Boehringer Ingelheim

Digital Forensic and Cybersecurity Incident Responder (Sant Cugat del Vallès, Spain, Barcelona)

Sant Cugat del Vallès, Spain Type not listed
Information Technology

Boehringer Ingelheim is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

In this senior role, you will lead and support incident response and digital forensics activities, partnering closely with SOC analysts, infrastructure, and application teams.

This position includes escalation of ownership during major incidents and requires participation in an on-call rotation. Work hands-on with complex security incidents across endpoints, identity, network, and cloud.

Partner with global teams to quickly manage threats and reduce business impact.

Impact: As a Cybersecurity Incident Responder, you'll play a crucial role in protecting our organization's information systems and data, making a significant impact on our business operations.

Tasks and responsibilities

Monitor and analyze the security infrastructure, playing a key role in identifying and addressing threats and incidents to maintain the integrity, confidentiality, and availability of critical data and systems.

Contribute to security incident response processes and best practices.

Be the leader of critical security incident investigations.

Carry out comprehensive security investigations by analyzing logs, network traffic… and other data sources to find root causes.

Continuously improve and monitor our security incident detection and response workflows.

Collaborate with cross-functional teams to implement and improve use cases, runbooks, and procedures to properly handle occurring security incidents.

Act as a point of escalation for analysts on the team.

Leverage your expertise to identify, evaluate, and recommend new tools and technologies that can enhance the incident response capabilities of the team.

Provide expertise on Incident Response Activities and Digital Forensics, including the capture and preservation of system logs, volatile memory captures, image captures…

Requirements 

5+ years of experience hands-on incident response.

Hands-on experience in digital forensics, including the collection, triage, and analysis of evidence from endpoints using artifact extraction tools.

Demonstrable experience in at least two of the following areas: Malware Analysis, Cloud Security, Vulnerability Management or Operational Technology.

Programming experience in scripting languages like (Python, PowerShell or Bash).

Solid understanding of Linux and Windows architecture, common networking protocols, and packet inspection concepts.

Experience with security technologies such as firewalls, IDS/IPS, anti-malware, SIEM, and endpoint detection and response (EDR) tools.

Excellent problem-solving skills and the ability to perform effectively under pressure during high-severity incidents.

Strong written and verbal communication skills, including the ability to document findings and present recommendations.

Advanced knowledge of common attack techniques (system exploits, network attacks, web protocols, phishing, and malware).

Knowledge of how to integrate AI/LLM capabilities into Incident Response, such as automated evidence summarization, SOC/IR playbook automation, or detection-rule generation, is considered a plus.

Hands-on experience in Red Team is considered a plus.

Knowledge of cloud architecture, particularly AWS, is considered a plus.

Security certifications like CRTO, OSCP, GCIH, GCFA, GEIR… are considered a plus.

Please note: The job title used in this advertisement may differ from the official contractual title.

#IamBoehringerIngelheim because…

We are continuously working to design the best experience for you. Here are some examples of how we will take care of you:

Flexible working conditions

Life and accident insurance

Health insurance at a competitive price

Investment in your learning and development

Gym membership discounts

If you have read this far, what are you waiting for to apply? We want to know more about you!

]]>

Job details

Seniority
Not listed
Function
Information Technology
Therapeutic area
Not listed
Location
Sant Cugat del Vallès, Spain
Employment type
Not listed

How this role compares

Computed from every other active Information Technology role in our database, not just this employer's listings.

We currently track 1097 comparable Information Technology roles across 55 biopharma companies.

1097Comparable roles tracked
1035Currently active
55Companies hiring similar roles
29Countries represented

Salary context

143 of 1097 peers report a salary range (USD, annualized)

Peers share this role's job function. This posting doesn't list a seniority level, so peers aren't narrowed by seniority either -- the range below may span more levels than usual.

This roleSubject Not listed on this posting
Lowest disclosed · Senior Data Security Engineer (Insider Risk Management – Engineering) · AbbVie $0/hr – $0/hr (≈ $0–$0/yr)
Highest disclosed · Senior Director, Targets and Mechanisms Solutions · Pfizer $230,900/yr – $384,800/yr
Peer group range $0 – $307,850 (median $165,900)

Where these roles are based

Top locations among the 1097 comparable roles

India507
United States241
Spain105
Poland72
Portugal32
China13

+ 23 more countries

Seniority mix

612 of 1097 peers have a known seniority level

Senior290
Manager135
Associate52
Principal50
Associate Director39
Director28
Senior Director13
Intern/Fellow/Postdoc4
Executive/VP1

Therapeutic area mix

1 of 1097 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden

Oncology1

Similar opportunities

The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.

40%similar
Roche Sant Cugat del Vallès, Barcelona, Spain
Same function Same country
40%similar
Roche Sant Cugat del Vallès, Barcelona, Spain Senior
Same function Same country
40%similar
Novartis Barcelona Gran Vía, Spain
Same function Same country
40%similar
Novartis Barcelona Gran Vía, Spain Associate Director
Same function Same country
40%similar
Novartis Barcelona Gran Vía, Spain Associate Director
Same function Same country
40%similar
Novartis Barcelona Gran Vía, Spain Associate Director
Same function Same country

How we calculate "similar"

No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.

Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.

40%
Lead Software Engineer (Rust)
Roche · Sant Cugat del Vallès, Barcelona, Spain · Seniority not listed
Function Therapeutic area Seniority Country
40%
Associate Director Business Analysis (GCO)
Novartis · Barcelona Gran Vía, Spain · Associate Director
Function Therapeutic area Seniority Country
40%
Snr. Specialist, Platform Services - Data, Digital & IT
Novartis · Barcelona Gran Vía, Spain · Seniority not listed
Function Therapeutic area Seniority Country
40%
Associate Director, Solution Design Expert (Advanced Therapies)
Novartis · Barcelona Gran Vía, Spain · Associate Director
Function Therapeutic area Seniority Country
Unmatched or unknown dimensions score exactly the same: 0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.