28 Sep
|
Important Business
|
New Delhi
28 Sep
Important Business
New Delhi
Job
Title - Cyber Incident Responder (Incident Management)
Job
Summary
We
are seeking an experienced Cyber Incident Responder whose primary mandate is to
contain and recover from security incidents swiftly and effectively, minimizing
damage, downtime, and business impact — followed by thorough Root Cause
Analysis (RCA) and Incident Reporting to prevent recurrence. Using CrowdStrike
XDR, SIEM, Forcepoint DLP, Fortinet Proxy, and Fortinet WAF, this role is the
front line of defence once a threat is confirmed, and the owner of documenting
what happened, why, and how to stop it happening again.
Key
Responsibilities (In Priority Order)
1. Incident Containment (Primary Responsibility)
· Take
immediate, decisive action to isolate compromised hosts, accounts, or network
segments to stop lateral movement and further damage.
· Use
CrowdStrike XDR to isolate infected endpoints, kill malicious processes, and
block malicious hashes/IOCs in real time.
· Block
malicious IPs, URLs, and domains via Fortinet Proxy and Fortinet WAF to cut off
command-and-control (C2) communication and active attack traffic.
· Trigger
and enforce Forcepoint DLP blocking actions to stop active data exfiltration
attempts.
· Coordinate
with network, infrastructure, and application teams to execute emergency
containment actions (e.g., firewall rule changes, account disablement, network
segmentation).
· Make
fast, risk-based containment decisions under pressure, balancing business
continuity against threat severity.
2. Recovery & Restoration (Primary Responsibility)
· Lead
remediation efforts to eliminate the root cause — removing malware, closing
exploited vulnerabilities, resetting compromised credentials.
· Validate
system integrity before restoring affected endpoints, applications, or services
to production.
· Work
with IT/Infra teams to restore data from clean backups where required, ensuring
no reinfection.
· Re-enable
and monitor previously isolated systems closely post-recovery to confirm the
threat is fully neutralized.
· Verify
that DLP, proxy, WAF, and endpoint policies are restored/tuned appropriately
after the incident, avoiding residual exposure.
· Confirm
business services are fully operational and communicate recovery status to
stakeholders.
3. Root Cause Analysis (RCA) Preparation
· Conduct
detailed post-incident investigation to determine the root cause, entry point,
attack vector, and scope of impact (systems/users/data affected).
· Reconstruct
the full attack timeline using logs from CrowdStrike XDR, SIEM, Forcepoint DLP,
Fortinet Proxy, and Fortinet WAF.
· Identify
contributing factors — control gaps, policy misconfigurations, missing patches,
human error — that allowed the incident to occur.
· Determine
why the incident was/wasn't detected earlier and assess detection/response
effectiveness.
· Document
clear, evidence-backed conclusions and map findings to the MITRE ATT&CK;
framework where applicable.
· Recommend
specific corrective and preventive actions (CAPA) to eliminate the root cause
and reduce recurrence risk.
· Present
RCA findings to SOC leadership and relevant stakeholders (IT, application
owners, compliance) for sign-off.
4. Incident Report Preparation
· Prepare
comprehensive, well-structured incident reports for every confirmed incident,
including:
o Incident summary,
severity, and classification
o Detection source and
timeline (detected → contained → recovered)
o Affected systems,
users, and data
o Containment and
recovery actions taken, with timestamps
o Root cause and
contributing factors
o Business impact
assessment (downtime, data loss, financial/reputational impact)
o Corrective and
preventive action (CAPA) recommendations with ownership and timelines
· Prepare
executive summaries for leadership with key metrics (MTTD, MTTC, MTTR) and
business-relevant impact in non-technical language.
· Maintain
an incident report repository/log for audit, compliance, and trend-analysis
purposes.
· Ensure
reports meet internal quality standards and any regulatory/compliance reporting
obligations (ISO 27001, PCI-DSS, GDPR breach notification timelines, etc., as
applicable).
· Track
closure of CAPA items from RCA reports and report on their implementation
status.
5. Detection, Investigation & Monitoring
· Monitor
and triage alerts from CrowdStrike XDR, SIEM, Forcepoint DLP, Fortinet Proxy,
and Fortinet WAF to identify genuine incidents needing containment.
· Investigate
the attack timeline, entry point, and scope to inform containment and recovery
decisions.
· Analyze
logs across endpoint, network, proxy, WAF, and DLP sources to trace attacker
activity and confirm full eradication.
6. Incident Management (Process & SLA Ownership)
· Own
incidents end-to-end in the ITSM/ticketing system, ensuring containment,
recovery, RCA, and reporting SLAs are all met.
· Document
containment and recovery actions in real time during active incidents to
support accurate RCA and reporting afterward.
· Communicate
incident status, and later RCA/report findings, clearly and promptly to
leadership.
7. Preventive & Continuous Improvement Activities
· Maintain
and refine incident response playbooks/runbooks for containment, recovery, RCA,
and reporting per threat type (ransomware, data exfiltration, web attack,
etc.).
· Recommend
policy tuning across CrowdStrike, SIEM, Forcepoint DLP, Fortinet Proxy, and WAF
based on RCA findings to reduce future incidents.
· Participate
in tabletop exercises and simulations, including RCA/reporting readiness
drills.
· Support
audits and compliance requirements related to incident handling, RCA, and
reporting documentation.
Required
Skills & Qualifications
1. Technical Skills
· Proven
hands-on experience executing containment actions in CrowdStrike Falcon XDR
(host isolation, Real-Time Response, process/network containment).
· Experience
actively blocking threats via Fortinet Proxy and Fortinet WAF (URL/IP blocking,
rule changes, attack mitigation).
· Experience
enforcing Forcepoint DLP blocking policies during live data-loss incidents.
· Solid
SIEM skills for rapid investigation, log correlation, and evidence-gathering to
support RCA (Splunk, QRadar, Sentinel, or similar).
· Solid
understanding of system recovery processes — backup/restore, credential
rotation, patching, and validation testing.
· Demonstrated
ability to conduct RCA and write clear, structured incident reports for both
technical and executive audiences.
· Familiarity
with MITRE ATT&CK;, Cyber Kill Chain, and common attack techniques
(ransomware, phishing, lateral movement, data exfiltration).
2. Soft Skills
· Ability
to remain calm and make fast, sound decisions under high-pressure,
time-critical situations.
· Strong
ownership mentality — sees an incident through from containment to full
recovery to final report closure.
· Excellent
cross-team coordination skills (IT, network, application, business
stakeholders) during active incidents.
· Strong
analytical and investigative mindset for root cause determination.
· Excellent
written communication skills — able to translate technical findings into clear,
actionable reports for varied audiences.
Educational
Qualifications
· Bachelor's
degree in Computer Science, Information Technology, Cybersecurity, or related
field.
· Certifications
(Preferred)
· CrowdStrike
Certified Falcon Responder (CCFR) / CCFA
· GIAC
Certified Incident Handler (GCIH)
· CompTIA
CySA+ / Security+
· Fortinet
NSE Certifications (NSE 4/5)
· Certified
SOC Analyst (CSA)
Experience
· 3–6
years in Cyber Security Operations/Incident Response, with demonstrable
experience personally executing containment and recovery actions, and
independently preparing RCA and incident reports for live incidents.
Key
Performance Indicators (KPIs)
· Mean
Time to Contain (MTTC) — primary KPI
· Mean
Time to Recover (MTTR) — primary KPI
· RCA
turnaround time (incident closure to RCA submission)
· Incident
report quality and timeliness (completeness, accuracy, on-time submission)
· Percentage
of incidents contained within SLA before escalation/spread
· Successful
recovery rate without reinfection/recurrence
· Reduction
in repeat/similar incidents attributable to CAPA implementation from RCA
Work
Environment
· Requires
availability for immediate response during active incidents, including
on-call/rotational shifts.
· High-pressure
environment during live incidents; calm, decisive action expected.
· Close
collaboration with SOC, IT Infra, Network, and Compliance teams during
containment, recovery, RCA, and reporting activities.
📌 Cyber Incident Responder (Incident Management) (New Delhi)
🏢 Important Business
📍 New Delhi