DFIR Analyst (Delhi)

DFIR Analyst (Delhi)

10 Sep
|
Innefu Labs
|
Delhi

10 Sep

Innefu Labs

Delhi

DFIR Analyst – Digital Forensics s Incident Response

Experience: 2–3 Years | Full-time | Cybersecurity / DFIR

Job Summary

We are seeking a motivated and hands-on DFIR Analyst with 2–3 years of experience in digital forensics, incident response, security operations, or related cybersecurity functions. The candidate will investigate security incidents across Windows, Linux, and macOS environments, perform endpoint and log analysis, correlate forensic evidence with SIEM/EDR telemetry, identify indicators of compromise, and support containment and remediation activities.

Key Responsibilities

- Perform triage, investigation, and analysis of cybersecurity incidents across Windows, Linux, and macOS endpoints and servers.
- Analyze Windows artifacts including EVTX, Registry, Prefetch, AmCache, ShimCache, SRUM, Scheduled Tasks, Services, Autoruns, browser artifacts, PowerShell logs, and other relevant artifacts.
- Analyze Linux artifacts including system/authentication logs, shell history, cron jobs, systemd services, SSH activity, user accounts, processes, network configuration, and persistence mechanisms.
- Analyze macOS artifacts including Unified Logs, plist files, LaunchAgents, LaunchDaemons, login items, browser artifacts, user activity, and APFS-related evidence.
- Perform basic memory forensics and volatile-data analysis using tools such as Volatility or equivalent tooling.
- Investigate suspicious files, scripts, processes, persistence mechanisms, and malware behavior; perform basic static and dynamic malwaretriage.
- Extract, validate, and correlate IOCs including hashes, domains,



URLs, IP addresses, filenames, registry keys, user accounts, and process indicators.
- Build investigation timelines and reconstruct attack activity by correlating endpoint, network, authentication, and security telemetry.
- Support threat hunting activities using SIEM, EDR, threat intelligence, forensic artifacts, and MITRE ATTCCK-based hypotheses.
- Contribute to the development and improvement of DFIR playbooks, investigation procedures, detection use cases, and automation opportunities.

Technical Skills s Qualifications

- 2–3 years of hands-on experience in DFIR, incident response, SOC, threat hunting, cybersecurity operations, or digital forensics.
- Strong understanding of digital forensics and file systems, including NTFS, FAT/exFAT, ext4, and APFS, with practical knowledge of forensic artifacts and metadata.
- Hands-on experience with forensic and security tools such as Magnet AXIOM, FTK, EnCase, X-Ways, KAPE, Velociraptor, Autopsy, EDR/XDR, or equivalent platforms.
- Strong understanding of incident response, malware, IOCs, MITRE ATTCCK, and attacker TTPs, including persistence, credential theft, lateral movement, C2, and data exfiltration.
- Positive analytical,



investigative, communication, and problem-solving skills, with basic scripting/querying knowledge in Python, PowerShell, Bash, KQL, SPL, SQL, or equivalent.

Stakeholder s Communication Responsibilities

- Collaborate with SOC, Incident Response, IT, Security Engineering, and management teams during investigations.
- Clearly communicate incident severity, impact, forensic findings, evidence, and recommended next steps to technical and non-technical stakeholders.
- Participate in client/customer calls, investigation briefings, technical discussions, and post-incident reviews as required.

Education s Certifications

- Bachelor’s degree in computer science, Information Technology, Cybersecurity, Electronics, or a related discipline, or equivalent practical experience.
- Relevant certifications are preferred but not mandatory, such as Security+, CEH, CHFI, GCIH, GCFE, GCFA, SC-200, or equivalent.
- Practical hands-on DFIR experience, labs, projects, or relevant professional experience may be considered in place of certifications.

Preferred Additional Exposure

- Threat intelligence platforms and IOC enrichment.
- Cloud security and incident response involving AWS, Azure, or Microsoft 365.
- SOAR platforms and security automation.
- YARA, Sigma, or other detection-rule concepts.
- Vulnerability and exposure-management concepts.
- Container or server forensics.
- Experience with ransomware, phishing, credential compromise, insider-threat, or data-exfiltration investigations.

📌 DFIR Analyst (Delhi)
🏢 Innefu Labs
📍 Delhi

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: dfir analyst (delhi) / delhi