08 Oct
|
Persistent
|
Mumbai
Job Description
About Persistent
We are an AI-led, platform-driven Digital Engineering and Enterprise Modernization partner, combining deep technical expertise and industry experience to help our clients anticipate what’s next. Our offerings and proven solutions create a unique competitive advantage for our clients by giving them the power to see beyond and rise above. We work with many industry-leading organizations across the world, including 20 Fortune 50 companies and 4 of the 5 top banks in both the US and India, and numerous innovators across the healthcare ecosystem.
Our disruptor’s mindset, commitment to client success, and agility to thrive in the dynamic environment have enabled us to sustain our growth momentum. Persistent has been recognized across top industry platforms for innovation, leadership, and inclusion. We reported $1,654.4M FY26 revenue with 17.4% Y-o-Y growth. We have delivered 24 sequential quarters of growth with $436.0M in Q4 FY26 revenue, up 3.2% Q-o-Q and 16.2% Y-o-Y growth. Our 27,500+ global team members, located in 18 countries, have been instrumental in helping the market leaders transform their industries. We have been recognized as the Fastest Growing IT Services Brand Globally in the 2026 Brand Finance IT Services 25 Report. We named a Leader in the Everest Group Private Equity (PE) Services PEAK Matrix® Assessment 2026 and Software Product Engineering PEAK Matrix® Assessment 2026.
About Position:
We are seeking an experienced DFIR Specialist with a strong background in Identity and Access Management (IAM) and Entra ID to join our cybersecurity team. The ideal candidate will play a critical role in supporting cybersecurity incident investigations, digital forensics, threat analysis, and incident response activities. You will be responsible for investigating security incidents, collecting and analyzing forensic evidence, determining root causes and impacts, and supporting containment and remediation efforts.
-
Role: DFIR Specialist
- Location: Mumbai
- Experience: 8 to 12 Years
- Job Type: Full-Time Employment
What You'll Do:
- Investigate cybersecurity incidents including malware infections, account compromises, phishing attacks, ransomware incidents, and suspicious activities.
- Perform forensic acquisition and analysis of endpoints, servers, logs, and digital evidence.
- Conduct incident triage, containment, eradication, recovery,
and post-incident reviews.
- Perform memory, disk, file-system, network, and log analysis during investigations.
- Identify Indicators of Compromise (IOCs), determine attack vectors, and assess affected assets.
- Conduct detailed timeline analysis and reconstruct attacker activities during security incidents.
- Support proactive threat hunting and investigate suspicious behaviors across enterprise environments.
- Collaborate with SOC, Security Engineering, Infrastructure, Cloud, and Application teams during incident response activities.
- Maintain proper evidence handling procedures and chain-of-custody documentation.
- Prepare incident investigation reports, technical findings, root-cause analyses, and remediation recommendations.
- Contribute to DFIR procedures, incident response playbooks, and continuous improvement initiatives.
- Support security operations during critical incidents and major investigations.
Expertise You'll Bring:
- Strong expertise in Digital Forensics and Incident Response (DFIR).
- Extensive experience in Cyber Incident Investigation and Security Operations.
- Deep knowledge of Identity and Access Management (IAM) and Microsoft Entra ID.
- Expertise in endpoint and host-based forensic investigations.
- Robust experience in Windows and Linux forensic analysis.
- Hands-on experience with disk, memory, file-system, network, and log analysis.
- Strong understanding of incident response lifecycle, investigation methodologies, and evidence handling.
- Experience with malware analysis, IOC analysis, and threat actor activity investigations.
- Experience using SIEM and EDR platforms for security investigations.
- Deep understanding of MITRE ATT&CK; framework and adversary tactics, techniques, and procedures.
- Scripting and automation experience using PowerShell, Python, or similar technologies.
- Knowledge of cloud security investigations across Azure, AWS, and GCP environments.
- Hands-on experience investigating enterprise-level cybersecurity incidents.
- Familiarity with memory forensics,
disk forensics, and advanced threat-hunting techniques.
- Experience using forensic tools such as EnCase, FTK, Volatility, and related DFIR platforms.
- Experience working with CrowdStrike Falcon, Microsoft Defender, Microsoft Sentinel, Splunk, and similar security solutions.
- Strong analytical, troubleshooting, and problem-solving capabilities.
- Excellent documentation, reporting, and stakeholder communication skills.
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related discipline is preferred.
- Certifications such as GCFA, GCFE, GCIH, CHFI, Security+, CISSP, or equivalent are advantageous.
- Strong commitment to incident response excellence, continuous learning, and cybersecurity best practices.
Benefits:
- Competitive salary and benefits package
- Culture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certifications
- Opportunity to work with cutting-edge technologies
- Employee engagement initiatives such as project parties, flexible work hours, and Long Service awards
- Annual health check-ups
- Insurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parents
Values-Driven, People-Centric & Inclusive Work Environment:
Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds.
- We support hybrid work and flexible hours to fit diverse lifestyles.
- Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.
- If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employment
Let’s unleash your full potential at Persistent - persistent.com/careers
“Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind.”
1
Open Positions
Identity and Access Management-Entra ID,Security testing
Skills Required
Mumbai
Location
Identity and Access Management-Entra ID,Security testing
Desirable Skills
188649
Job Code
📌 DFIR Specialist (Mumbai)
🏢 Persistent
📍 Mumbai