Hiring.Camp

Senior Cybersecurity Incident Response Specialist

UltraViolet Cyber

·

Today

Location
Hyderabad
Workplace
Onsite
Type
Full-time
Department
Commercial
Seniority
Senior
Source
Lever

Description

Experience: 8–10 Years

Function: Cybersecurity – Incident Response / DFIR
Role Level: Senior

Role Overview

We are looking for an experienced Cybersecurity Incident Response Specialist with 8–10 years of hands-on cybersecurity experience to manage and investigate security incidents across enterprise environments.
The candidate will be responsible for end-to-end ownership of cybersecurity incidents, including triage, investigation, containment, eradication, recovery, Root Cause Analysis (RCA), malware analysis, and digital forensic analysis. The role also requires strong customer-facing skills to lead incident discussions, provide regular updates, explain technical findings, and present investigation outcomes and recommendations.

Key Responsibilities

Incident Response & Investigation
•    Take end-to-end ownership of cybersecurity incidents from initial detection through closure.
•    Lead investigation of Critical, High, and complex security incidents and coordinate response activities across relevant teams.
•    Perform incident triage, scoping, containment, eradication, recovery, and post-incident analysis.
•   Investigate incidents involving ransomware, malware, phishing, account compromise, credential theft, data exfiltration, insider threats, web attacks, lateral movement, privilege escalation, and other advanced threats.
•    Analyze security alerts and correlate information across EDR, SIEM, network, identity, cloud, email, and other security technologies.
•    Develop incident timelines and determine the attack vector, affected assets, compromised accounts, attacker activity, persistence mechanisms, and overall impact.
•    Identify Indicators of Compromise (IOCs), attacker Tactics, Techniques, and Procedures (TTPs), and map findings to the MITRE ATT&CK framework.
•  Coordinate with SOC, Threat Hunting, Threat Intelligence, IT, Cloud, Network, IAM, Application, Legal, and other stakeholders during major incidents.
Root Cause Analysis (RCA)
•    Perform detailed Root Cause Analysis for security incidents.
•  Determine the initial attack vector, contributing factors, security/control gaps, and reasons existing preventive or detective controls did not stop or detect the activity earlier.
•    Conduct post-incident reviews and lessons-learned sessions.
•    Develop clear corrective and preventive actions based on investigation findings.
•    Track remediation recommendations with relevant stakeholders through closure.
•    Prepare comprehensive RCA reports suitable for technical teams, management, and customers.
Malware Analysis
•    Perform static and dynamic malware analysis to understand malicious file behaviour and capabilities.
•    Analyze suspicious executables, scripts, PowerShell commands, documents, URLs, and other artifacts.
•  Identify malware persistence mechanisms, command-and-control activity, network indicators, file-system changes, registry modifications, and related behaviors.
•    Extract IOCs and behavioral indicators for threat hunting and detection engineering.
•    Perform malware sandboxing and behavioral analysis where required.
•    Provide recommendations for detection, containment, and prevention based on malware-analysis findings.
Digital Forensics
•    Perform digital forensic investigations on endpoints and other relevant systems.
•  Analyze Windows/Linux artifacts, event logs, file systems, registry artifacts, browser artifacts, authentication logs, memory artifacts, and other forensic evidence.
•    Perform disk and memory analysis where required.
•    Collect and preserve digital evidence following appropriate forensic procedures and chain-of-custody requirements.
•    Build forensic timelines and reconstruct attacker activities.
•    Determine the scope and impact of compromise using forensic evidence.
•    Document forensic findings clearly and maintain investigation evidence appropriately.
Customer & Stakeholder Management
•    Act as a key technical point of contact for customers during cybersecurity incidents.
•    Lead incident calls and communicate investigation progress, impact, containment status, risks, and next steps.
•    Provide timely and accurate incident updates to customers and internal leadership.
•    Translate complex technical investigation findings into clear business-level communication.
•    Manage customer expectations during high-severity and time-sensitive incidents.
•    Present RCA and forensic investigation findings to customers and senior stakeholders.
•    Handle technical questions and confidently explain investigation methodology, evidence, conclusions, and recommendations.
•    Coordinate with multiple internal and customer teams to drive incidents toward timely resolution.
Incident Reporting & Documentation
•    Prepare detailed incident investigation reports, including: 
o    Executive summary
o    Incident timeline
o    Scope and impact
o    Root cause
o    Attack vector
o    IOCs and TTPs
o    Investigation findings
o    Containment and remediation actions
o    Control gaps
o    Corrective and preventive recommendations
o    Lessons learned
•    Maintain accurate incident records, evidence, investigation notes, and supporting documentation.
•    Contribute to the development and improvement of Incident Response playbooks, SOPs, investigation procedures, and escalation processes.
Required Technical Skills
The candidate should have strong hands-on experience in:
•    Cybersecurity Incident Response / DFIR
•    Security Incident Investigation
•    Root Cause Analysis (RCA)
•    Digital Forensics
•    Malware Analysis
•    Threat Hunting
•    Endpoint and Network Investigation
•    Windows and Linux Forensics
•    Disk and Memory Analysis
•    Log Analysis and Timeline Reconstruction
•    IOC and TTP Analysis
•    MITRE ATT&CK Framework
•    SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, or similar
•    EDR/XDR platforms such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Cortex XDR, or similar
•    Network security technologies including Firewall, IDS/IPS, Proxy, DNS, VPN, and WAF
•    Cloud security investigation across AWS, Azure, and/or GCP environments
•    Identity and authentication-related investigations
•    Email and phishing investigations
•    Forensic and malware-analysis tools such as Volatility, Autopsy, FTK, EnCase, Wireshark, Sysinternals, YARA, Ghidra, IDA, or equivalent tools
•    Scripting/automation using Python, PowerShell, or similar technologies would be an advantage.
Required Experience
•    8–10 years of overall cybersecurity experience, with significant hands-on experience in Incident Response, DFIR, SOC, Threat Hunting, or related security domains.
•    Demonstrated experience independently handling complex and high-severity cybersecurity incidents.
•    Strong experience conducting RCA and presenting investigation findings.
•    Hands-on experience with malware and forensic investigations.
•    Experience handling customer-facing security incidents and leading technical/customer incident calls.
•    Experience coordinating investigations involving multiple technical and business teams.
•    Ability to work effectively under pressure during Critical/High-severity incidents.
•    Strong analytical, troubleshooting, and problem-solving skills.
Communication & Leadership Skills
•    Excellent verbal and written communication skills.
•    Strong customer-facing and stakeholder-management capabilities.
•    Ability to communicate effectively with both technical and non-technical stakeholders.
•    Ability to lead incident bridges/calls during critical incidents.
•    Strong documentation and report-writing skills.
•    Ability to take ownership, make investigation decisions, and drive incidents to closure.
•    Ability to mentor junior Incident Response/SOC analysts and provide technical guidance during investigations.

Skills

PythonAWSAzureGCPLinuxCybersecuritySIEMSOCSplunk

Similar Jobs

13

Senior Cybersecurity Incident Response Expert

Robert Bosch · hosur road bangalore, India

5 days ago

Senior Manager Cybersecurity Incident Response and Business Continuity

Pax8Inc · United States, United States of America · Remote

1 week ago

Senior Product Cybersecurity Engineer, Product Security Incident Response Team (PSIRT)

General Motors · GM Global Technical Center - Cole Engineering Center Podium, United States of America · Hybrid

2 weeks ago

Senior Cybersecurity Incident Analyst

General Motors · GM Global Technical Center - Michigan IT Innovation Center, United States of America · Hybrid

2 weeks ago

Senior Cybersecurity Incident Responder

bakertilly · IND KA Bangalore - Cherry Hills, India

2 months ago

Cybersecurity Incident Senior Analyst

Babelgroup · MADRID, Spain +4 · Remote

2 months ago

Senior Cybersecurity Incident Responder (f/m/d)

Job Market · Oberkochen, Germany +4

4 months ago

Senior Cybersecurity Incident Responder (f/m/d)

Job Market · Oberkochen, Germany +1

6 months ago

Senior Cybersecurity Incident Responder (f/m/x)

Job Market · Budapest - ZDI, Hungary · Hybrid

6 months ago

Senior Associate/Cybersecurity & Incident Response (Forensic Services practice)

Charlesriverassociates · Toronto, ON, Canada

1+ year ago

Senior Associate/Cybersecurity & Incident Response (Forensic Services practice)

Charlesriverassociates · Boston, MA, United States; Chicago, IL, United States; Dallas, Texas, United States; Houston, Texas, United States; Washington, DC, United States +4

1+ year ago

Senior Cybersecurity Incident Response Administrator - Senior w/Secret Clearance

Teksynap · Radford, VA, US

1+ year ago

Senior Cybersecurity Incident Response Administrator

Sev1Tech · Radford, VA, US +1

1+ year ago