CF CloudFrame Job Scanner Open Dashboard →
Verified Active Opening

Senior Cybersecurity Incident Response Specialist

Uvcyber • Hyderabad

Job Description

Experience: 8–10 Years Function: Cybersecurity – Incident Response / DFIR Role Level: Senior Role Overview We are looking for an experienced Cybersecurity Incident Response Specialist with 8–10 years of hands-on cybersecurity experience to manage and investigate security incidents across enterprise environments. The candidate will be responsible for end-to-end ownership of cybersecurity incidents, including triage, investigation, containment, eradication, recovery, Root Cause Analysis (RCA), malware analysis, and digital forensic analysis. The role also requires strong customer-facing skills to lead incident discussions, provide regular updates, explain technical findings, and present investigation outcomes and recommendations. Key Responsibilities Incident Response & Investigation • Take end-to-end ownership of cybersecurity incidents from initial detection through closure. • Lead investigation of Critical, High, and complex security incidents and coordinate response activities across relevant teams. • Perform incident triage, scoping, containment, eradication, recovery, and post-incident analysis. • Investigate incidents involving ransomware, malware, phishing, account compromise, credential theft, data exfiltration, insider threats, web attacks, lateral movement, privilege escalation, and other advanced threats. • Analyze security alerts and correlate information across EDR, SIEM, network, identity, cloud, email, and other security technologies. • Develop incident timelines and determine the attack vector, affected assets, compromised accounts, attacker activity, persistence mechanisms, and overall impact. • Identify Indicators of Compromise (IOCs), attacker Tactics, Techniques, and Procedures (TTPs), and map findings to the MITRE ATT&CK framework. • Coordinate with SOC, Threat Hunting, Threat Intelligence, IT, Cloud, Network, IAM, Application, Legal, and other stakeholders during major incidents. Root Cause Analysis (RCA) • Perform detailed Root Cause Analysis for security incidents. • Determine the initial attack vector, contributing factors, security/control gaps, and reasons existing preventive or detective controls did not stop or detect the activity earlier. • Conduct post-incident reviews and lessons-learned sessions. • Develop clear corrective and preventive actions based on investigation findings. • Track remediation recommendations with relevant stakeholders through closure. • Prepare comprehensive RCA reports suitable for technical teams, management, and customers. Malware Analysis • Perform static and dynamic malware analysis to understand malicious file behaviour and capabilities. • Analyze suspicious executables, scripts, PowerShell commands, documents, URLs, and other artifacts. • Identify malware persistence mechanisms, command-and-control activity, network indicators, file-system changes, registry modifications, and related behaviors. • Extract IOCs and behavioral indicators for threat hunting and detection engineering. • Perform malware sandboxing and behavioral analysis where required. • Provide recommendations for detection, containment, and prevention based on malware-analysis findings. Digital Forensics • Perform digital forensic investigations on endpoints and other relevant systems. • Analyze Windows/Linux artifacts, event logs, file systems, registry artifacts, browser artifacts, authentication logs, memory artifacts, and other forensic evidence. • Perform disk and memory analysis where required. • Collect and preserve digital evidence following appropriate forensic procedures and chain-of-custody requirements. • Build forensic timelines and reconstruct attacker activities. • Determine the scope and impact of compromise using forensic evidence. • Document forensic findings clearly and maintain investigation evidence appropriately. Customer & Stakeholder Management • Act as a key technical point of contact for customers during cybersecurity incidents. • Lead incident calls and communicate investigati

Job Reference ID: CF-201880 • Posted on CloudFrame Job Scanner