Tech - CSIRT and DFIR Manager

Telefónica·Spain

What they offer

  • Full-time hours

    Per the ad.

  • Hybrid

    Office and home days — the ad has the split.

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Speak native-level Spanish

    Listed as a requirement in the ad.

  • Work in English

    English is required, per the ad.

  • Be near Spain for hybrid days

    No relocation package mentioned.

  • Have 10+ years of experience

    Lead-level role.

Pulled from the advert automatically — the full ad is what counts.

Added 2 months ago
Read the full advert

About the role

Your mission will be to lead the CSIRT & DFIR team, ensuring proper security incident management, from detection through to resolution and subsequent learning.

Your day-to-day:

What you'll do

Coordinate the global operation of DFIR/CSIRT services, ensuring an effective response to cybersecurity incidents.

Keep the team's operations documented and up to date, including laboratory environments.

Ensure proper coordination between DFIR/CSIRT and the rest of the cybersecurity teams.

Manage team capacity and development, ensuring adequate resources, training, and tools.

Oversee the financial management of services and prepare reporting for management (costs, business cases, etc.).

Collaborate on the evolution of existing services and the development of new capabilities.

Manage client relationships (including executive and legal levels) during incidents and service delivery.

Support sales and pre-sales in commercial opportunities related to the services.

Maintain strategic relationships with cybersecurity solution vendors.

Act as a liaison with management on critical incidents and the overall status of the service.

Occasionally participate in visibility initiatives (events, articles, corporate blog).

Education & certifications

Education

Required:

University degree (bachelor's and/or master's) in related fields: computer science or telecommunications, preferably.

Master's degree or postgraduate qualification in the field of cybersecurity.

Desirable

Certifications such as: GCFA, GCIH, CISSP, CISM, CEH, CHFI, etc.

Languages

Spanish: native or highly fluent.

Required: English (advanced level, C1).

What you'll get

  • Work-life balance measures and flexible working hours
  • Ongoing training and certifications.
  • Hybrid remote work model.
  • Attractive social benefits package
  • Excellent dynamic and multidisciplinary work environment
  • Volunteering programs

How you'll work

Residence in Madrid.

Full-time - Availability.

About the company & team

WHAT IS TELEFÓNICA TECH?

Telefónica Tech is the leading digital transformation company of the Telefónica Group. We offer a wide range of integrated technological services and solutions in Cybersecurity, Cloud, IoT, Big Data, Artificial Intelligence, and Blockchain, with which we support our clients in their digital transformation.

We are a group of over 6,200 brave people who work every day from different points around the world to achieve excellence, through leadership based on transparency and team spirit. If you identify with our pillars, we can't wait to meet you!

www.telefonicatech.com

WHAT DO WE DO IN THE TEAM?

In the Digital Forensics & Incident Response (DFIR) unit of Telefónica Cybersecurity & Cloud Tech, we protect digital assets against advanced threats, leading incident detection and response and forensic analysis. We work on investigating complex cyberattacks, ensuring an effective response and continuously improving our capabilities and processes to anticipate new risks.

Experience

AND FOR THIS, WE BELIEVE IT WOULD BE IDEAL IF YOU HAD...

Experience

Over 10 years of experience in cybersecurity service management.

Proven experience in managing complex security incidents.

Experience in large corporate environments, preferably Telecom or multinational companies.

Participation in digital forensic investigations (host, network, cloud).

Experience coordinating multidisciplinary teams and crisis management.

Technical knowledge

Deep knowledge of forensic techniques (DFIR), threat intelligence, and general incident response methodology (NIST 800-61 v2 and similar frameworks).

General knowledge of offensive security, analysis, and vulnerabilities, as well as other SOC services such as SIEM, SASE, DLP, etc.

Basic knowledge of data privacy: GDPR, LOPD, ENSv3, etc.

Skills

To perform the role, the skills that would best fit the team and the project would be:

Strong self-management and time organization skills.

Ability to manage multiple activities simultaneously under pressure.

Ability to coordinate and facilitate meetings (in-person and virtual) in Spanish and English.

Excellent communication and presentation skills, with the ability to synthesize (Spanish and English).

Experience communicating with senior management (C-level).

Ability to manage and resolve complaints.

Experience managing distributed and international teams.

Additional information

#WeAreDiverse #WePromoteEquality

We are convinced that diverse and inclusive teams are more innovative, transformative, and achieve better results.

Therefore, we promote and guarantee the inclusion of all people regardless of gender, age, sexual orientation and identity, culture, disability, or any other condition.

We want to meet you! 😊

This job was automatically translated to English, .

About the company

Telefónica

Telefónica

Telecom

View company profile
Spanish company
100000 employees