Tech_CSIRT and DFIR Lead

Telefónica
Telefónica
Madrid, SpainOn-siteCompetitiveAdded 1 month agoLead · 10+ yearsPermanentRemote: Hybrid🇪🇸Spanish: Native

This job was originally posted in Spanish and automatically translated to English.

Requirements

Experience
10+ years of experience in cybersecurity services management.
Proven experience in managing complex security incidents.
Experience in large corporate environments, preferably Telco or multinationals.
Participation in digital forensic investigations (host, network, cloud).
Experience in coordinating multidisciplinary teams and crisis management.
Education
Required:
University degree (Bachelor's and/or Master's) in related areas: preferably computer science or telecommunications
Master's or postgraduate training related to the field of cybersecurity
Desirable
Certifications such as: GCFA, GCIH, CISSP, CISM, CEH, CHFI, etc.
Residency in Madrid.
Technical Knowledge
Deep knowledge of forensic techniques (DFIR), threat intelligence, and general incident response methodology (NIST 800-61 v2 and similar frameworks)
General knowledge of offensive security, analysis and vulnerabilities, as well as other SOC services such as SIEM, SASE, DLP, etc.
Basic knowledge of data privacy: GDPR, LOPD, ENSv3, etc.
To perform the role, the skills that would fit the team and project would be:
Experience in managing distributed and international teams.
High capacity for self-management and time organization.
Ability to manage multiple activities simultaneously in high-pressure environments.
Ability to coordinate and facilitate meetings (in-person and virtual) in Spanish and English.
Excellent communication and presentation skills, with a capacity for synthesis (Spanish and English).
Experience in communicating with senior management (C-level).
Ability to manage and resolve complaints.
LANGUAGES
Spanish: native or very fluent
Required: English (high level, C1)
Full-time - Availability

Benefits

• Work-life balance measures and flexible hours.
• Continuous training and certifications.
• Hybrid remote work model.
• Attractive social benefits package.
• Excellent dynamic and multidisciplinary work environment.
• Volunteering programs.

Job Description

WHAT IS TELEFONICA TECH?

Telefónica Tech is the leading digital transformation company of the Telefónica Group. We have a wide range of integrated technological services and solutions in Cybersecurity, Cloud, IoT, Big Data, Artificial Intelligence, and Blockchain, with which we accompany our clients in their digital transformation.

We are a group of more than 6,200 brave people working daily from different parts of the world to achieve excellence, through leadership based on transparency and team spirit. If you identify with our pillars, we look forward to meeting you!

www.telefonicatech.com

WHAT DO WE DO IN THE TEAM?

In the Digital Forensics & Incident Response (DFIR) unit of Telefónica Cybersecurity & Cloud Tech, we protect digital assets against advanced threats, leading incident detection and response as well as forensic analysis. We work on investigating complex cyberattacks, ensuring an effective response and continuously improving our capabilities and processes to anticipate new risks.

WHAT WILL YOUR DAY-TO-DAY BE LIKE?

Your mission will be to lead the CSIRT & DFIR team, ensuring the correct management of security incidents, from detection to resolution and subsequent learning.

Your day-to-day:

  • Coordinate the global operation of DFIR and Threat Hunting services, ensuring an effective response to cybersecurity incidents.
  • Keep the team's operations documented and updated, including laboratory environments.
  • Ensure correct coordination between DFIR/Threat Hunting and the rest of the cybersecurity teams.
  • Manage team capacity and development, ensuring adequate resources, training, and tools.
  • Oversee the financial management of services and prepare reporting for management (costs, business cases, etc.).
  • Collaborate on the evolution of existing services and the development of new capabilities.
  • Manage client relationships (including executive and legal levels) during incidents and service delivery.
  • Support sales and pre-sales in commercial opportunities related to the services.
  • Maintain strategic relationships with cybersecurity solution vendors.
  • Act as a liaison with management regarding critical incidents and the overall status of the service.
  • Participate occasionally in visibility initiatives (events, articles, corporate blog).

TO ACHIEVE THIS, WE BELIEVE IT WOULD BE IDEAL IF YOU HAD...

Experience

  • 10+ years of experience in cybersecurity services management.
  • Proven experience in managing complex security incidents.
  • Experience in large corporate environments, preferably Telco or multinationals.
  • Participation in digital forensic investigations (host, network, cloud).
  • Experience in coordinating multidisciplinary teams and crisis management.

Education

Required:

  • University degree (Bachelor's and/or Master's) in related areas: preferably computer science or telecommunications
  • Master's or postgraduate training related to the field of cybersecurity

Desirable

  • Certifications such as: GCFA, GCIH, CISSP, CISM, CEH, CHFI, etc.
  • Residency in Madrid.

Technical Knowledge

  • Deep knowledge of forensic techniques (DFIR), threat intelligence, and general incident response methodology (NIST 800-61 v2 and similar frameworks)
  • General knowledge of offensive security, analysis and vulnerabilities, as well as other SOC services such as SIEM, SASE, DLP, etc.
  • Basic knowledge of data privacy: GDPR, LOPD, ENSv3, etc.

To perform the role, the skills that would fit the team and project would be:

  • Experience in managing distributed and international teams.
  • High capacity for self-management and time organization.
  • Ability to manage multiple activities simultaneously in high-pressure environments.
  • Ability to coordinate and facilitate meetings (in-person and virtual) in Spanish and English.
  • Excellent communication and presentation skills, with a capacity for synthesis (Spanish and English).
  • Experience in communicating with senior management (C-level).
  • Ability to manage and resolve complaints.

LANGUAGES

  • Spanish: native or very fluent
  • Required: English (high level, C1)
  • Full-time - Availability

WHAT DO WE OFFER?

• Work-life balance measures and flexible hours.
• Continuous training and certifications.
• Hybrid remote work model.
• Attractive social benefits package.
• Excellent dynamic and multidisciplinary work environment.
• Volunteering programs.

#WeAreDiverse #WePromoteEquality
We are convinced that diverse and inclusive teams are more innovative, transformative, and achieve better results.
Therefore, we promote and guarantee the inclusion of all people regardless of gender, age, sexual orientation and identity, culture, disability, or any other condition.

We want to meet you! 😊

Need a visa? No sponsorship mentioned here. Browse visa jobs