Dfir Sr Consultant

One Esecurity

Huelva

Presencial

EUR 70.000 - 110.000

Jornada completa

Hace 10 días
Generador de candidaturas

Destaca para este puesto: genera un currículum y una carta de presentación adaptados en cuestión de un minuto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Flexible schedules
Tele-working

Descripción de la vacante

One eSecurity, líder en detección de amenazas y DFIR, busca un profesional de ciberseguridad remoto con 5+ años de experiencia en DFIR. Si tienes ojo para amenazas avanzadas y experiencia práctica en respuesta a incidentes, únete y genera impacto.

Trabajarás en investigaciones complejas, detección, informes y mejoras continuas, con oportunidades para liderar y mentorizar equipos en un entorno global y remoto.

Formación

  • 7+ años de experiencia en DFIR, IR, Threat Hunting, SOC o funciones relacionadas.
  • Experiencia liderando investigaciones de incidentes complejos en entornos empresariales.
  • Conocimiento profundo de TTPs, metodologías de intrusión y tradecraft de amenazas.
  • Experiencia práctica en Windows, Linux y macOS, AD/Entra ID y nubes (AWS/Azure/GCP).
  • Conocimiento de plataformas EDR/XDR, análisis de red y forense de malware.

Responsabilidades

  • Dirigir investigaciones de incidentes cibernéticos complejos en entornos empresariales, nube e híbridos.
  • Coordinar y liderar técnicamente durante incidentes de alta severidad (ransomware, intrusiones, amenazas internas).
  • Realizar forense digital, threat hunting, triage de malware y análisis de causa raíz.
  • Desarrollar estrategias de detección y cobertura alineadas con MITRE ATT&CK.
  • Traducir inteligencia de amenazas en detecciones y playbooks de IR.
  • Mentorizar analistas y apoyar operaciones de IR (Tier 1–3).
  • Conducir revisiones post-incidentes y mejorar procesos, herramientas y estándares.
  • Elaborar informes técnicos y ejecutivos de alta calidad y recomendaciones.
  • Impulsar automatización y mejoras en ingeniería de seguridad mediante scripting.

Conocimientos

DFIR
Incident Response
Threat Hunting
SOC
Windows
Linux
macOS
Active Directory
Entra ID
AWS
Azure
GCP
Microsoft 365
EDR/XDR
Automation
Python
PowerShell
Bash
ATT&CK
Threat Intelligence

Educación

GCFA / GCIH

Herramientas

Velociraptor
GRR
KAPE
Volatility
FTK
EnCase
X-Ways
Axiom

Descripción del empleo

Descripción del trabajo

At One eSecurity, we are a market-leading specialist in Threat Detection and Digital Forensics & Incident Response (DFIR). Our commitment to excellence, innovation, and passion drives everything we do

We're looking for a top-tier, fully remote cybersecurity professional with 5+ years of experience in DFIR. If you have a sharp eye for advanced threats and hands‑on expertise in incident response, join us and make an impact!

Keys responsibilities:

  • Lead complex cyber incident investigations across enterprise, cloud, and hybrid environments.
  • Coordinate and provide technical leadership during high‑severity incidents, including ransomware, intrusions, insider threats, and APT activity.
  • Perform advanced digital forensics, threat hunting, malware triage, and root cause analysis across endpoints, networks, cloud, and identity platforms.
  • Develop detection strategies and improve detection coverage aligned with adversary TTPs and MITRE ATT&CK.
  • Translate threat intelligence into actionable detections, hunting hypotheses, and incident response playbooks.
  • Mentor analysts and support incident response operations across Tier 1–3 teams.
  • Lead post‑incident reviews and contribute to continuous improvement of IR processes, tooling, and operational standards.
  • Produce high‑quality technical and executive‑level reports and recommendations.
  • Drive automation and operational efficiency through scripting and security engineering improvements.

Requiered experience & qualifications:

  • 7+ years of experience in DFIR, Incident Response, Threat Hunting, SOC, or related cybersecurity functions.
  • Strong experience leading complex cyber incident investigations in enterprise environments.
  • Deep understanding of attacker TTPs, intrusion methodologies, and modern threat actor tradecraft.
  • Hands‑on investigation experience across:
  • Windows, Linux, and macOS
  • Active Directory / Entra ID
  • AWS, Azure, or GCP
  • Microsoft 365 / Google Workspace
  • Enterprise EDR/XDR platforms
  • Strong analytical, communication, and problem‑solving skills.
  • Ability to operate effectively under pressure and communicate with both technical and executive stakeholders.
  • Experience mentoring analysts and leading technical response activities.

Technical skills:

  • DFIR & Endpoint Forensics (Velociraptor, GRR, KAPE, Volatility, FTK, EnCase, X-Ways, Volatility, Axiom)
  • Deep knowledge of raw forensic artifacts and operating system internals (Windows, Linux, macOS), with the ability to manually parse and validate artifacts independently of commercial DFIR tooling (MFT, Registry, EVTX, Prefetch, Amcache, Shimcache, SRUM, USN Journal, browser artifacts, memory structures, file system metadata, and timeline reconstruction)
  • Detection Engineering & Threat Hunting
  • SIEM/XDR and EDR platforms
  • Network traffic analysis and network forensics
  • Malware triage and reverse engineering
  • Scripting and automation (Python, PowerShell, Bash)
  • Cyber Threat Intelligence and ATT&CK-based detection methodologies

Nice to have

  • Experience in regulated or critical infrastructure environments.
  • Experience supporting global incident response operations.
  • Offensive security or adversary emulation experience.

Certifications

GCFA, GCIH, or equivalent certifications are highly valued.

Languages

  • English and Spanish(required)

What We Offer

What makes us different from other companies?

  • Exciting professional DFIR projects for the largest corporations across the globe.
  • Flexible schedules and tele-working.
  • A top team of highly recognized professionals in the field.
  • An attractive salary.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Dfir Sr Consultant
Dfir Sr Consultant

One Esecurity • Barcelona

Presencial
EUR 75.000 - 110.000
Flexible schedules
Tele‑working
Remote work with global clients
+1
Dfir Sr Consultant
Dfir Sr Consultant

One Esecurity • Albacete

Presencial
EUR 90.000 - 120.000
Flexible schedules
Tele-working
Top professionals
Dfir Sr Consultant
Dfir Sr Consultant

One Esecurity • Meis

Presencial
EUR 70.000 - 90.000
Teletrabajo
Salario atractivo
Dfir Sr Consultant
Dfir Sr Consultant

One Esecurity • País Vasco

Presencial
EUR 70.000 - 110.000
Flexible schedules
Tele-working
Equipe de alto nivel
Senior DFIR Consultant - Remote Incident Response Leader
Senior DFIR Consultant - Remote Incident Response Leader

One Esecurity • Valencia

Presencial
EUR 90.000 - 130.000
Flexible schedules
Teleworking
Professional development
Remote Senior DFIR Consultant - Incident Response Lead
Remote Senior DFIR Consultant - Incident Response Lead

One Esecurity • Huelva

Presencial
EUR 70.000 - 110.000
Flexible schedules
Tele-working
Senior DFIR Incident Response Lead - Remote
Senior DFIR Incident Response Lead - Remote

One Esecurity • País Vasco

Presencial
EUR 70.000 - 110.000
Flexible schedules
Tele-working
Equipe de alto nivel
Remote Senior DFIR Lead - Incident Response
Remote Senior DFIR Lead - Incident Response

One Esecurity • Barcelona

Presencial
EUR 75.000 - 110.000
Flexible schedules
Tele‑working
Remote work with global clients
+1
Remote DFIR Lead & Incident Response Expert
Remote DFIR Lead & Incident Response Expert

One Esecurity • Meis

Presencial
EUR 70.000 - 90.000
Teletrabajo
Salario atractivo
Senior DFIR Consultant – Remote Incident Response Leader
Senior DFIR Consultant – Remote Incident Response Leader

One Esecurity • Badajoz

Presencial
EUR 90.000 - 130.000
Flexible schedules
Tele-working
Attractive salary