Consultant (Gurugram)

Consultant (Gurugram)

07 Sep
|
EY
|
Gurugram

07 Sep

EY

Gurugram

Job Summary

The opportunity: - Discovery - Gurgaon.

National comprises sector-agnostic teams working across industries for a well-rounded experience.

ASU - Forensics - Discovery:

Successful organizations depend on their reputation for keeping promises, respecting laws and behaving ethically to maintain stakeholder trust. EY Forensic Integrity Services professionals help organizations protect and restore enterprise and financial reputation. We assist companies and their legal counsel to investigate facts, resolve disputes and manage regulatory challenges. We put integrity at the heart of compliance programs to help better manage ethical and reputational risks.

Responsibilities

- DFIR Analyst is responsible for investigating security incidents, analysing digital evidence and helping in containment and remediation of cyber security incident. The Analyst should be having experience on hands-on investigations, triage, evidence collection and documentation of complex cyber security incidents. 1. Key Responsibilities
- Understand incident details, affected systems, business impact and available infrastructure context.
- Identify relevant evidence sources, including logs, endpoint data, network data and security platform telemetry.
- Review alerts and logs from SIEM, EDR, SOAR, IDS/IPS, email security and other available sources.
- Validate suspicious activity and correlate events to reconstruct the probable attack path.
- Support initial containment actions such as endpoint isolation, IOC blocking and access restriction.
- Acquire forensic images, memory captures, logs and volatile data using approved procedures and tools.
- Preserve evidence integrity by minimizing contamination and maintaining proper chain-of-custody records.




- Analyse forensic artifacts such as event logs, registry, prefetch, LNK files, browser artifacts, metadata and EDR telemetry.
- Investigate endpoint, malware, email and network indicators to identify persistence, lateral movement, exfiltration and root cause.
- Enrich indicators using threat intelligence sources and map attacker behaviour to MITRE ATTCK techniques.
- Prepare triage and investigation reports covering timelines, findings, impact, corrective actions and recommendations. 2. Tools Technology Knowledge
- Hands-on knowledge of forensic tools such as Autopsy, Sleuth Kit, FTK Imager, EnCase, Cellebrite and Volatility.
- Working familiarity with EDR and incident response platforms including Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne and Carbon Black.
- Ability to analyze logs using SIEM and log analytics platforms such as Splunk, Elastic, Microsoft Sentinel and QRadar.
- Basic understanding of network and packet analysis tools including Wireshark, NetFlow analyzers and related investigation utilities.
- Awareness of malware analysis and triage tools such as KAPE, sandbox platforms, VirusTotal and OTX. 3. Required Skills and Competencies
- Strong understanding of Windows and Linux internals, Active Directory and common cloud platforms such as AWS and Azure.
- Knowledge of common cyber-attack techniques, including phishing, ransomware,



credential theft and lateral movement.
- Ability to review logs, identify anomalies and correlate suspicious activities across multiple evidence sources.
- Basic scripting capability in PowerShell or Python to support investigation automation and data analysis.
- Solid analytical, troubleshooting and communication skills during incident response activities.
- Ability to work under pressure while maintaining attention to detail in evidence handling and documentation. 4. Experience Qualifications
- 2-4 years of experience in DFIR investigations.
- Bachelor s degree in IT/CS or equivalent experience.
- Preferred certifications: o GIAC GCIH / GCFA o CEH/ CHFI o Tool specific such as EnCE and FTK AccessData Certified Examiner, or in any SIEM tool related.

Skills and attributes

To qualify for the role you must have

Qualification

- Bachelor of Technology in Computer Science

Experience

- Frontend Development (2+ years)

What we look for

People with the ability to work in a collaborative manner to provide services across multiple client departments while following the commercial and legal requirements. You will need a practical approach to solving issues and complex problems with the ability to deliver insightful and practical solutions. We look for people who are agile, curious, mindful, and able to sustain positive energy, while being adaptable and creative in their approach.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Consultant (Gurugram)
🏢 EY
📍 Gurugram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: consultant (gurugram) / gurugram