Incident Handler
8 hours ago
Marbella
We’re hiring an Incident Handler – Detection & Response Asegúrese de leer la descripción completa a continuación y, si confía en que cumple todos los requisitos, envíe su solicitud de inmediato. We are looking for an experienced Incident Handler to join a cybersecurity team specialized in MDR, Threat Intelligence, Detection Engineering, Threat Hunting, Incident Response, Pentesting and Red Team operations. About the role As an Incident Handler, you will lead the response to high-criticality security incidents, acting across three key areas: strategic incident response, technical team coordination, and crisis management with the affected client. You will define investigation hypotheses, prioritize containment and recovery actions, and make decisions under uncertainty to minimize business impact. You will also coordinate DFIR analysts and collaborate closely with Red Team, Detection Engineering and Threat Intelligence teams to understand and anticipate attacker behavior. During major incidents, you will act as the main point of contact for the client, advising leadership and crisis committees on operational, legal and regulatory decisions, including notifications to authorities, insurer coordination and communication with relevant cybersecurity bodies. What you’ll do • Lead and coordinate high-criticality security incidents., • Define investigation, containment and recovery strategies., • Guide DFIR analysts during complex investigations., • Work closely with Threat Intelligence, Detection Engineering and Red Team teams., • Communicate clearly with clients, executive teams, legal teams, insurers and regulators., • Prepare and supervise technical and executive incident reports., • Support decision-making during crisis situations. What we’re looking for • Minimum 1 year of experience in incident response, with exposure to real crisis situations., • Minimum 3 years of experience in cybersecurity or related roles., • Experience managing incidents such as ransomware, BEC, identity compromise or critical infrastructure attacks., • Strong understanding of attack vectors, TTPs and MITRE ATT&CK., • Functional knowledge of Windows/Active Directory, M365/Entra ID and cloud environments such as Azure or AWS., • Good networking and communication protocol knowledge., • Excellent communication skills in Spanish; strong English is a plus., • Leadership, coordination and stakeholder management skills under pressure., • DFIR, incident management or cybersecurity certifications such as GCIH, GCFA, CISM, CISSP, ECIH or similar will be valued. What’s offered • Salary range: €34,000 – €38,000 gross/year + variable compensation., • Additional on-call compensation, including:, • Fixed weekly availability payment when on-call., • Payment for hours worked when intervention is required., • Remote work or office-based work in central Barcelona., • Flexible working hours and work-life balance support., • Continuous internal and external training., • Career development plan tailored to your interests and growth., • Direct involvement in real high-impact incidents across different sectors. xcskxlj Interested? Apply via LinkedIn or submit your CV via .