Tech - Digital Forensics and Incident Response Analyst DFIR N3
Telefónica·Spain
What they offer
Full-time hours
Per the ad.
Hybrid
Office and home days — the ad has the split.
What they ask for
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
Speak native-level Spanish
Listed as a requirement in the ad.
Work in English
English is required, per the ad.
Be near Spain for hybrid days
No relocation package mentioned.
Have 3+ years of experience
Senior-level role.
Pulled from the advert automatically — the full ad is what counts.
This job was published 5 months ago
What you'll do
You will be part of the DFIR team, handling new incidents and providing continuity to ongoing investigations. Your responsibilities will include:
Conducting investigations in corporate environments and security incidents, identifying threats and suspicious activity.
Coordinating teams involved in incident response.
Collecting, preserving, and analyzing digital evidence, identifying the root cause and scope of the incident.
Examining security events, access logs, and other relevant data to reconstruct the attack sequence.
Using forensic tools to analyze systems, networks, and devices in search of IoCs or malicious activity.
Preparing detailed reports with findings and improvement recommendations.
Investigating intrusions, cloning devices, analyzing data, holding client meetings, and acting as an Incident Handler or technical analyst.
What we're looking for
AND FOR THIS, WE BELIEVE IT WOULD BE IDEAL IF YOU HAD...
Experience
More than 3 years in cybersecurity, with at least 1 year in incident investigation and forensics.
Demonstrable experience in:
Forensic analysis applied to IR.
Cybersecurity incident management.
Advanced forensics on Windows and Linux.
Dynamic analysis in sandbox environments (AnyRun, JoeSandbox, CAPE) and static tools (yara, CAPA, FLOSS).
Investigation in cloud environments (Microsoft, AWS, Google).
Cross-functional coordination between different areas.
Nice to have
Experience with English-speaking clients, knowledge of mobile device forensics, and a motivation for continuous learning will be valued.
Education & certifications
Education
Required: Higher Level Training (FP Superior) or a university degree in computer science or telecommunications.
Desirable: Certifications such as GCIH, GCFE, GCFA, GREM, CHFI.
Languages
English B2 or higher (spoken and written).
What you'll get
- Work-life balance measures and flexible working hours
- Ongoing training and certifications.
- Hybrid remote work model.
- Attractive social benefits package
- Excellent dynamic and multidisciplinary work environment
- Volunteering programs
How you'll work
This position requires on-call availability.
About the company & team
WHAT IS TELEFÓNICA TECH?
Telefónica Tech is the leading digital transformation company of the Telefónica Group. We offer a wide range of integrated technological services and solutions in Cybersecurity, Cloud, IoT, Big Data, Artificial Intelligence, and Blockchain, with which we support our clients in their digital transformation.
We are a group of over 6,200 brave people who work every day from different points around the world to achieve excellence, through leadership based on transparency and team spirit. If you identify with our pillars, we can't wait to meet you!
www.telefonicatech.com
WHAT DO WE DO IN THE TEAM?
In the Digital Forensics and Incident Response (DFIR) unit at Telefónica Cybersecurity & Cloud Tech, we have a young and dynamic team responsible for managing our clients' main cybersecurity incidents. Our goal is to contain, analyze, and eradicate threats, guiding clients throughout the process and providing recommendations to prevent future incidents.
Technical knowledge
Required:
Use of forensic solutions for evidence acquisition (triage or full acquisition).
Knowledge of file systems and operating systems (Windows, MacOS, iOS, Android).
Proficiency with forensic suites (Magnet AXIOM, X-Ways, KAPE, Nirsoft).
Knowledge of threat actor TTPs.
Desirable:
General knowledge of IR and cybersecurity for log analysis (Firewalls, EDR, SIEM).
Forensic experience in Azure, AWS, or GCP.
Key Competencies
We are looking for someone with teamwork skills, proactivity, problem-solving ability, client communication skills, creativity, and critical thinking.
Additional information
#WeAreDiverse #WePromoteEquality
We are convinced that diverse and inclusive teams are more innovative, transformative, and achieve better results.
Therefore, we promote and guarantee the inclusion of all people regardless of gender, age, sexual orientation and identity, culture, disability, or any other condition.
We want to meet you! 😊
What you'll do
Formarás parte del equipo DFIR atendiendo nuevos incidentes y dando continuidad a investigaciones en curso. Entre tus responsabilidades estarán:
Conducir investigaciones en entornos corporativos e incidentes de seguridad, identificando amenazas y actividades sospechosas.
Coordinar equipos implicados en la respuesta ante incidentes.
Recolectar, preservar y analizar evidencias digitales, identificando causa raíz y alcance del incidente.
Examinar eventos de seguridad, registros de acceso y otros datos relevantes para reconstruir la secuencia de ataque.
Utilizar herramientas forenses para analizar sistemas, redes y dispositivos en búsqueda de IoCs o actividad maliciosa.
Preparar informes detallados con hallazgos y recomendaciones de mejora.
Investigar intrusiones, clonar dispositivos, analizar datos, mantener reuniones con clientes y actuar como Incident Handler o analista técnico.
What we're looking for
Y PARA ELLO, CREEMOS QUE SERÍA IDEAL QUE CONTARAS CON...
Experiencia
Más de 3 años en ciberseguridad, con al menos 1 año en investigación de incidentes y forense.
Experiencia demostrable en:
Análisis forense aplicado a IR.
Gestión de incidentes de ciberseguridad.
Forense avanzado en Windows y Linux.
Análisis dinámico en sandbox (AnyRun, JoeSandbox, CAPE) y herramientas estáticas (yara, CAPA, FLOSS).
Investigación en entornos cloud (Microsoft, AWS, Google).
Coordinación transversal entre distintas áreas.
Nice to have
Se valorará experiencia con clientes en inglés, conocimientos de análisis forense en móviles y motivación por seguir aprendiendo.
Education & certifications
Formación
Requerida: FP Superior o titulación universitaria en informática o telecomunicaciones.
Deseable: certificaciones como GCIH, GCFE, GCFA, GREM, CHFI.
Languages
Idiomas
Inglés B2 o superior (hablado y escrito).
What you'll get
- Medidas de conciliación y flexibilidad horaria.
- Formación continua y certificaciones.
- Modelo híbrido de teletrabajo.
- Atractivo paquete de beneficios sociales.
- Excelente ambiente de trabajo dinámico y multidisciplinar.
- Programas de voluntariado.
How you'll work
Este trabajo tiene guardias.
About the company & team
¿QUÉ ES TELEFONICA TECH?
Telefónica Tech es la compañía líder en trasformación digital del Grupo Telefónica. Contamos con una amplia oferta de servicios y soluciones tecnológicas integradas de Ciberseguridad, Cloud, IoT, Big Data, Inteligencia Artificial y Blockchain, con la que acompañamos a nuestros clientes en su transformación digital.
Somos un grupo de más de 6200 personas valientes que trabajamos a diario desde distintos puntos del mundo para alcanzar la excelencia, a través de un liderazgo basado en la transparencia y en el espírItu de equipo. Si te identificas con nuestros pilares, ¡estamos deseando conocerte!
www.telefonicatech.com
¿QUÉ HACEMOS EN EL EQUIPO?
En la unidad de Respuesta de Incidentes y Análisis Forense (DFIR) de Telefónica Cybersecurity & Cloud Tech contamos con un equipo joven y dinámico encargado de gestionar los principales incidentes de ciberseguridad de nuestros clientes. Nuestro objetivo es contener, analizar y erradicar amenazas, guiando a los clientes durante todo el proceso y ofreciéndoles recomendaciones para evitar futuras incidencias.
Conocimientos técnicos
Necesarios:
Uso de soluciones forenses para adquisición de evidencias (triaje o completa).
Conocimiento de sistemas de ficheros y sistemas operativos (Windows, MacOS, iOS, Android).
Manejo de suites forenses (Magnet AXIOM, X-Ways, KAPE, Nirsoft).
Conocimiento de TTPs de actores de amenazas.
Deseables:
Conocimientos generales de IR y ciberseguridad para análisis de logs (Firewalls, EDR, SIEM).
Experiencia forense en Azure, AWS o GCP.
Competencias clave
Buscamos a alguien con trabajo en equipo, proactividad, capacidad resolutiva, comunicación con clientes, creatividad y pensamiento crítico.
Additional information
#SomosDiversos #Fomentamosigualdad
Estamos convencidos/as de que los equipos diversos e inclusivos son más innovadores, transformadores y consiguen mejores resultados.
Por ello promovemos y garantizamos la inclusión de todas las personas sin importar género, edad, orientación e identidad sexual, cultura, discapacidad o cualquier otra condición
¡Queremos conocerte! 😊
This job was automatically translated to English, .
About the company
Telefónica
Telecom