:** Spain - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Data Analysis, Build Automation, Business Software, CompTIA Security+, Cyber Security, Databases, Continuous Integration, Linux, Python (Programming Language), Windows PowerShell, Shell Script, Systems Architecture, Software Vulnerability Management, Scripting, DevOps Tools - Open-source, Malware, Cyber Threat Analysis, Information Technology, Web Technologies, Cyber Warfare, Golang - **Published:** September 28, 2026 - **Apply:** https://www.buscojobs.com.es/senior-security-incident-responder-en-espana-ID-372482227 ## About the Role Take part in on-call rotations supporting the team's round-the-clock availability for critical incidents.What you'll bring- A university degree (Master's preferred) in Computer Science, Cyber Security, or a related field. Solid hands-on experience in incident response, including complex environments; background in IT forensics, malware analysis, or vulnerability management is a plus. - Strong technical grounding in system architecture and core security technologies, including Linux and Windows, Active Directory / Entra ID, web technologies, email, networking, cryptography, and common DevOps tooling. - Software and scripting skills in Python, Golang, shell scripting, PowerShell, CI/CD, and database management. A solid grasp of the technical and organizational sides of information security, backed by prior defensive or offensive experience. - Good working knowledge of core attack concepts, terminology, tools, tactics, techniques, and procedures. - Strong analytical and problem-solving skills, with the ability to gather, structure, and communicate large volumes of information precisely. - Excellent communication skills in English, both written and spoken, including security terminology; additional languages are a plus. - Willingness to join on-call shifts. Relevant certifications (e.G. SANS/GIAC, GCIH, GNFA, GCFA, GREM, GCFE, GIME, CompTIA Security+, CISSP, CISA, or CISM) are a plus but not required.What's on offer- A hybrid work model balancing in-person collaboration with remote flexibility, including limited days working from abroad each year. ## Description Senior Security Incident ResponderBarcelona or MadridFull-timeHybrid working modelThe Incident Response team within our organization's Cyber Defense Center is a group of dedicated incident responders working to limit the impact of security incidents across our global infrastructure.We coordinate the response to cybersecurity incidents, run investigations across the organization, and contribute to strategic security initiatives.As a Senior Security Incident Responder, you'll take on a central role on this team, leading complex response efforts, bringing deep technical expertise, and helping continuously strengthen our security posture and internal capabilities.What you'll do- Own and coordinate security incident response activities across a diverse, distributed environment, engaging technical and non-technical stakeholders throughout every phase of an incident.- Acquire and analyze data from multiple sources during investigations and report findings clearly and actionably.- Lead incident reviews, spot areas for improvement, and help implement them, including updates to guidelines, runbooks, and internal processes.- Contribute ideas and build automation scripts or custom tooling to enhance the team's internal toolset.- Analyze complex attack patterns and threat actors, draw out technical insights, and recommend ways to improve detection and defense capabilities.- Work closely with internal teams such as Threat Intelligence, Vulnerability Management, and Business Applications, as well as external partners, to keep incident response coordinated end to end.- Take part in on-call rotations supporting the team's round-the-clock availability for critical incidents.What you'll bring- A university degree (Master's preferred) in Computer Science, Cyber Security, or a related field.Solid hands-on experience in incident response, including complex environments; background in IT forensics, malware analysis, or vulnerability management is a plus.- Strong technical grounding in system architecture and core security technologies, including Linux and Windows, Active Directory / Entra ID, web technologies, email, networking, cryptography, and common DevOps tooling.- Software and scripting skills in Python, Golang, shell scripting, PowerShell, CI/CD, and database management.A solid grasp of the technical and organizational sides of information security, backed by prior defensive or offensive experience.- Good working knowledge of core attack concepts, terminology, tools, tactics, techniques, and procedures.- Strong analytical and problem-solving skills, with the ability to gather, structure, and communicate large volumes of information precisely.- Excellent communication skills in English, both written and spoken, including security terminology; additional languages are a plus.- Willingness to join on-call shifts.Relevant certifications (e.G. SANS/GIAC, GCIH, GNFA, GCFA, GREM, GCFE, GIME, CompTIA Security+, CISSP, CISA, or CISM) are a plus but not required.What's on offer- A hybrid work model balancing in-person collaboration with remote flexibility, including limited days working from abroad each year.- A competitive compensation and benefits package with a bonus scheme, pension contributions, an employee share program, and various discounts (specifics vary by location).- Ongoing career development through digital learning programs and international mobility opportunities, in a culture that values innovation and ownership.- Flexible working arrangements and health and wellbeing support, including parental leave benefits and help returning from career breaks.#J-*****-Ljbffr ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs)