DFIR Analyst

Innefu Labs

Delhi

On-site

INR 800,000 - 1,400,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Innefu Labs in Delhi is seeking a DFIR Analyst with 2–3 years of hands-on experience in digital forensics, incident response, and security operations.

You will investigate incidents across Windows, Linux, and macOS, analyze artifacts, correlate IOC data, and support containment and remediation.

Bachelor's degree in CS/IT or related field is preferred; certifications such as Security+, CEH, GCFE, GCIA are advantageous. Strong analytical and communication skills are essential.

Qualifications

  • 2–3 years of hands-on DFIR, incident response, SOC, threat hunting, cybersecurity operations, or digital forensics.
  • Strong understanding of artifacts across Windows, Linux, and macOS.
  • Experience with memory forensics and IOC extraction.
  • Knowledge of MITRE ATT&CK and security tooling.

Responsibilities

  • Triage, investigate, and analyze security incidents across endpoints.
  • Analyze Windows artifacts, Linux logs, and macOS evidence.
  • Build timelines and correlate telemetry from multiple sources.
  • Support containment, remediation, and threat-hunting activities.
  • Develop and improve DFIR playbooks and detection use cases.

Skills

DFIR experience
Incident response
Threat hunting
Security operations
Digital forensics

Education

Bachelor's degree in Computer Science/IT

Tools

Magnet AXIOM
FTK
EnCase
X-Ways
KAPE
Velociraptor
Autopsy
EDR/XDR

Job description

DFIR Analyst – Digital Forensics s Incident Response

Experience: 2–3 Years | Full-time | Cybersecurity / DFIR

Job Summary

We are seeking a motivated and hands-on DFIR Analyst with 2–3 years of experience in digital forensics, incident response, security operations, or related cybersecurity functions. The candidate will investigate security incidents across Windows, Linux, and macOS environments, perform endpoint and log analysis, correlate forensic evidence with SIEM/EDR telemetry, identify indicators of compromise, and support containment and remediation activities.

Key Responsibilities
  • Perform triage, investigation, and analysis of cybersecurity incidents across Windows, Linux, and macOS endpoints and servers.
  • Analyze Windows artifacts including EVTX, Registry, Prefetch, AmCache, ShimCache, SRUM, Scheduled Tasks, Services, Autoruns, browser artifacts, PowerShell logs, and other relevant artifacts.
  • Analyze Linux artifacts including system/authentication logs, shell history, cron jobs, systemd services, SSH activity, user accounts, processes, network configuration, and persistence mechanisms.
  • Analyze macOS artifacts including Unified Logs, plist files, LaunchAgents, LaunchDaemons, login items, browser artifacts, user activity, and APFS-related evidence.
  • Perform basic memory forensics and volatile-data analysis using tools such as Volatility or equivalent tooling.
  • Investigate suspicious files, scripts, processes, persistence mechanisms, and malware behavior; perform basic static and dynamic malwaretriage.
  • Extract, validate, and correlate IOCs including hashes, domains, URLs, IP addresses, filenames, registry keys, user accounts, and process indicators.
  • Build investigation timelines and reconstruct attack activity by correlating endpoint, network, authentication, and security telemetry.
  • Support threat hunting activities using SIEM, EDR, threat intelligence, forensic artifacts, and MITRE ATTCCK-based hypotheses.
  • Contribute to the development and improvement of DFIR playbooks, investigation procedures, detection use cases, and automation opportunities.
Technical Skills s Qualifications
  • 2–3 years of hands-on experience in DFIR, incident response, SOC, threat hunting, cybersecurity operations, or digital forensics.
  • Strong understanding of digital forensics and file systems, including NTFS, FAT/exFAT, ext4, and APFS, with practical knowledge of forensic artifacts and metadata.
  • Hands-on experience with forensic and security tools such as Magnet AXIOM, FTK, EnCase, X-Ways, KAPE, Velociraptor, Autopsy, EDR/XDR, or equivalent platforms.
  • Strong understanding of incident response, malware, IOCs, MITRE ATT & CK, and attacker TTPs, including persistence, credential theft, lateral movement, C2, and data exfiltration.
  • Good analytical, investigative, communication, and problem-solving skills, with basic scripting/querying knowledge in Python, PowerShell, Bash, KQL, SPL, SQL, or equivalent.
Stakeholder s Communication Responsibilities
  • Collaborate with SOC, Incident Response, IT, Security Engineering, and management teams during investigations.
  • Clearly communicate incident severity, impact, forensic findings, evidence, and recommended next steps to technical and non-technical stakeholders.
  • Participate in client/customer calls, investigation briefings, technical discussions, and post-incident reviews as required.
Education s Certifications
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, Electronics, or a related discipline, or equivalent practical experience.
  • Relevant certifications are preferred but not mandatory, such as Security+, CEH, CHFI, GCIH, GCFE, GCFA, SC-200, or equivalent.
  • Practical hands-on DFIR experience, labs, projects, or relevant professional experience may be considered in place of certifications.
Preferred Additional Exposure
  • Threat intelligence platforms and IOC enrichment.
  • Cloud security and incident response involving AWS, Azure, or Microsoft 365.
  • SOAR platforms and security automation.
  • YARA, Sigma, or other detection-rule concepts.
  • Vulnerability and exposure-management concepts.
  • Container or server forensics.
  • Experience with ransomware, phishing, credential compromise, insider-threat, or data-exfiltration investigations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Digital Forensic Analyst
Digital Forensic Analyst

Quess IT Staffing • Mumbai

On-site
INR 1,000,000 - 1,500,000
DFIR Lead
DFIR Lead

UST • Thiruvananthapuram

On-site
INR 1,500,000 - 2,100,000
Digital Forensics and Incident Response (DFIR) Specialist
Digital Forensics and Incident Response (DFIR) Specialist

Forensic Focus Limited • Jaipur

On-site
INR 1,800,000 - 3,200,000
Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

UltraViolet Cyber • Hyderabad

On-site
INR 2,800,000 - 4,200,000
Forensics Discovery Consultant
Forensics Discovery Consultant

EY • Gurugram District

On-site
INR 1,800,000 - 2,500,000
Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

Uvcyber • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Opening for Digital Forensic Analyst @ Mumbai
Opening for Digital Forensic Analyst @ Mumbai

Quess IT Staffing • Mumbai

On-site
INR 700,000 - 1,200,000
DFIR Analyst
DFIR Analyst

Forensic Focus Limited • Delhi

On-site
INR 240,000 - 2,000,000
Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

Forensic Focus Limited • Hyderabad

On-site
INR 2,500,000 - 4,000,000
Digital Forensics Analyst
Digital Forensics Analyst

Forensic Focus Limited • Delhi

On-site
INR 800,000 - 1,600,000