CSIRTEngineer (India)

CSIRTEngineer (India)

12 Aug
|
NextGen Identity
|
India

12 Aug

NextGen Identity

India

? We're Hiring: CSIRT L3 Engineer | NextGen Identity

? Location: Remote (India)

? Experience: 5+ Years

⏳ Availability: Immediate Joiners Preferred

Role: CSIRT L3 Engineer

We're looking for an experienced CSIRT L3 Engineer with robust expertise in advanced incident response, digital forensics, threat hunting, detection engineering, and security incident management. The ideal candidate should be capable of handling complex security incidents, leading major incident response activities, performing root cause analysis, and providing technical mentorship to L1 and L2 analysts.

⭐ Must-Have Skills

✅ 5+ years of experience in CSIRT, Incident Response, SOC, Digital Forensics, or Cybersecurity.

✅ Strong experience in advanced forensic analysis across disk, memory, network, and cloud environments.

✅ Strong expertise in root cause analysis, attack timeline reconstruction, and MITRE ATT&CK; mapping.

✅ Experience with threat hunting using threat intelligence, IOCs, TTPs, and behavioral indicators.

✅ Hands-on experience with SIEM, EDR, and NDR detection engineering and rule tuning.

✅ Experience acting as an Incident Commander during major security incidents.

✅ Basic malware and artifact analysis experience or the ability to coordinate with dedicated malware analysis teams.

✅ Strong communication, stakeholder management, and technical leadership skills.

✅ Experience mentoring L1/L2 SOC or CSIRT analysts and reviewing complex escalations.

Key Responsibilities

Perform advanced forensic investigations across disk, memory, network, endpoint, and cloud environments.





Conduct detailed root cause analysis (RCA) and reconstruct attack timelines to determine the scope, impact, and attack path.

Map incidents and attacker activity to the MITRE ATT&CK; framework.

Perform basic malware and artifact analysis and coordinate with specialized malware analysis teams when required.

Conduct proactive threat hunting using threat intelligence, IOCs, TTPs, and other threat indicators.

Design, develop, tune, and optimize SIEM, EDR, and NDR detection rules to improve detection accuracy.

Act as Incident Commander for major security incidents and coordinate investigation, containment, eradication, and recovery activities.

Mentor and provide technical guidance to L1 and L2 analysts, including reviewing escalations and investigation findings.

Own and maintain incident response playbooks, runbooks, SOPs, and operational procedures.

Coordinate with Legal, Compliance, PR, Leadership, and other stakeholders during major security incidents.

Support breach notification and regulatory reporting requirements, including GDPR, CERT-In, and PCI-DSS.

Lead post-incident reviews, RCA, and lessons-learned activities, ensuring remediation actions are tracked to closure.

Prepare and present incident metrics,



executive summaries, investigation findings, and security recommendations to leadership.

Contribute to tabletop exercises, purple teaming, SOAR automation, and continuous improvement of incident response capabilities.

Required Skills & Experience

5+ years of experience in CSIRT, Incident Response, SOC, Digital Forensics, or Cybersecurity.

Strong understanding of incident response lifecycle, digital forensics, threat intelligence, and attack methodologies.

Hands-on experience with SIEM, EDR, NDR, threat hunting, and detection engineering.

Strong knowledge of MITRE ATT&CK;, IOCs, TTPs, and attack timeline analysis.

Experience with disk, memory, network, endpoint, and cloud forensics.

Experience handling major security incidents and incident command responsibilities.

Strong documentation, analytical, communication, and stakeholder management skills.

Ability to mentor junior analysts and independently handle complex security investigations.

Experience working with cross-functional teams and senior leadership during high-severity incidents.

Why Join Us?

Work on complex enterprise cybersecurity and incident response engagements.

Exposure to advanced DFIR, threat hunting, detection engineering, and security technologies.

Collaborate with global clients and experienced cybersecurity professionals.

Opportunity to lead major security incidents and strategic security initiatives.

Continuous learning and career growth in Cybersecurity, CSIRT, and Incident Response.

📌 CSIRTEngineer (India)
🏢 NextGen Identity
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: csirtengineer (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: csirtengineer (india) / india