Cyber Incident Responder (Incident Management) (Delhi)

Cyber Incident Responder (Incident Management) (Delhi)

24 Sep
|
Elfonze Technologies
|
Delhi

24 Sep

Elfonze Technologies

Delhi

Job Title - Cyber Incident Responder (Incident Management)

Job Summary

We are seeking an experienced Cyber Incident Responder whose primary mandate is to contain and recover from security incidents swiftly and effectively, minimizing damage, downtime, and business impact — followed by thorough Root Cause Analysis (RCA) and Incident Reporting to prevent recurrence.

Using

CrowdStrike XDR, SIEM, Forcepoint DLP, Fortinet Proxy, and Fortinet WAF, this role is the front line of defence once a threat is confirmed, and the owner of documenting what happened, why, and how to stop it happening again.

Key Responsibilities (In Priority Order)

1. Incident Containment (Primary Responsibility)

· Take immediate, decisive action to isolate compromised hosts, accounts, or network segments to stop lateral movement and further damage.

· Use CrowdStrike XDR to isolate infected endpoints, kill malicious processes, and block malicious hashes/IOCs in real time.

· Block malicious IPs, URLs, and domains via Fortinet Proxy and Fortinet WAF to cut off command-and-control (C2) communication and active attack traffic.

· Trigger and enforce Forcepoint DLP blocking actions to stop active data exfiltration attempts.

· Coordinate with network, infrastructure, and application teams to execute emergency containment actions (e.g., firewall rule changes, account disablement, network segmentation).

· Make fast, risk-based containment decisions under pressure, balancing business continuity against threat severity.

2. Recovery & Restoration (Primary Responsibility)

· Lead remediation efforts to eliminate the root cause — removing malware, closing exploited vulnerabilities, resetting compromised credentials.

· Validate system integrity before restoring affected endpoints, applications, or services to production.

· Work with IT/Infra teams to restore data from clean backups where required, ensuring no reinfection.

· Re-enable and monitor previously isolated systems closely post-recovery to confirm the threat is fully neutralized.

· Verify that DLP, proxy, WAF, and endpoint policies are restored/tuned appropriately after the incident, avoiding residual exposure.

· Confirm business services are fully operational and communicate recovery status to stakeholders.

3. Root Cause Analysis (RCA) Preparation

· Conduct detailed post-incident investigation to determine the root cause, entry point, attack vector, and scope of impact (systems/users/data affected).

· Reconstruct the full attack timeline using logs from CrowdStrike XDR, SIEM, Forcepoint DLP, Fortinet Proxy, and Fortinet WAF.

· Identify contributing factors — control gaps, policy misconfigurations, missing patches, human error — that allowed the incident to occur.

· Determine why the incident was/wasn't detected earlier and assess detection/response effectiveness.

· Document clear, evidence-backed conclusions and map findings to the MITRE ATT&CK; framework where applicable.

· Recommend specific corrective and preventive actions (CAPA)



to eliminate the root cause and reduce recurrence risk.

· Present RCA findings to SOC leadership and relevant stakeholders (IT, application owners, compliance) for sign-off.

4. Incident Report Preparation

· Prepare comprehensive, well-structured incident reports for every confirmed incident, including:

o Incident summary, severity, and classification o Detection source and timeline (detected → contained → recovered)

o Affected systems, users, and data o Containment and recovery actions taken, with timestamps o Root cause and contributing factors o Business impact assessment (downtime, data loss, financial/reputational impact)

o Corrective and preventive action (CAPA) recommendations with ownership and timelines

· Prepare executive summaries for leadership with key metrics (MTTD, MTTC, MTTR) and business-relevant impact in non-technical language.

· Maintain an incident report repository/log for audit, compliance, and trend-analysis purposes.

· Ensure reports meet internal quality standards and any regulatory/compliance reporting obligations (ISO 27001, PCI-DSS, GDPR breach notification timelines, etc., as applicable).

· Track closure of CAPA items from RCA reports and report on their implementation status.

5. Detection, Investigation & Monitoring

· Monitor and triage alerts from CrowdStrike XDR, SIEM, Forcepoint DLP, Fortinet Proxy, and Fortinet WAF to identify genuine incidents needing containment.

· Investigate the attack timeline, entry point, and scope to inform containment and recovery decisions.

· Analyze logs across endpoint, network, proxy, WAF, and DLP sources to trace attacker activity and confirm full eradication.

6. Incident Management (Process & SLA Ownership)

· Own incidents end-to-end in the ITSM/ticketing system, ensuring containment, recovery, RCA, and reporting SLAs are all met.

· Document containment and recovery actions in real time during active incidents to support accurate RCA and reporting afterward.

· Communicate incident status, and later RCA/report findings, clearly and promptly to leadership.

7. Preventive & Continuous Improvement Activities

· Maintain and refine incident response playbooks/runbooks for containment, recovery, RCA, and reporting per threat type (ransomware, data exfiltration, web attack, etc.).

· Recommend policy tuning across CrowdStrike, SIEM, Forcepoint DLP, Fortinet Proxy, and WAF based on RCA findings to reduce future incidents.

· Participate in tabletop exercises and simulations, including RCA/reporting readiness drills.

· Support audits and compliance requirements related to incident handling, RCA, and reporting documentation.





Required Skills & Qualifications

1. Technical Skills

· Proven hands-on experience executing containment actions in CrowdStrike Falcon XDR (host isolation, Real-Time Response, process/network containment).

· Experience actively blocking threats via Fortinet Proxy and Fortinet WAF (URL/IP blocking, rule changes, attack mitigation).

· Experience enforcing Forcepoint DLP blocking policies during live data-loss incidents.

· Strong SIEM skills for rapid investigation, log correlation, and evidence-gathering to support RCA (Splunk, QRadar, Sentinel, or similar).

· Solid understanding of system recovery processes — backup/restore, credential rotation, patching, and validation testing.

· Demonstrated ability to conduct RCA and write clear, structured incident reports for both technical and executive audiences.

· Familiarity with MITRE ATT&CK;, Cyber Kill Chain, and common attack techniques (ransomware, phishing, lateral movement, data exfiltration).

2. Soft Skills

· Ability to remain calm and make rapid, sound decisions under high-pressure, time-critical situations.

· Strong ownership mentality — sees an incident through from containment to full recovery to final report closure.

· Excellent cross-team coordination skills (IT, network, application, business stakeholders) during active incidents.

· Strong analytical and investigative mindset for root cause determination.

· Excellent written communication skills — able to translate technical findings into clear, actionable reports for varied audiences.

Educational Qualifications

· Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field.

· Certifications (Preferred)

· CrowdStrike Certified Falcon Responder (CCFR) / CCFA

· GIAC Certified Incident Handler (GCIH)

· CompTIA CySA+ / Security+

· Fortinet NSE Certifications (NSE 4/5)

· Certified SOC Analyst (CSA)

Experience

· 3–6 years in Cyber Security Operations/Incident Response, with demonstrable experience personally executing containment and recovery actions, and independently preparing RCA and incident reports for live incidents.

Key Performance Indicators (KPIs)

· Mean Time to Contain (MTTC) — primary KPI

· Mean Time to Recover (MTTR) — primary KPI

· RCA turnaround time (incident closure to RCA submission)

· Incident report quality and timeliness (completeness, accuracy, on-time submission)

· Percentage of incidents contained within SLA before escalation/spread

· Successful recovery rate without reinfection/recurrence

· Reduction in repeat/similar incidents attributable to CAPA implementation from RCA

Work Environment

· Requires availability for immediate response during active incidents, including on-call/rotational shifts.

· High-pressure environment during live incidents; calm, decisive action expected.

· Close collaboration with SOC, IT Infra, Network, and Compliance teams during containment, recovery, RCA, and reporting activities.

📌 Cyber Incident Responder (Incident Management) (Delhi)
🏢 Elfonze Technologies
📍 Delhi

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyber incident responder (incident management) (delhi) / delhi