Overview
We are seeking an experienced cybersecurity professional to take ownership of enterprise incident response, threat investigation, and digital forensics activities within a large-scale technology environment. This position plays a critical role in identifying, investigating, containing, and remediating security threats while driving continuous improvement of detection and response capabilities.
Key Responsibilities
- Direct and coordinate end-to-end response efforts for cybersecurity incidents, including triage, containment, remediation, recovery, and post-incident review.
- Investigate suspicious activity by analyzing security telemetry from systems such as security monitoring platforms, endpoint security solutions, network security controls, and infrastructure logs.
- Conduct forensic investigations on affected devices and systems, including examination of memory, storage media, and network activity while maintaining proper evidence handling procedures.
- Analyze potentially malicious files, scripts, and executables to identify indicators of compromise and support defensive actions.
- Produce comprehensive investigation documentation covering root causes, business impact, attack timelines, and recommended corrective actions.
- Partner with technical and non-technical stakeholders to communicate findings, response status, and risk mitigation strategies.
- Lead proactive threat hunting initiatives to uncover hidden threats and reduce organizational risk exposure.
- Assess existing security controls and recommend enhancements to improve detection, prevention, and response effectiveness.
- Share expertise with internal teams through coaching, knowledge transfer, and incident response best practice guidance.
- Maintain awareness of emerging attack techniques, threat actor behaviors, and evolving security technologies.
Required Qualifications
- Degree in Computer Science, Information Security, Information Technology, or a related discipline, or equivalent qualified experience.
- At least 8 years of hands-on cybersecurity experience, particularly within incident response, threat investigation, detection engineering, or forensic analysis functions.
- Strong practical experience with enterprise security technologies, including security monitoring platforms, endpoint protection and detection solutions, network intrusion detection/prevention systems, vulnerability assessment tools, and firewall technologies.
- Advanced log investigation capabilities, including analysis of operating system, application, and network logs.
- Demonstrated expertise in incident response frameworks, workflows, and operational procedures.
- Experience using automation or scripting languages such as Python, PowerShell, or Bash to improve security operations efficiency.
- Strong accountability, initiative, and ownership mindset.
- Excellent analytical, troubleshooting, communication, and decision-making skills.
- Ability to remain effective during high-severity incidents and manage multiple investigations simultaneously.
Preferred Qualifications
- Industry-recognized cybersecurity certifications such as CISSP, GCIH, OSCP, CEH, or similar credentials.
- Experience operating within or supporting a Security Operations Center environment, including handling escalated security cases.
- Hands-on proficiency with forensic investigation platforms and malware analysis technologies.
- Experience investigating security incidents involving cloud infrastructure and cloud-native services.
- Familiarity with threat intelligence methodologies and adversary behavior frameworks such as MITRE ATT&CK.;
- Ability to work effectively in global environments with diverse stakeholders.
📌 Sr Incident Response & Digital Forensics Analyst (India)
🏢 Huxley
📍 India