21 Aug
|
Rakuten Symphony
|
Bengaluru
21 Aug
Rakuten Symphony
Bengaluru
:
Description:
The Security Engineering & Operations Supervisory Department at Rakuten Mobile is seeking a Senior DFIR Lead to join a growing cyber defense organization. The candidate will serve as a lead responder for complex security incidents, performing deep-dive forensic investigations, root cause analysis, and containment activities. This role is ideal for a seasoned investigator who thrives under pressure, possesses a forensic mindset, and can turn incident findings into strategic improvements that harden our environment against future threats.
Responsibilities:
- Lead and execute end-to-end incident response investigations, from initial triage and scoping to containment, eradication, and recovery.
- Perform deep-dive forensic analysis of endpoints, network traffic, and cloud environments to reconstruct intrusion chains and identify the scope of compromise.
- Conduct advanced malware analysis (static and dynamic) to understand adversary capabilities, persistence mechanisms, and command-and-control (C2) infrastructure.
- Develop and maintain incident response playbooks and standard operating procedures (SOPs) for various threat scenarios, ensuring alignment with industry best practices.
- Collaborate with the Threat Hunting and Detection Engineering teams to provide "lessons learned" from investigations, ensuring that incident findings are converted into permanent detection logic.
- Partner with Legal, Privacy, and IT stakeholders during high-stakes incidents to ensure proper evidence handling, chain-of-custody, and regulatory compliance.
- Utilize advanced forensic tools (e.g., EnCase, FTK, Magnet AXIOM, Volatility) and SIEM/EDR platforms to conduct investigations and validate findings.
- Automate forensic collection and analysis processes using scripting languages (e.g.,
Python, PowerShell) to reduce time-to-respond during critical incidents.
- Provide mentorship to junior analysts, conducting peer reviews of forensic reports and overseeing the technical quality of investigations.
- Maintain a high level of readiness for 24/7 incident response support, providing expert guidance during major security breaches.
Requirements:
Qualifications:
- Minimum of 10-12 years of experience in cybersecurity, with significant expertise in Digital Forensics and Incident Response.
- Bachelor’s degree in computer science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience.
- Industry certifications such as SANS GCFA, GCFE, GNFA, or CISSP are highly preferred.
Required Skills & Knowledge:
- Expertise in forensic artifacts across major Operating Systems (Windows, Linux, macOS), including file system analysis, memory forensics, and registry/log analysis.
- Deep expertise in investigating security incidents within telecommunications environments. Ability to perform forensic analysis on mobile core network elements, identifying anomalies in signaling protocols (e.g., 4G/5G, SS7, Diameter, GTP, HTTP/2).
Experience in tracing malicious activity across complex, high-throughput telecom traffic flows.
- Proven experience conducting incident response in containerized environments.
Ability to perform runtime forensics within Kubernetes (K8s) clusters, including container breakout analysis, pod-level log correlation, and forensic inspection of ephemeral storage. Deep understanding of K8s API audit logs, etcd integrity, and the forensic implications of container orchestration
- In-depth knowledge of the MITRE ATT&CK; framework for mapping adversary behavior during investigations and identifying gaps in current security controls.
- Strong understanding of enterprise network architecture and protocols, with the ability to perform full-packet capture analysis to identify malicious traffic patterns.
- Deep understanding of cloud-native environments, including Kubernetes and container orchestration; proven experience performing incident response within AWS, Azure, or GCP.
- Experience leveraging advanced AI/ML capabilities, including LLMs, to assist in log correlation, code analysis, and the summarization of complex incident timelines.
- Exceptional analytical expertise, critical thinking, and the ability to remain calm and methodical under high-pressure, time-sensitive situations.
- Excellent written and verbal communication skills, with the ability to produce high-quality, court-admissible forensic reports for both technical and executive audiences.
- Demonstrated strong documentation discipline, capable of maintaining strict chain-of-custody and producing repeatable, defensible investigation results.
- Ability to work effectively in a fast-paced environment, with flexibility for non-standard work hours during active incident response operations.
- Solid aptitude for continuous learning, particularly regarding emerging attacker tradecraft and new forensic methodologies.
📌 Staff Engineer, Digital Forensics & Incident Response (Bengaluru)
🏢 Rakuten Symphony
📍 Bengaluru