The English-language job board for Spain
Overview
Job details
Full-time hours
Per the ad.
Fully remote
Per the ad.
Requirements
Have the right to work in Spain
JustMarkets doesn't mention sponsorship, but this role may fit the Digital nomad visa.
Work in English
English is required, per the ad.
Pay & benefits
What you'll get
- 20 paid vacation days per year
- 10 paid sick leave days per year
- Public holidays as per the company's approved Public holiday list
- Medical budget
- Opportunity to work remotely
- Professional education budget
- Language learning budget
- Wellness budget (gym membership, sports gear and related expenses)
Requirements
What we're looking for
- Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned
- Experience leading complex security incidents and coordinating multiple technical teams during active response
- Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs
- Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration
- Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles
- Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation
- Experience with Microsoft Entra ID / Active Directory incident investigation
- Understanding of common incident scenarios including ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse
- Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective
- Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly
Nice to have
- Hands-on experience with Cortex XDR, Elastic Security or equivalent enterprise platforms
- Experience investigating AWS or other cloud environments
- Experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, FTK or equivalent
- Experience investigating ransomware, BEC, insider-threat or cloud-account-compromise cases
- Experience developing or improving incident response playbooks and containment procedures
- Experience running tabletop or cyber incident exercises
- Experience working with Legal, Privacy, HR or regulators during security incidents
- Experience managing external DFIR or incident-response retainers
- Python, PowerShell or other scripting experience useful for investigation and evidence processing
- Experience in fintech, payments, brokerage, trading, banking or another regulated environment
- Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP or equivalent
The role
We are inviting you, a highly motivated and results-oriented Incident Response & DFIR Lead to join our team on a full-time basis.
Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.
What you'll do
- Lead incident response, containment and forensic coordination for confirmed security incidents
- Act as Incident Commander for major security incidents within the defined authority model
- Assign incident roles and maintain clear ownership of investigation, containment and recovery actions
- Maintain incident timelines, evidence logs, decision logs and action tracking
- Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry
- Direct forensic collection and analysis required to determine attack path, scope, persistence and impact
- Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners
- Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required
- Coordinate eradication and recovery activities and ensure systems return to a sufficiently trusted state
- Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements
- Maintain practical forensic and evidence-handling standards
- Develop and maintain incident playbooks, forensic checklists and containment procedures
- Lead post-incident reviews and root-cause analysis
- Ensure post-incident remediation actions have accountable owners, due dates and follow-up
- Identify telemetry, detection and forensic-readiness gaps exposed during investigations
- Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners
- Support incident exercises and readiness testing
- Develop and mentor Incident Response / DFIR Specialists
- Coordinate with external forensic, incident-response or specialist providers where required
- Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders
Hiring process
Application review, one or more interviews, then an offer; described as fast and easy 1 interview
- Applications are reviewed quickly and candidates are kept informed at every step.
About JustMarkets
JustMarkets is a global fintech company operating in the multi-asset brokerage space, providing retail and institutional clients with access to trading in forex, commodities, indices, and shares. The company has grown into an international brand with a significant presence across multiple regions, including Europe, Asia, and Latin America, and is known for its proprietary trading platforms and customer-centric approach.
In Spain, JustMarkets has established a dedicated hub to support its growing client base and expand its European footprint. The company's Spain office is a key part of its global operations, offering roles in engineering, product, design, marketing, and finance. For international professionals, JustMarkets presents opportunities to work in a fast-paced, multicultural environment, with a strong emphasis on technology and data-driven decision-making, making it an attractive option for those looking to build a career in the fintech sector in Spain.
- Industry
- Fintech
- Founded
- 2012
- Employees
- 500–1,000
- Headquarters
- Limassol, Cyprus
- In Spain
- Madrid
- Website
- justmarkets.com
Good to know if you are moving
- The company's global HQ is in Limassol, Cyprus, but its Spain office in Madrid is a key hub for European operations, offering a range of roles in tech, product, and marketing.
- JustMarkets is a global fintech company, so English is likely the working language, making it accessible for international professionals.
- The company offers a modern tech stack and data-driven approach, which can be appealing for engineers and data specialists.
- Roles in Spain span a wide range of functions, from engineering and design to finance and HR, indicating a multi-disciplinary environment.
- As a regulated broker, the company offers a stable and compliance-focused work environment, which is a plus for professionals from the financial sector.
More jobs like this
or browse Security·Security·Mid-level·Remote·Cybersecurity·Digital nomad visa fit·Fintech



