Overview:Responsible for investigating cybersecurity incidents, performing digital forensic investigations, and supporting enterprise incident response activities to protect the organization's critical assets. The role focuses on Digital Forensics, Incident Response (DFIR), Evidence Collection, Malware Analysis, Threat Hunting, and Root Cause Analysis to identify, contain, eradicate, and recover from security incidents while preserving forensic integrity and strengthening the organization's overall security posture.
Key Responsibilities:Investigate cybersecurity incidents by performing Incident Investigation, Host Analysis, Network Analysis, and Breach Analysis across endpoints, servers, cloud environments, and enterprise networks. Lead or support incident response activities throughout the incident lifecycle, including identification, triage, threat containment, eradication, recovery, and post-incident analysis. Perform Evidence Collection, Artifact Collection, Forensic Imaging, and Disk Imaging while maintaining Chain of Custody and forensic integrity. Conduct Memory Analysis and Memory Dump Analysis to identify malicious activity, persistence mechanisms, and attacker techniques. Perform Disk Forensics, Windows Forensics, Linux Forensics, and Network Forensics to determine the scope and impact of security incidents. Investigate malware, ransomware, phishing attacks, insider threats, account compromise, and other advanced cyber threats through Malware Analysis and Malware Triage. Perform Root Cause Analysis, Timeline Analysis, and Timeline Creation to reconstruct attack activity and determine attack vectors. Identify, analyze, and extract Indicators of Compromise (IOC Analysis and IOC Extraction), Indicators of Attack (IOAs), and adversary Tactics, Techniques, and Procedures (TTPs) to support incident investigations and Threat Hunting activities. Utilize forensic and investigation tools such as Volatility, Autopsy, FTK, EnCase, SIEM platforms, and Endpoint Detection and Response (EDR/XDR) solutions to analyze system artifacts, memory, logs, and network traffic. Perform Log Analysis across operating systems, applications, security devices, and cloud platforms to identify malicious activity and support forensic investigations. Coordinate with SOC, Threat Intelligence, IT Infrastructure, Cloud Operations, and other stakeholders during incident investigations and response activities. Develop comprehensive Case Documentation, investigation reports, executive summaries, forensic findings, technical timelines, and remediation recommendations. Maintain and improve incident response playbooks, forensic procedures, investigation methodologies, and digital evidence handling processes. Contribute to the continuous improvement of the organization's Digital Forensics, Incident Response (DFIR), Threat Hunting, and cyber incident response capabilities.
Talent Profile:Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Digital Forensics, or a related field. Relevant cybersecurity certifications are preferred. Proven experience of 2+ years in Digital Forensics and Incident Response (DFIR), including hands-on experience conducting Incident Investigation, Digital Forensics, Evidence Collection, Memory Analysis, Disk Forensics, Malware Analysis, Threat Hunting, Root Cause Analysis, IOC Analysis, Timeline Analysis, Log Analysis, and enterprise incident response using forensic tools such as Volatility, Autopsy, FTK, EnCase, and enterprise SIEM/EDR platforms.
Job Nature:SITE, Project-Based.
In addition to the monthly salary, SITE provides you these Benefits:Social allowance. Mobile allowance. Medical Insurance employee, his/her family, and parents.