Consultant - Forensics - National - ASU - Forensics - Discovery - Gurgaon

EY

Gurugram District

On-site

INR 900,000 - 1,300,000

Full time

10 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

EY seeks a DFIR Analyst to investigate security incidents, collect evidence, and support containment and remediation across Windows and Linux environments. You will review SIEM and EDR alerts, correlate events, and prepare detailed investigation reports while maintaining evidence integrity.

Ideal candidates have 2–4 years in DFIR, strong analysis and scripting skills, and relevant certifications. This role offers opportunities to advance within EY's Forensics & Integrity Services in Gurgaon.

Qualifications

  • Bachelor’s degree in IT/CS or equivalent experience.
  • 2–4 years of experience in DFIR investigations.
  • Preferred certifications: GIAC GCIH / GCFA, CEH/CHFI, EnCE, FTK AccessData Certified Examiner, or SIEM tooling.
  • Proficient in analyzing logs and intrusions across multiple sources.

Responsibilities

  • Investigate security incidents, analyse digital evidence and assist containment and remediation.
  • Identify affected systems, business impact and infrastructure context.
  • Review alerts and logs from SIEM/EDR/SOAR/IDS‑IPS and other sources.
  • Prepare triage and investigation reports with timelines, findings, and recommendations.
  • Maintain evidence integrity and proper chain-of-custody.

Skills

Windows internals
Linux internals
Incident response
PowerShell or Python
Log analysis
Communication

Education

Bachelor’s degree in IT/CS or equivalent
Bachelor of Technology in Computer Science

Tools

Autopsy
Sleuth Kit
FTK Imager
EnCase
Cellebrite
Volatility
Splunk
Elastic
Microsoft Defender XDR
CrowdStrike Falcon
SENTINELONE
QRadar
Wireshark

Job description

Requisition Id: 1739229 As a global leader in assurance, tax, transaction and advisory services, we hire and develop the most passionate people in their field to help build a better working world. This starts with a culture that believes in giving you the training, opportunities and creative freedom. At EY, we don't just focus on who you are now, but who you can become. We believe that it’s your career and ‘It’s yours to build’ which means potential here is limitless and we'll provide you with motivating and fulfilling experiences throughout your career to help you on the path to becoming your best professional self.

The opportunity
: Consultant-National-Forensics-ASU - Forensics - Discovery - Gurgaon
National :
National comprises of sector agnostic teams working across industries for a well rounded experience.
ASU - Forensics - Discovery :
Successful organizations depend on their reputation for keeping promises, respecting laws and behaving ethically to maintain stakeholder trust. EY Forensic & Integrity Services professionals help organizations protect and restore enterprise and financial reputation. We assist companies and their legal counsel to investigate facts, resolve disputes and manage regulatory challenges. We put integrity at the heart of compliance programs to help better manage ethical and reputational risks. Our integrated approach ranges from enhancements in areas of perceived weakness or issues — including governance, controls, culture and data insights — to full organizational design and structural implementation. We want to help companies safeguard and restore financial and brand reputations. The insights and quality services we deliver help build trust and confidence in the capital markets and in economies the world over.
Your Key Responsibilities
Technical Excellence
  • DFIR Analyst is responsible for investigating security incidents, analysing digital evidence and helping in containment and remediation of cyber security incident. The Analyst should be having experience on hands-on investigations, triage, evidence collection and documentation of complex cyber security incidents. 1. Key Responsibilities
  • Understand incident details, affected systems, business impact and available infrastructure context.
  • Identify relevant evidence sources, including logs, endpoint data, network data and security platform telemetry.
  • Review alerts and logs from SIEM, EDR, SOAR, IDS/IPS, email security and other available sources.
  • Validate suspicious activity and correlate events to reconstruct the probable attack path.
  • Support initial containment actions such as endpoint isolation, IOC blocking and access restriction.
  • Acquire forensic images, memory captures, logs and volatile data using approved procedures and tools.
  • Preserve evidence integrity by minimizing contamination and maintaining proper chain-of-custody records.
  • Analyse forensic artifacts such as event logs, registry, prefetch, LNK files, browser artifacts, metadata and EDR telemetry.
  • Investigate endpoint, malware, email and network indicators to identify persistence, lateral movement, exfiltration and root cause.
  • Enrich indicators using threat intelligence sources and map attacker behaviour to MITRE ATT&CK techniques.
  • Prepare triage and investigation reports covering timelines, findings, impact, corrective actions and recommendations. 2. Tools & Technology Knowledge
  • Hands-on knowledge of forensic tools such as Autopsy, Sleuth Kit, FTK Imager, EnCase, Cellebrite and Volatility.
  • Working familiarity with EDR and incident response platforms including Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne and Carbon Black.
  • Ability to analyze logs using SIEM and log analytics platforms such as Splunk, Elastic, Microsoft Sentinel and QRadar.
  • Basic understanding of network and packet analysis tools including Wireshark, NetFlow analyzers and related investigation utilities.
  • Awareness of malware analysis and triage tools such as KAPE, sandbox platforms, VirusTotal and OTX. 3. Required Skills and Competencies
  • Strong understanding of Windows and Linux internals, Active Directory and common cloud platforms such as AWS and Azure.
  • Knowledge of common cyber-attack techniques, including phishing, ransomware, credential theft and lateral movement.
  • Ability to review logs, identify anomalies and correlate suspicious activities across multiple evidence sources.
  • Basic scripting capability in PowerShell or Python to support investigation automation and data analysis.
  • Strong analytical, troubleshooting and communication skills during incident response activities.
  • Ability to work under pressure while maintaining attention to detail in evidence handling and documentation. 4. Experience & Qualifications
  • 2–4 years of experience in DFIR investigations.
  • Bachelor’s degree in IT/CS or equivalent experience.
  • Preferred certifications: o GIAC GCIH / GCFA o CEH/ CHFI o Tool specific such as EnCE and FTK AccessData Certified Examiner, or in any SIEM tool related.
Skills And Attributes
To qualify for the role you must have
Qualification
  • Bachelor of Technology in Computer Science
Experience
  • Frontend Development (2+ years)
What We Look For
People with the ability to work in a collaborative manner to provide services across multiple client departments while following the commercial and legal requirements. You will need a practical approach to solving issues and complex problems with the ability to deliver insightful and practical solutions. We look for people who are agile, curious, mindful, and able to sustain positive energy, while being adaptable and creative in their approach.
What We Offer
Fuelled by the brilliance of our people, EY has emerged as the strongest brand and the most attractive employer in our field, with market-leading growth over competitors. Our people work side-by-side with market-leading entrepreneurs, game-changers, disruptors, and visionaries. As an organization, we are investing more time, technology, and money than ever before in skills and learning for our people. At EY, you will have a personalized Career Journey and also the chance to tap into the resources of our career frameworks to better know about your roles, skills, and opportunities. EY is equally committed to being an inclusive employer, and we strive to achieve the right balance for our people—enabling us to deliver excellent client service while allowing our people to build their careers as well as focus on their wellbeing. Join us in shaping the future with confidence.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Consultant - Forensics - National - ASU - Forensics - Discovery - Gurgaon
Consultant - Forensics - National - ASU - Forensics - Discovery - Gurgaon

Ernst & Young Advisory Services Sdn Bhd • Gurugram District

On-site
INR 1,200,000 - 1,800,000
Analyst - Forensics - National - ASU - Forensics - Investigations & Compliance - Noida
Analyst - Forensics - National - ASU - Forensics - Investigations & Compliance - Noida

EY • Dadri

On-site
INR 600,000 - 1,200,000
Consultant - Forensics - National - ASU - Forensics - Investigations & Compliance - Noida
Consultant - Forensics - National - ASU - Forensics - Investigations & Compliance - Noida

Ernst & Young Advisory Services Sdn Bhd • Dadri

On-site
INR 1,000,000 - 1,700,000
Senior Analyst - Forensics - National - ASU - Forensics - Investigations & Compliance - Gurgaon
Senior Analyst - Forensics - National - ASU - Forensics - Investigations & Compliance - Gurgaon

EY • Gurugram District

On-site
INR 1,000,000 - 1,600,000
Associate Consultant - Forensics - National - ASU - Forensics - Investigations & Compliance -Gurgaon
Associate Consultant - Forensics - National - ASU - Forensics - Investigations & Compliance -Gurgaon

Ernst & Young Advisory Services Sdn Bhd • Gurugram District

On-site
INR 800,000 - 1,200,000
Personalized Career Journey
Inclusive work environment
Director - Forensics - National - ASU - Forensics - Investigations And Compliance - Gurgaon
Director - Forensics - National - ASU - Forensics - Investigations And Compliance - Gurgaon

EY • Gurugram District

On-site
INR 4,000,000 - 6,000,000
Senior Consultant - Forensics - National - ASU - Forensics - Investigations & Compliance - Noida
Senior Consultant - Forensics - National - ASU - Forensics - Investigations & Compliance - Noida

Ernst & Young Advisory Services Sdn Bhd • Dadri

On-site
INR 1,600,000 - 2,100,000
Consultant - Forensics - National - ASU - Forensics - Discovery - Hyderabad
Consultant - Forensics - National - ASU - Forensics - Discovery - Hyderabad

EY • Hyderabad

On-site
INR 1,200,000 - 2,400,000
Analyst - Forensics - National - ASU - Forensics - Investigations & Compliance - Gurgaon
Analyst - Forensics - National - ASU - Forensics - Investigations & Compliance - Gurgaon

EY • Gurugram District

On-site
INR 420,000 - 660,000
Director - Forensics - National - ASU - Forensics - Investigations & Compliance - Gurgaon
Director - Forensics - National - ASU - Forensics - Investigations & Compliance - Gurgaon

EY • Gurugram District

On-site
INR 4,500,000 - 6,500,000