The English-language job board for Spain

Incident Response & DFIR Lead

Remote, Europe·Full-time·Added 3 days ago

JustMarkets

78 open roles

Overview

Job details

  • Full-time hours

    Per the ad.

  • Fully remote

    Per the ad.

Requirements

  • Have the right to work in Spain

    JustMarkets doesn't mention sponsorship, but this role may fit the Digital nomad visa.

  • Work in English

    English is required, per the ad.

Pay & benefits

What you'll get

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company's approved Public holiday list
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)

Requirements

What we're looking for

  • Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned
  • Experience leading complex security incidents and coordinating multiple technical teams during active response
  • Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs
  • Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration
  • Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles
  • Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation
  • Experience with Microsoft Entra ID / Active Directory incident investigation
  • Understanding of common incident scenarios including ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse
  • Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective
  • Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly

Nice to have

  • Hands-on experience with Cortex XDR, Elastic Security or equivalent enterprise platforms
  • Experience investigating AWS or other cloud environments
  • Experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, FTK or equivalent
  • Experience investigating ransomware, BEC, insider-threat or cloud-account-compromise cases
  • Experience developing or improving incident response playbooks and containment procedures
  • Experience running tabletop or cyber incident exercises
  • Experience working with Legal, Privacy, HR or regulators during security incidents
  • Experience managing external DFIR or incident-response retainers
  • Python, PowerShell or other scripting experience useful for investigation and evidence processing
  • Experience in fintech, payments, brokerage, trading, banking or another regulated environment
  • Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP or equivalent

The role

We are inviting you, a highly motivated and results-oriented Incident Response & DFIR Lead to join our team on a full-time basis.

Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.

What you'll do

  • Lead incident response, containment and forensic coordination for confirmed security incidents
  • Act as Incident Commander for major security incidents within the defined authority model
  • Assign incident roles and maintain clear ownership of investigation, containment and recovery actions
  • Maintain incident timelines, evidence logs, decision logs and action tracking
  • Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry
  • Direct forensic collection and analysis required to determine attack path, scope, persistence and impact
  • Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners
  • Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required
  • Coordinate eradication and recovery activities and ensure systems return to a sufficiently trusted state
  • Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements
  • Maintain practical forensic and evidence-handling standards
  • Develop and maintain incident playbooks, forensic checklists and containment procedures
  • Lead post-incident reviews and root-cause analysis
  • Ensure post-incident remediation actions have accountable owners, due dates and follow-up
  • Identify telemetry, detection and forensic-readiness gaps exposed during investigations
  • Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners
  • Support incident exercises and readiness testing
  • Develop and mentor Incident Response / DFIR Specialists
  • Coordinate with external forensic, incident-response or specialist providers where required
  • Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders

Hiring process

Application review, one or more interviews, then an offer; described as fast and easy 1 interview

  • Applications are reviewed quickly and candidates are kept informed at every step.

About JustMarkets

JustMarkets is a global fintech company operating in the multi-asset brokerage space, providing retail and institutional clients with access to trading in forex, commodities, indices, and shares. The company has grown into an international brand with a significant presence across multiple regions, including Europe, Asia, and Latin America, and is known for its proprietary trading platforms and customer-centric approach.

In Spain, JustMarkets has established a dedicated hub to support its growing client base and expand its European footprint. The company's Spain office is a key part of its global operations, offering roles in engineering, product, design, marketing, and finance. For international professionals, JustMarkets presents opportunities to work in a fast-paced, multicultural environment, with a strong emphasis on technology and data-driven decision-making, making it an attractive option for those looking to build a career in the fintech sector in Spain.

Industry
Fintech
Founded
2012
Employees
500–1,000
Headquarters
Limassol, Cyprus
In Spain
Madrid

Good to know if you are moving

  • The company's global HQ is in Limassol, Cyprus, but its Spain office in Madrid is a key hub for European operations, offering a range of roles in tech, product, and marketing.
  • JustMarkets is a global fintech company, so English is likely the working language, making it accessible for international professionals.
  • The company offers a modern tech stack and data-driven approach, which can be appealing for engineers and data specialists.
  • Roles in Spain span a wide range of functions, from engineering and design to finance and HR, indicating a multi-disciplinary environment.
  • As a regulated broker, the company offers a stable and compliance-focused work environment, which is a plus for professionals from the financial sector.
All open roles at JustMarkets
WhatsApp