Why Mizuho
At Mizuho, we provide the stability of an international industry leader with the career trajectory of a growing business. Our steady, strategic growth gives our people at all levels rewarding degrees of responsibility and richer work experience than a boutique firm or an established giant could offer alone.
It’s the local expertise of our employees that makes our global network so powerful. By collaborating with colleagues and clients who share the same ambition and drive, you can amplify your sphere of influence and base of knowledge as part of one of the largest banks in the world.
Mizuho Global Services (MGS) is seeking a senior, hands-on Digital Forensics & Incident Response (DFIR) Lead to lead enterprise cyber investigations and strengthen incident response capabilities across Mizuho's global operations. This role is responsible for managing high-severity incidents, conducting advanced forensic investigations, preserving evidentiary integrity, and improving cyber defense, detection, and response capabilities.
As a leader within the Cyber Fusion Center, you will partner with Security Operations, Threat Hunting, Threat Intelligence, Detection Engineering, Security Engineering, Risk, Legal, and Compliance teams to reduce cyber risk and enhance organizational resilience.
Key Responsibilities:
- Lead investigations and response activities for high-impact cybersecurity incidents, including ransomware, malware, insider threats, cloud compromise, credential compromise, and data breaches.
- Direct digital forensic investigations across endpoint, memory, network, identity, email, and cloud environments to determine attack scope, root cause, business impact, and remediation requirements.
- Coordinate cross-functional response efforts supporting containment, eradication, recovery, regulatory reporting, and post-incident remediation activities.
- Perform advanced forensic analysis, attack-path reconstruction, malware investigations, evidence correlation, and incident scoping to support accurate and timely decision-making.
- Improve cyber defense capabilities by translating investigation findings into detections, threat hunting use cases, incident response playbooks, automation opportunities, and security control improvements.
- Mature DFIR readiness through improved incident response standards, forensic procedures, tabletop exercises, simulations, and response preparedness programs.
- Provide technical leadership, mentorship, executive reporting, and support for audit, legal, compliance, and evidentiary requirements.
Required Qualifications:
- 12-15 years of cybersecurity experience, including significant hands-on expertise in Digital Forensics & Incident Response (DFIR).
- Proven experience leading enterprise-scale cyber investigations involving ransomware, malware, insider threats, cloud incidents, credential compromise, advanced threats, and data exfiltration.
- Deep expertise in endpoint, memory, disk, network, identity, email, and cloud forensics, along with incident response, threat hunting, attack-path analysis, and detection engineering principles.
- Experience supporting legal, regulatory, compliance, audit, and evidentiary requirements, including chain-of-custody and forensic evidence preservation.
- Solid leadership, communication, stakeholder management, investigative, analytical, and executive reporting skills.
- Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Technology, or equivalent experience.
- Security Technologies: Splunk Enterprise Security, Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto Cortex XDR, Palo Alto Cortex XSOAR, Velociraptor, Volatility, KAPE, Magnet AXIOM,
EnCase, FTK, Wireshark, YARA, Sysinternals, Microsoft Azure, Microsoft 365, AWS, Active Directory, Microsoft Entra ID, Windows, Linux, SIEM, SOAR, EDR/XDR, cloud security, threat intelligence, forensic analysis, and security automation platforms.
Preferred Qualifications:
- Certifications such as GCFA, GCIH, GNFA, GREM, GCFE, CISSP, CCSP, or equivalent.
- Experience in malware reverse engineering, adversary simulation, threat hunting, detection engineering, cloud-native investigations, and incident response automation.
- Experience supporting financial services or other highly regulated industries.
- Familiarity with NIST, CIS Controls, FFIEC, and cybersecurity regulatory frameworks
Company Overview: Mizuho Pune is an integral part of Mizuho Financial Group, one of the world’s leading financial institutions with a strong global presence across the Americas, EMEA, and Asia. Based in India, Mizuho Pune supports Mizuho’s international businesses by delivering high-quality, scalable, and resilient services across multiple functions.
Mizuho Pune plays a critical role in driving operational excellence, standardization, and innovation for Mizuho Americas. By combining deep domain expertise with strong process, technology, and analytical capabilities, it partners closely with regional and global teams to support corporate and investment banking, capital markets, and corporate services functions, while adhering to the highest standards of risk management, regulatory compliance, and control.
Mizuho Pune offers competitive compensation and benefits package aligned with industry standards and local market practices.
Mizuho Pune is an equal opportunity employer and is committed to fostering an inclusive and diverse workplace.
Employment is subject to applicable background verification checks in accordance with Indian laws and company policies.
https://www.mizuhogroup.com/asia-pacific/mizuho-global-services/careers
📌 Digital Forensics & Incident Response (DFIR) Lead (Pune)
🏢 Mizuho
📍 Pune