09 Sep
|
Aptita Consulting Partners
|
Secunderabad
09 Sep
Aptita Consulting Partners
Secunderabad
Job Summary
The Senior Forensic Analyst leads forensic analysis for assigned projects, working closely with forensic leads and other analysts to perform both triage-level and advanced forensic investigations.
The role focuses on identifying threat actor behavior, unauthorized access, ransomware activity, and how a cyber intrusion occurred. The analyst will investigate digital evidence, identify Indicators of Compromise (IOCs) and attacker Tactics, Techniques, and Procedures (TTPs), and develop a clear timeline of the incident.
Roles & Responsibilities
- Lead forensic analysis supporting ransomware and cyber-compromise investigations.
- Perform forensic analysis of operating system artifacts and recover deleted data.
- Conduct forensic investigations across Windows, Linux/Unix, Mac, and RAM/memory.
- Analyze network and operating system logs, including:
- Windows Event Logs
- Unified Audit Logs
- Firewall Logs
- VPN Logs
- Other security and system logs
- Work with the Security Operations Center (SOC) and leverage data from Endpoint Detection and Response (EDR) solutions.
- Identify Indicators of Compromise (IOCs) and attacker Tactics, Techniques, and Procedures (TTPs).
- Prepare explicit forensic findings and investigative updates, including a timeline of events.
- Use incident-mapping frameworks such as MITRE ATT&CK; and the Lockheed Martin Cyber Kill Chain.
- Prepare and review forensic investigation reports, investigative updates, and appendices.
- Perform peer reviews of reports prepared by other analysts.
- Support the forensic lead in managing investigation timelines, delivery, and execution.
- Work independently and prioritize tasks across multiple investigations.
Skills & Technical Knowledge
Strong knowledge of:
- Windows disk forensics
- Linux/Unix disk forensics
- Memory/RAM forensics
- Network Security Monitoring (NSM)
- Network traffic analysis
- Log analysis
- Enterprise security controls
Forensic & Security Tools
Hands-on experience with tools such as:
- EnCase
- Axiom
- FTK
- X-Ways
- SIFT
- Splunk
- Redline
- Volatility
- Wireshark
- TCPDump
- Open-source forensic tools
- EDR platforms, preferably SentinelOne
Preferred Qualifications
- Experience presenting technical findings to non-technical audiences.
- Experience leading or mentoring forensic analysts.
- Robust report-writing and documentation skills.
- Experience handling PII, PHI, confidential, sensitive, and proprietary data.
- Experience with cyber insurance investigations.
- Strong analytical, problem-solving, and critical-thinking skills.
- Excellent verbal and written communication skills.
- Ability to work independently with minimal supervision.
- Proficiency in Microsoft Office/Suite products.
Education & Experience
Required
- Bachelor's degree in Information Security, Computer Science, Digital Forensics, Cybersecurity, or a related field with 4+ years of Incident Response or Digital Forensics experience.
OR
- Master's/Advanced degree with 3+ years of relevant experience.
Certifications
Candidate must possess at least 2 of the following certifications:
- Security+
- Network+
- SANS GCED
- GCIH
- GCFE
- GCFA
- CEH
- CHFI
- EnCE
Ideal Candidate Profile
The ideal candidate will have:
4+ years of DFIR / Digital Forensics experience
- Ransomware / Cyber Incident Investigation
- Windows & Linux Forensics
- Memory Forensics
- Network & Log Analysis
- EDR/SOC experience
- Forensic tools such as EnCase/FTK/Axiom/Volatility/Wireshark
- MITRE ATT&CK; / Cyber Kill Chain
- At least 2 relevant certifications
📌 Senior Forensic Analyst (Secunderabad)
🏢 Aptita Consulting Partners
📍 Secunderabad