> Markdown version of [/jobs/ext/3207315-digital-forensic-and-cybersecurity-incident-responder](https://www.wearedevelopers.com/jobs/ext/3207315-digital-forensic-and-cybersecurity-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Digital Forensic and Cybersecurity Incident Responder - **Company:** Boehringer Ingelheim España, S.A. - **Location:** Sant Cugat del Vallès, Spain - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Bash Shell, Cloud Computing Security, Cloud Engineering, Cyber Security, Information Systems, Computer Programming, Computer Networks, Linux, Digital Forensics, Intrusion Detection Systems, Python (Programming Language), Network Protocols, Windows PowerShell, Anti-Phishing, Red Team (Cyber Security), Runbook, Security Information and Event Management, Software Vulnerability Management, Scripting, In-Plane Switching (IPS), Large Language Models, Malware, Firewalls (Computer Science), Malware Detection - **Published:** September 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2cc45b028a859073 ## About the Role * 5+ years of experience hands-on incident response. * Hands-on experience in digital forensics, including the collection, triage, and analysis of evidence from endpoints using artifact extraction tools. * Demonstrable experience in at least two of the following areas: Malware Analysis, Cloud Security, Vulnerability Management or Operational Technology. * Programming experience in scripting languages like (Python, PowerShell or Bash). * Solid understanding of Linux and Windows architecture, common networking protocols, and packet inspection concepts. * Experience with security technologies such as firewalls, IDS/IPS, anti-malware, SIEM, and endpoint detection and response (EDR) tools. * Excellent problem-solving skills and the ability to perform effectively under pressure during high-severity incidents. * Strong written and verbal communication skills, including the ability to document findings and present recommendations. * Advanced knowledge of common attack techniques (system exploits, network attacks, web protocols, phishing, and malware). * Knowledge of how to integrate AI/LLM capabilities into Incident Response, such as automated evidence summarization, SOC/IR playbook automation, or detection-rule generation, is considered a plus. * Hands-on experience in Red Team is considered a plus. * Knowledge of cloud architecture, particularly AWS, is considered a plus. * Security certifications like CRTO, OSCP, GCIH, GCFA, GEIR… are considered a plus. ## Description This position includes escalation of ownership during major incidents and requires participation in an on-call rotation. Work hands-on with complex security incidents across endpoints, identity, network, and cloud. Partner with global teams to quickly manage threats and reduce business impact. Impact: As a Digital Forensic and Cybersecurity Incident Responder, you'll play a crucial role in protecting our organization's information systems and data, making a significant impact on our business operations. Tasks and responsibilities * Monitor and analyze the security infrastructure, playing a key role in identifying and addressing threats and incidents to maintain the integrity, confidentiality, and availability of critical data and systems. * Contribute to security incident response processes and best practices. * Be the leader of critical security incident investigations. * Carry out comprehensive security investigations by analyzing logs, network traffic… and other data sources to find root causes. * Continuously improve and monitor our security incident detection and response workflows. * Collaborate with cross-functional teams to implement and improve use cases, runbooks, and procedures to properly handle occurring security incidents. * Act as a point of escalation for analysts on the team. * Leverage your expertise to identify, evaluate, and recommend new tools and technologies that can enhance the incident response capabilities of the team. * Provide expertise on Incident Response Activities and Digital Forensics, including the capture and preservation of system logs, volatile memory captures, image captures… ## Related Videos - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) ## Related Articles - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)