Sattrix Information Security
Website:
sattrix.com
Job details:
Role: Digital Forensics & Incident Response (DFIR) Lead
Location: Navi Mumbai (Onsite)
6 days working (2nd & 4th Saturday off)
Regular Shift: 10:30 - 6:30
Position Summary:
We are hiring Digital Forensics & Incident Response (DFIR) professionals to support in detecting, investigating, containing, and responding to cybersecurity incidents. The selected candidates will work on digital forensic investigations, malware analysis, incident response, threat hunting, attack reconstruction, and cyber crisis management to strengthen the security posture.
Depending on experience and technical expertise, candidates will contribute to incident triage, forensic evidence collection, advanced investigations, malware analysis, cloud forensics, ransomware response, DFIR automation, and enterprise incident response strategy.
Candidates with 8–12+ years of relevant DFIR or Incident Response experience are encouraged to apply. Roles will be aligned based on technical evaluation and requirements.
Key Responsibilities:
Incident Detection & Response
• Monitor, triage, and investigate security incidents received from SIEM, EDR, NDR, XDR, email security, cloud security platforms, and threat intelligence feeds.
• Validate security alerts, assess incident severity, and support timely incident response.
• Perform evidence collection from Windows, Linux, Active Directory, cloud platforms, endpoints, firewalls, and network devices.
• Collect and preserve forensic artifacts including event logs, registry hives, memory dumps, disk images, browser history, scheduled tasks, startup entries, endpoint telemetry, and network connections.
• Maintain proper chain of custody and forensic evidence handling procedures.
• Perform IOC validation using threat intelligence platforms.
• Execute containment actions such as endpoint isolation, account disablement, malicious process termination, and IP blocking.
• Investigate phishing campaigns, malicious attachments, and Business Email Compromise (BEC) incidents.
• Document incidents throughout the investigation lifecycle and prepare operational reports.
Advanced Investigation & Forensics
• Lead investigations involving malware, ransomware, insider threats, cloud compromises, identity attacks, data exfiltration, and advanced cyber incidents.
• Perform host, memory, disk, network, cloud, and mobile forensics (where applicable).
• Conduct malware triage and behavioral analysis.
• Investigate persistence mechanisms, privilege escalation, lateral movement, credential theft, PowerShell activity, WMI abuse, scheduled tasks, Kerberos attacks, Pass-the-Hash, and command-and-control communications.
• Correlate endpoint, identity, network, and cloud telemetry to reconstruct attack timelines.
• Develop containment, eradication, recovery, and root cause analysis reports.
• Support Threat Hunting, Detection Engineering, Purple Team, Legal, Compliance, Audit, and Regulatory investigations.
Enterprise Incident Response Leadership
• Lead enterprise incident response for high-severity cybersecurity incidents.
• Direct investigations involving ransomware, nation-state attacks, APT campaigns, supply chain attacks, insider threats, cloud breaches, and zero-day exploitation.
• Develop and maintain enterprise incident response frameworks, forensic standards, playbooks, and crisis communication plans.
• Coordinate with SOC, Threat Intelligence, Red Team, IT Operations, Cloud Teams, Legal, Compliance, Privacy, Risk, HR, and Executive Leadership.
• Drive DFIR automation using SOAR and orchestration platforms.
• Conduct tabletop exercises, cyber crisis simulations, and post-incident reviews.
• Develop DFIR metrics, executive dashboards, lessons learned programs, and maturity roadmaps.
• Mentor junior analysts and contribute to capability development across the DFIR function.
Technical Expertise:
Candidates should have knowledge or experience in one or more of the following areas:
- Incident Response & Investigation
Incident Triage, Digital Forensics, Malware Analysis, Ransomware Investigation, Business Email Compromise (BEC), Insider Threat Investigation, Cloud Incident Response, Identity & Access Investigations, Threat Hunting, Root Cause Analysis, Attack Timeline Reconstruction, Incident Containment & Recovery.
Windows Forensics, Linux Forensics, Memory Forensics, Disk Forensics, Network Forensics, Cloud Forensics, Microsoft 365 Investigations, Azure / Entra ID Investigations, AWS CloudTrail Analysis, Evidence Collection & Preservation.
SIEM Analysis, EDR/XDR Investigation, IOC Analysis, Log Analysis, MITRE ATT&CK, MITRE D3FEND, Threat Intelligence Correlation.
Preferred Tools:
Candidates should have experience with some or more of the following:
Microsoft Defender XDR, Microsoft Sentinel, CrowdStrike Falcon, SentinelOne, Cortex XDR, Splunk, IBM QRadar, Velociraptor, FTK Imager, FTK, EnCase, Magnet AXIOM, Autopsy, Volatility, Rekall, KAPE, Hayabusa, Plaso, Timesketch, Wireshark, NetworkMiner, CyberChef, VirusTotal, MISP, Cortex XSOAR, Splunk SOAR, ServiceNow Security Operations.
Required Skills:
Digital Forensics, Incident Response, Malware Analysis, Memory & Disk Forensics, Network Forensics, Cloud Forensics, Threat Hunting, SIEM & EDR Analysis, IOC Analysis, Windows & Linux Internals, Active Directory Security, Networking Fundamentals, MITRE ATT&CK Framework, Evidence Preservation & Chain of Custody, Root Cause Analysis, Cyber Crisis Management (Lead Roles), SOAR & Security Automation (Lead Roles), Executive Communication (Lead Roles).
Email - kirti.rustagi@siliconcomnet.com
Click on Apply to know more.