Cybersecurity Incident Response Specialist

Achieve Cybersecurity Solutions

Hyderabad

On-site

INR 2,500,000 - 4,200,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Achieve Cybersecurity Solutions in Hyderabad seeks an experienced Senior Cybersecurity Incident Response Specialist to manage and investigate security incidents across enterprise environments.

The role covers triage, investigation, containment, eradication, recovery, RCA, malware analysis, and digital forensics, with strong customer-facing skills to lead incident discussions and provide clear recommendations.

Qualifications

  • 8–10 years hands-on cybersecurity incident response experience.
  • Experience leading investigations and coordinating across teams.
  • Strong knowledge of malware analysis, forensics, and RCA.

Responsibilities

  • Take end-to-end ownership of incidents from detection to closure.
  • Lead investigation of high-severity incidents and coordinate responses.
  • Perform RCA, malware analysis, and digital forensic investigations.
  • Prepare incident reports and present findings to stakeholders.

Skills

Stakeholder mgmt
Critical Inc Mgmt
Malware Analysis
Digital Forensics
Incident Reporting
Threat Hunting
SIEM
EDR/XDR

Tools

Splunk
Microsoft Sentinel
QRadar
CrowdStrike
Microsoft Defender for Endpoints
Cortex XDR

Job description

Job Description Senior Cybersecurity Incident Response Specialist

Experience: 8-10 Years
Function: Cybersecurity Incident Response / DFIR
Primary Skills: Stakeholder Management,Critical Incident Management(CIRT),Malware Analysis,Digital Forensics,Incident Reporting & Documentation,Threat Hunting,SIEM,EDR/XDR


Should be willing to work in Second Shift


Interview Mode:--Candidates must attend F2F interview for final discussion(Weekdays only)

Mode of work : Work From Office


Office Address : UV Cyber, Cyber Towers, Quadrant 3, 3rd floor, Madhapur, Hyderabad -- 500081

Role Overview

We are looking for an experienced Cybersecurity Incident Response Specialist with 810 years of hands-on cybersecurity experience to manage and investigate security incidents across enterprise environments.

The candidate will be responsible for end-to-end ownership of cybersecurity incidents, including triage, investigation, containment, eradication, recovery, Root Cause Analysis (RCA), malware analysis, and digital forensic analysis. The role also requires strong customer-facing skills to lead incident discussions, provide regular updates, explain technical findings, and present investigation outcomes and recommendations.

Key Responsibilities
Incident Response & Investigation
  • Take end-to-end ownership of cybersecurity incidents from initial detection through closure.
  • Lead investigation of Critical, High, and complex security incidents and coordinate response activities across relevant teams.
  • Perform incident triage, scoping, containment, eradication, recovery, and post-incident analysis.
  • Investigate incidents involving ransomware, malware, phishing, account compromise, credential theft, data exfiltration, insider threats, web attacks, lateral movement, privilege escalation, and other advanced threats.
  • Analyze security alerts and correlate information across EDR, SIEM, network, identity, cloud, email, and other security technologies.
  • Develop incident timelines and determine the attack vector, affected assets, compromised accounts, attacker activity, persistence mechanisms, and overall impact.
  • Identify Indicators of Compromise (IOCs), attacker Tactics, Techniques, and Procedures (TTPs), and map findings to the MITRE ATT&CK framework.
  • Coordinate with SOC, Threat Hunting, Threat Intelligence, IT, Cloud, Network, IAM, Application, Legal, and other stakeholders during major incidents.
Root Cause Analysis (RCA)
  • Perform detailed Root Cause Analysis for security incidents.
  • Determine the initial attack vector, contributing factors, security/control gaps, and reasons existing preventive or detective controls did not stop or detect the activity earlier.
  • Conduct post-incident reviews and lessons-learned sessions.
  • Develop clear corrective and preventive actions based on investigation findings.
  • Track remediation recommendations with relevant stakeholders through closure.
  • Prepare comprehensive RCA reports suitable for technical teams, management, and customers.
Malware Analysis
  • Perform static and dynamic malware analysis to understand malicious file behavior and capabilities.
  • Analyze suspicious executables, scripts, PowerShell commands, documents, URLs, and other artifacts.
  • Identify malware persistence mechanisms, command-and-control activity, network indicators, file-system changes, registry modifications, and related behaviors.
  • Extract IOCs and behavioral indicators for threat hunting and detection engineering.
  • Perform malware sandboxing and behavioral analysis where required.
  • Provide recommendations for detection, containment, and prevention based on malware-analysis findings.
Digital Forensics
  • Perform digital forensic investigations on endpoints and other relevant systems.
  • Analyze Windows/Linux artifacts, event logs, file systems, registry artifacts, browser artifacts, authentication logs, memory artifacts, and other forensic evidence.
  • Perform disk and memory analysis where required.
  • Collect and preserve digital evidence following appropriate forensic procedures and chain-of-custody requirements.
  • Build forensic timelines and reconstruct attacker activities.
  • Determine the scope and impact of compromise using forensic evidence.
  • Document forensic findings clearly and maintain investigation evidence appropriately.
Customer & Stakeholder Management
  • Act as a key technical point of contact for customers during cybersecurity incidents.
  • Lead incident calls and communicate investigation progress, impact, containment status, risks, and next steps.
  • Provide timely and accurate incident updates to customers and internal leadership.
  • Translate complex technical investigation findings into clear business-level communication.
  • Manage customer expectations during high-severity and time-sensitive incidents.
  • Present RCA and forensic investigation findings to customers and senior stakeholders.
  • Handle technical questions and confidently explain investigation methodology, evidence, conclusions, and recommendations.
  • Coordinate with multiple internal and customer teams to drive incidents toward timely resolution.
Incident Reporting & Documentation
  • Prepare detailed incident investigation reports, including:
  • Maintain accurate incident records, evidence, investigation notes, and supporting documentation.
  • Contribute to the development and improvement of Incident Response playbooks, SOPs, investigation procedures, and escalation processes.
  • Executive summary
  • Incident timeline
  • Scope and impact
  • Root cause
  • Attack vector
  • IOCs and TTPs
  • Investigation findings
  • Containment and remediation actions
  • Control gaps
  • Corrective and preventive recommendations
  • Lessons learned
Required Technical Skills

The candidate should have strong hands-on experience in:

  • Cybersecurity Incident Response / DFIR
  • Security Incident Investigation
  • Root Cause Analysis (RCA)
  • Digital Forensics
  • Malware Analysis
  • Threat Hunting
  • Endpoint and Network Investigation
  • Windows and Linux Forensics
  • Disk and Memory Analysis
  • Log Analysis and Timeline Reconstruction
  • IOC and TTP Analysis
  • MITRE ATT&CK Framework
  • SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, or similar
  • EDR/XDR platforms such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Cortex XDR, or similar
  • Network security technologies including Firewall, IDS/IPS, Proxy, DNS, VPN, and WAF
  • Cloud security investigation across AWS, Azure, and/or GCP environments
  • Identity and authentication-related investigations
  • Email and phishing investigations
  • Forensic and malware-analysis tools such as Volatility, Autopsy, FTK, EnCase, Wireshark, Sysinternals,
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

UltraViolet Cyber • Hyderabad

On-site
INR 2,800,000 - 4,200,000
Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

Uvcyber • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Walk-in | SOC - Incident Response & Handling - AM/DM
Walk-in | SOC - Incident Response & Handling - AM/DM

Deloitte Shared Services India • Mumbai, Hyderabad

On-site
INR 1,500,000 - 2,200,000
Walk-in | SOC - Incident Response & Handling - Consultant
Walk-in | SOC - Incident Response & Handling - Consultant

Deloitte Shared Services India • Mumbai, Hyderabad

On-site
INR 700,000 - 1,200,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

Hybrid
INR 1,500,000 - 2,100,000
Flexible/Remote work
Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

Forensic Focus Limited • Hyderabad

On-site
INR 2,500,000 - 4,000,000
Cyber Triage Analyst
Cyber Triage Analyst

Randstad Enterprise • Kerala

On-site
INR 2,000,000 - 4,000,000
Cyber Security Analyst
Cyber Security Analyst

Sunrise Biztech Systems • Hyderabad

On-site
INR 1,800,000 - 2,800,000
Senior Manager, Threat Detection & Response
Senior Manager, Threat Detection & Response

Johnson & Johnson • Hyderabad

On-site
INR 2,000,000 - 3,000,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Dun & Bradstreet India • Hyderabad

On-site
INR 1,800,000 - 3,000,000