> Markdown version of [/jobs/ext/3137357-digital-forensic-and-cybersecurity-incident-responder](https://www.wearedevelopers.com/jobs/ext/3137357-digital-forensic-and-cybersecurity-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Digital Forensic And Cybersecurity Incident Responder - **Company:** Boehringer Ingelheim - **Location:** ReocĂ­n, Spain - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Bash Shell, Cloud Computing Security, Cyber Security, Information Systems, Computer Networks, Linux, Digital Forensics, Intrusion Detection Systems, Python (Programming Language), Log Analysis, Packet Analyzer, Windows PowerShell, Anti-Phishing, Red Team (Cyber Security), Security Information and Event Management, Systems Integration, Software Vulnerability Management, Scripting, In-Plane Switching (IPS), Large Language Models, Malware, Firewalls (Computer Science), Malware Detection - **Published:** September 29, 2026 - **Apply:** https://www.buscojobs.com.es/digital-forensic-and-cybersecurity-incident-responder-en-reocin-ID-373337106 ## About the Role This role offers meaningful impact by protecting information systems and data at scale, with a strong emphasis on collaboration and rapid problem-solving. Compensaciones / Beneficios Flexible working conditions Life and accident insurance Health insurance at a competitive price Investment in your learning and development Gym membership discounts Responsabilidades Monitor and analyze security infrastructure to identify threats and incidents Lead critical security incident investigations Escalate ownership during major incidents and participate in on-call rotations Analyze logs, network traffic, and data sources to determine root causes Improve incident detection and response workflows and playbooks Collaborate cross-functionally to implement and refine use cases and procedures Serve as escalation point for analysts on the team Evaluate and recommend new tools to boost IR capabilities Preserve evidence and perform digital forensics operations on endpoints (logs, memory, images) Requisitos principales 5+ years hands-on incident response experience Hands-on digital forensics experience with evidence collection and analysis from endpoints Experience in at least two: Malware Analysis, Cloud Security, Vulnerability Management, or Operational Technology Scripting experience (Python, PowerShell, or Bash) Solid understanding of Linux and Windows architectures, networking, and packet analysis Experience with firewalls, IDS/IPS, anti-malware, SIEM, and EDR tools Strong problem-solving skills and ability to work under high-severity pressure Excellent written and verbal communication for documenting findings and presenting recommendations Advanced knowledge of common attack techniques (exploits, network attacks, phishing, malware) Knowledge of integrating AI/LLM capabilities into IR (plus) Red Team experience (plus) AWS knowledge (plus) Security certifications (CRTO, OSCP, GCIH, GCFA, GEIR) (plus) Strong communication (written and verbal) Composure under pressure Collaboration and teamwork Incident response Digital forensics Malware analysis ## Description Overview As a Cybersecurity Incident Responder, you lead and support incident response and digital forensics across endpoints, identities, networks, and cloud.You work with SOC, infrastructure, and application teams to minimize business impact and drive improvements in detection and response.You will manage major incidents, participate in on-call rotations, and help shape repeatable playbooks and use cases.This role offers meaningful impact by protecting information systems and data at scale, with a strong emphasis on collaboration and rapid problem-solving.Compensaciones / Beneficios Flexible working conditions Life and accident insurance Health insurance at a competitive price Investment in your learning and development Gym membership discounts Responsabilidades Monitor and analyze security infrastructure to identify threats and incidents Lead critical security incident investigations Escalate ownership during major incidents and participate in on-call rotations Analyze logs, network traffic, and data sources to determine root causes Improve incident detection and response workflows and playbooks Collaborate cross-functionally to implement and refine use cases and procedures Serve as escalation point for analysts on the team Evaluate and recommend new tools to boost IR capabilities Preserve evidence and perform digital forensics operations on endpoints (logs, memory, images) Requisitos principales 5+ years hands-on incident response experience Hands-on digital forensics experience with evidence collection and analysis from endpoints Experience in at least two: Malware Analysis, Cloud Security, Vulnerability Management, or Operational Technology Scripting experience (Python, PowerShell, or Bash) Solid understanding of Linux and Windows architectures, networking, and packet analysis Experience with firewalls, IDS/IPS, anti-malware, SIEM, and EDR tools Strong problem-solving skills and ability to work under high-severity pressure Excellent written and verbal communication for documenting findings and presenting recommendations Advanced knowledge of common attack techniques (exploits, network attacks, phishing, malware) Knowledge of integrating AI/LLM capabilities into IR (plus) Red Team experience (plus) AWS knowledge (plus) Security certifications (CRTO, OSCP, GCIH, GCFA, GEIR) (plus) Strong communication (written and verbal) Composure under pressure Collaboration and teamwork Incident response Digital forensics Malware analysis ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)