Dfir Sr Consultant

One Esecurity

Barcelona

Presencial

EUR 75.000 - 110.000

Jornada completa

Hace 13 días
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Flexible schedules
Tele‑working
Remote work with global clients
Competitive salary

Descripción de la vacante

One eSecurity busca un profesional de ciberseguridad 100% remoto con 5+ años de DFIR para liderar investigaciones de incidentes complejos y mejorar la detección. Se valorará experiencia en entornos empresariales, nube e híbridos, así como habilidades de mentoría y comunicación con ejecutivos.

El rol ofrece teletrabajo, proyectos DFIR de alto impacto y oportunidades de desarrollo en un equipo líder en seguridad ofensiva/defensiva.

Formación

  • 7+ años de experiencia en DFIR, Respuesta a Incidentes o funciones de seguridad relacionadas.
  • Experiencia práctica liderando investigaciones de ciberseguridad en entornos empresariales.
  • Conocimiento profundo de TTPs de atacantes, metodologías de intrusión y ciberamenazas modernas.
  • Capacidad de comunicar hallazgos técnicos y a ejecutivos bajo presión.

Responsabilidades

  • Dirigir investigaciones complejas de incidentes cibernéticos en entornos empresariales, nube e híbridos.
  • Proporcionar liderazgo técnico durante incidentes de alta severidad, como ransomware y APT.
  • Realizar digital forensics, threat hunting y análisis de artefactos en múltiples plataformas.
  • Desarrollar estrategias de detección y mejorar cobertura basada en MITRE ATT&CK.
  • Traducir inteligencia de amenazas en detecciones y playbooks de respuesta.

Conocimientos

DFIR
Incident Response
Threat Hunting
Team Leadership
Mentoring
Automation
Scripting

Herramientas

Velociraptor
GRR
KAPE
Volatility
EnCase
X-Ways

Descripción del empleo

Descripción del trabajo

At One eSecurity, we are a market-leading specialist in Threat Detection and Digital Forensics & Incident Response (DFIR). Our commitment to excellence, innovation, and passion drives everything we do

We’re looking for a top-tier, fully remote cybersecurity professional with 5+ years of experience in DFIR. If you have a sharp eye for advanced threats and hands‑on expertise in incident response, join us and make an impact!

Keys responsibilities:

  • Lead complex cyber incident investigations across enterprise, cloud, and hybrid environments.
  • Coordinate and provide technical leadership during high‑severity incidents, including ransomware, intrusions, insider threats, and APT activity.
  • Perform advanced digital forensics, threat hunting, malware triage, and root cause analysis across endpoints, networks, cloud, and identity platforms.
  • Develop detection strategies and improve detection coverage aligned with adversary TTPs and MITRE ATT&CK.
  • Translate threat intelligence into actionable detections, hunting hypotheses, and incident response playbooks.
  • Mentor analysts and support incident response operations across Tier 1–3 teams.
  • Lead post‑incident reviews and contribute to continuous improvement of IR processes, tooling, and operational standards.
  • Produce high‑quality technical and executive‑level reports and recommendations.
  • Drive automation and operational efficiency through scripting and security engineering improvements.

Requiered experience & qualifications:

  • 7+ years of experience in DFIR, Incident Response, Threat Hunting, SOC, or related cybersecurity functions.
  • Strong experience leading complex cyber incident investigations in enterprise environments.
  • Deep understanding of attacker TTPs, intrusion methodologies, and modern threat actor tradecraft.
  • Hands‑on investigation experience across:
  • Windows, Linux, and macOS
  • Active Directory / Entra ID
  • AWS, Azure, or GCP
  • Microsoft 365 / Google Workspace
  • Enterprise EDR/XDR platforms
  • Strong analytical, communication, and problem‑solving skills.
  • Ability to operate effectively under pressure and communicate with both technical and executive stakeholders.
  • Experience mentoring analysts and leading technical response activities.

Technical skills:

  • DFIR & Endpoint Forensics (Velociraptor, GRR, KAPE, Volatility, FTK, EnCase, X-Ways, Volatility, Axiom)
  • Deep knowledge of raw forensic artifacts and operating system internals (Windows, Linux, macOS), with the ability to manually parse and validate artifacts independently of commercial DFIR tooling (MFT, Registry, EVTX, Prefetch, Amcache, Shimcache, SRUM, USN Journal, browser artifacts, memory structures, file system metadata, and timeline reconstruction)
  • Detection Engineering & Threat Hunting
  • SIEM/XDR and EDR platforms
  • Network traffic analysis and network forensics
  • Malware triage and reverse engineering
  • Scripting and automation (Python, PowerShell, Bash)
  • Cyber Threat Intelligence and ATT&CK‑based detection methodologies

Nice to have

  • Experience in regulated or critical infrastructure environments.
  • Experience supporting global incident response operations.
  • Offensive security or adversary emulation experience.

Certifications

GCFA, GCIH, or equivalent certifications are highly valued.

Languages

  • English and Spanish(required)

What We Offer

What makes us different from other companies?

  • Exciting professional DFIR projects for the largest corporations across the globe.
  • Flexible schedules and tele‑working.
  • A top team of highly recognized professionals in the field.
  • An attractive salary.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Remote Senior DFIR Lead - Incident Response
Remote Senior DFIR Lead - Incident Response

One Esecurity • Barcelona

Presencial
EUR 75.000 - 110.000
Flexible schedules
Tele‑working
Remote work with global clients
+1
Senior DFIR Consultant – Remote Incident Response Leader
Senior DFIR Consultant – Remote Incident Response Leader

One Esecurity • Badajoz

Presencial
EUR 90.000 - 130.000
Flexible schedules
Tele-working
Attractive salary
Senior DFIR Lead & Incident Response Architect (Remote)
Senior DFIR Lead & Incident Response Architect (Remote)

One Esecurity • Nava

Presencial
EUR 90.000 - 130.000
Flexible schedules
Teleworking
Especialista en DFIR
Especialista en DFIR

Advens • Madrid

Híbrido
EUR 40.000 - 60.000
Seguro médico pagado por la empresa
Opciones de retribución flexible
Reembolso de la factura del teléfono móvil
+1
Senior Security Incident Responder - Montash
Senior Security Incident Responder - Montash

Montash • Barcelona

Híbrido
EUR 70.000 - 100.000
Digital Forensics Analyst 100% REMOTO (H/M/X)
Digital Forensics Analyst 100% REMOTO (H/M/X)

Experis Manpower Group • Madrid

A distancia
EUR 40.000 - 60.000
Modalidad 100% remota
Desarrollo profesional en ciberseguridad avanzada
Senior Cyber Incident Response Analyst
Senior Cyber Incident Response Analyst

Integrity360 • Madrid

Presencial
EUR 60.000 - 90.000
Digital Forensic and Cybersecurity Incident Responder (Sant Cugat del Vallès, Spain, Barcelona)
Digital Forensic and Cybersecurity Incident Responder (Sant Cugat del Vallès, Spain, Barcelona)

Biopharma Careers • Sant Cugat del Vallès

Presencial
EUR 90.000 - 130.000
Cyber Security Analyst
Cyber Security Analyst

Graphic Packaging International • Barcelona

Presencial
EUR 45.000 - 65.000
Consultores/as Ciberseguridad EDR /XDR (Junior y Senior) (Madrid y/o Almería)
Consultores/as Ciberseguridad EDR /XDR (Junior y Senior) (Madrid y/o Almería)

TRC • Madrid

Híbrido
EUR 42.000 - 66.000
Seguro médico
Formación certificaciones
Transporte