DFIR , Forensics , SOC, VAPT
Job Title: DFIR Analyst (Digital
Forensics, Forensic Investigation, and Incident Response)
Department: Security
Command Centre
Reports To: Director or SOC Head
Location: Goregaon West, Mumbai
Job Type: Full-Time
Job Summary:
We are seeking an
experienced and detail-oriented DFIR Analyst to join our cybersecurity
team. This role focuses on digital forensics, forensic investigations, and
incident response activities. The ideal candidate will investigate and
analyze security incidents, perform in-depth forensic examinations of digital
systems, and support legal and compliance processes as needed. This position is
critical in uncovering root causes, supporting recovery, and improving our
organization’s threat resilience.
Key Responsibilities:
1. Incident
Response
- Lead
or support the containment, eradication, and recovery of cybersecurity
incidents including malware infections, data exfiltration, privilege
abuse, and APT activity.
- Coordinate
with stakeholders across IT, SOC, Legal, and Risk during active incidents.
- Document
incident timelines and create post-mortem reports with root cause
analysis.
2. Forensic
Investigation & Digital Forensics
- Collect,
preserve, and analyze digital evidence in a forensically sound manner,
ensuring chain of custody.
- Conduct forensic investigations of compromised endpoints, servers, cloud
systems, email, and mobile devices.
- Use
forensic tools (e.g., EnCase, FTK, X-Ways, Autopsy, Sleuth Kit, Volatility,
Velociraptor) to analyze disk, memory, registry, browser artifacts, system
logs, and deleted files, for all digital assets.
- Support
internal investigations involving fraud, data leakage, IP theft, or
employee misconduct.
- Work
with multiple compliance departments to produce evidence reports and
contribute to eDiscovery when required.
3. Threat
Analysis
- Perform
static and dynamic malware analysis and reverse engineering.
- Develop
Indicators of Compromise (IOCs), analyze TTPs using MITRE ATT&CK
framework.
- Collaborate
with threat intelligence teams to enrich investigations with contextual
insights.
4. Post-Incident
Review & Process Improvement
- Create
detailed incident and investigation reports for technical and executive
audiences.
- Recommend
preventive controls, detection improvements, and SOC playbook updates.
- Maintain
forensic investigation procedures aligned with legal, compliance, and
regulatory needs.
Required Skills & Qualifications:
- Bachelor’s
degree in Cybersecurity, Digital Forensics, Computer Science, or a related
field.
- 4+
years of experience in DFIR, forensic investigation, or cyber threat
analysis roles.
- Proficient
with forensic tools such as EnCase, FTK, Autopsy, X-Ways, Volatility,
Sleuth Kit, Velociraptor.
- Hands-on
experience with EDR, SIEM, and log analysis, Malware analysis etc..
platforms
- In-depth
knowledge of OS internals (Windows, Linux, macOS), file systems, memory
structure, and network protocols.
- Familiarity
with legal protocols for evidence handling and regulatory compliance.
Preferred Certifications:
- GCFA – GIAC Certified Forensic Analyst
- CHFI – Computer Hacking Forensic Investigator
- GCIH
/ GCIA / GNFA – GIAC Incident or Network Forensic
Certifications
- OSCP
/ CCFP / EnCE / CFCE – (Bonus)
Key Competencies:
- Strong
investigative and analytical mindset
- Excellent
communication and documentation skills
- Able
to work independently under pressure and during live incidents
- Familiar
with chain of custody, litigation support, and legal evidence standards