DFIR , Forensics , SOC, VAPT

Open 32d

Job Title: DFIR Analyst (Digital Forensics, Forensic Investigation, and Incident Response)

Department: Security Command Centre
Reports To: Director or SOC Head
Location: Goregaon West, Mumbai
Job Type: Full-Time


Job Summary:

We are seeking an experienced and detail-oriented DFIR Analyst to join our cybersecurity team. This role focuses on digital forensics, forensic investigations, and incident response activities. The ideal candidate will investigate and analyze security incidents, perform in-depth forensic examinations of digital systems, and support legal and compliance processes as needed. This position is critical in uncovering root causes, supporting recovery, and improving our organization’s threat resilience.

Key Responsibilities:

1. Incident Response

  • Lead or support the containment, eradication, and recovery of cybersecurity incidents including malware infections, data exfiltration, privilege abuse, and APT activity.
  • Coordinate with stakeholders across IT, SOC, Legal, and Risk during active incidents.
  • Document incident timelines and create post-mortem reports with root cause analysis.

2. Forensic Investigation & Digital Forensics

  • Collect, preserve, and analyze digital evidence in a forensically sound manner, ensuring chain of custody.
  • Conduct forensic investigations of compromised endpoints, servers, cloud systems, email, and mobile devices.
  • Use forensic tools (e.g., EnCase, FTK, X-Ways, Autopsy, Sleuth Kit, Volatility, Velociraptor) to analyze disk, memory, registry, browser artifacts, system logs, and deleted files, for all digital assets.
  • Support internal investigations involving fraud, data leakage, IP theft, or employee misconduct.
  • Work with multiple compliance departments to produce evidence reports and contribute to eDiscovery when required.

3. Threat Analysis

  • Perform static and dynamic malware analysis and reverse engineering.
  • Develop Indicators of Compromise (IOCs), analyze TTPs using MITRE ATT&CK framework.
  • Collaborate with threat intelligence teams to enrich investigations with contextual insights.

4. Post-Incident Review & Process Improvement

  • Create detailed incident and investigation reports for technical and executive audiences.
  • Recommend preventive controls, detection improvements, and SOC playbook updates.
  • Maintain forensic investigation procedures aligned with legal, compliance, and regulatory needs.

Required Skills & Qualifications:

  • Bachelor’s degree in Cybersecurity, Digital Forensics, Computer Science, or a related field.
  • 4+ years of experience in DFIR, forensic investigation, or cyber threat analysis roles.
  • Proficient with forensic tools such as EnCase, FTK, Autopsy, X-Ways, Volatility, Sleuth Kit, Velociraptor.
  • Hands-on experience with EDR, SIEM, and log analysis, Malware analysis etc.. platforms
  • In-depth knowledge of OS internals (Windows, Linux, macOS), file systems, memory structure, and network protocols.
  • Familiarity with legal protocols for evidence handling and regulatory compliance.

Preferred Certifications:

  • GCFA – GIAC Certified Forensic Analyst
  • CHFI – Computer Hacking Forensic Investigator
  • GCIH / GCIA / GNFA – GIAC Incident or Network Forensic Certifications
  • OSCP / CCFP / EnCE / CFCE – (Bonus)

Key Competencies:

  • Strong investigative and analytical mindset
  • Excellent communication and documentation skills
  • Able to work independently under pressure and during live incidents
  • Familiar with chain of custody, litigation support, and legal evidence standards