DFIR Specialist

Persistent Systems Limited

Chennai District

Hybrid

INR 2,600,000 - 4,600,000

Full time

44 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid work
Higher education sponsorship
Flexible work hours
Long Service awards
Accessibility-friendly office

Job summary

Persistent Systems Limited is seeking an experienced DFIR Specialist to join our cybersecurity team in Chennai. The role focuses on incident investigations, digital forensics, threat analysis, and incident response across enterprise environments.

You will investigate incidents, collect and analyze evidence, determine root causes, support containment and remediation, and collaborate with SOC, Cloud, and Infra teams. Strong IAM Entra ID and cross-platform forensics are essential.

Qualifications

  • Strong DFIR expertise with incident investigation and forensics.
  • Deep IAM and Entra ID knowledge, with enterprise-scale investigations.
  • Experience with Windows and Linux forensic analysis.
  • Proficient with memory, disk, and network evidence collection and analysis.
  • Experience using SIEM/EDR platforms and threat intel integration.

Responsibilities

  • Investigate cybersecurity incidents including malware infections and phishing attacks.
  • Perform forensic acquisition and analysis of endpoints, servers, logs, and digital evidence.
  • Conduct incident triage, containment, eradication, and recovery.
  • Identify IOCs, attack vectors, and affected assets; reconstruct attacker activity.
  • Prepare incident reports, root-cause analyses and remediation recommendations.

Skills

DFIR expertise
IAM knowledge
Scripting (PowerShell/Python)
Incident response lifecycle
Documentation & reporting

Education

Bachelor's degree in CS/IT/Cybersecurity

Tools

EnCase
FTK
Volatility
CrowdStrike Falcon
Microsoft Defender
Microsoft Sentinel
Splunk

Job description

We are an AI-led, platform-driven Digital Engineering and Enterprise Modernization partner, combining deep technical expertise and industry experience to help our clients anticipate what’s next. Our offerings and proven solutions create a unique competitive advantage for our clients by giving them the power to see beyond and rise above. We work with many industry-leading organizations across the world, including 20 Fortune 50 companies and 4 of the 5 top banks in both the US and India, and numerous innovators across the healthcare ecosystem.

We are seeking an experienced DFIR Specialist with a strong background in Identity and Access Management (IAM) and Entra ID to join our cybersecurity team. The ideal candidate will play a critical role in supporting cybersecurity incident investigations, digital forensics, threat analysis, and incident response activities. You will be responsible for investigating security incidents, collecting and analyzing forensic evidence, determining root causes and impacts, and supporting containment and remediation efforts.

  • Role: DFIR Specialist
  • Experience: 8 to 12 Years
  • Job Type: Full-Time Employment
What You'll Do:
  • Investigate cybersecurity incidents including malware infections, account compromises, phishing attacks, ransomware incidents, and suspicious activities.
  • Perform forensic acquisition and analysis of endpoints, servers, logs, and digital evidence.
  • Conduct incident triage, containment, eradication, recovery, and post-incident reviews.
  • Perform memory, disk, file-system, network, and log analysis during investigations.
  • Identify Indicators of Compromise (IOCs), determine attack vectors, and assess affected assets.
  • Conduct detailed timeline analysis and reconstruct attacker activities during security incidents.
  • Support proactive threat hunting and investigate suspicious behaviors across enterprise environments.
  • Collaborate with SOC, Security Engineering, Infrastructure, Cloud, and Application teams during incident response activities.
  • Maintain proper evidence handling procedures and chain-of-custody documentation.
  • Prepare incident investigation reports, technical findings, root-cause analyses, and remediation recommendations.
  • Contribute to DFIR procedures, incident response playbooks, and continuous improvement initiatives.
  • Support security operations during critical incidents and major investigations.
Expertise You'll Bring:
  • Strong expertise in Digital Forensics and Incident Response (DFIR).
  • Extensive experience in Cyber Incident Investigation and Security Operations.
  • Deep knowledge of Identity and Access Management (IAM) and Microsoft Entra ID.
  • Expertise in endpoint and host-based forensic investigations.
  • Strong experience in Windows and Linux forensic analysis.
  • Hands-on experience with disk, memory, file-system, network, and log analysis.
  • Strong understanding of incident response lifecycle, investigation methodologies, and evidence handling.
  • Experience with malware analysis, IOC analysis, and threat actor activity investigations.
  • Experience using SIEM and EDR platforms for security investigations.
  • Deep understanding of MITRE ATT&CK framework and adversary tactics, techniques, and procedures.
  • Scripting and automation experience using PowerShell, Python, or similar technologies.
  • Knowledge of cloud security investigations across Azure, AWS, and GCP environments.
  • Hands-on experience investigating enterprise-level cybersecurity incidents.
  • Familiarity with memory forensics, disk forensics, and advanced threat-hunting techniques.
  • Experience using forensic tools such as EnCase, FTK, Volatility, and related DFIR platforms.
  • Experience working with CrowdStrike Falcon, Microsoft Defender, Microsoft Sentinel, Splunk, and similar security solutions.
  • Strong analytical, troubleshooting, and problem-solving capabilities.
  • Excellent documentation, reporting, and stakeholder communication skills.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related discipline is preferred.
  • Certifications such as GCFA, GCFE, GCIH, CHFI, Security+, CISSP, or equivalent are advantageous.
  • Strong commitment to incident response excellence, continuous learning, and cybersecurity best practices.
  • Competitive salary and benefits package
  • Culture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certifications
  • Opportunity to work with cutting-edge technologies
  • Employee engagement initiatives such as project parties, flexible work hours, and Long Service awards
  • Insurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parents
Values-Driven, People-Centric & Inclusive Work Environment:

Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds.

  • We support hybrid work and flexible hours to fit diverse lifestyles.
  • Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.
  • If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employment

“Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind.”

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Digital Forensics and Incident Response (DFIR) Specialist
Digital Forensics and Incident Response (DFIR) Specialist

Zoho • India

Remote
INR 1,400,000 - 2,400,000
Security Operations SME (L3)
Security Operations SME (L3)

Persistent Systems Limited • Mumbai

Hybrid
INR 2,800,000 - 4,200,000
Hybrid work options
Flexible work hours
Long service awards
+3
Threat Intelligence & Threat Hunting Specialist
Threat Intelligence & Threat Hunting Specialist

Persistent Systems Limited • Chennai District

Hybrid
INR 3,500,000 - 7,000,000
Hybrid work arrangement
Career development support
Higher education & certifications
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobgether SRL • India

Remote
INR 4,000,000 - 7,000,000
Remote-first
Professional development
Global collaboration
+2
Senior DFIR Consultant
Senior DFIR Consultant

Positka • Chennai District

On-site
INR 4,000,000 - 7,000,000
Threat Intelligence & Threat Hunting Specialist
Threat Intelligence & Threat Hunting Specialist

Persistent Systems Limited • Mumbai

Hybrid
INR 3,000,000 - 4,200,000
Hybrid work
Education support
Cutting-edge technologies
+2
Forensics Discovery Consultant
Forensics Discovery Consultant

EY • Gurugram District

On-site
INR 1,800,000 - 2,500,000
Incident Responder
Incident Responder

KPMG Assurance and Consulting Services LLP • Mumbai

On-site
INR 800,000 - 1,200,000
International Contract Bench, Incident Response (DFIR)
International Contract Bench, Incident Response (DFIR)

Jobgether SRL • India

On-site
INR 2,066,000 - 4,133,000
Flexible contract
Live investigations
Cloud forensics exposure
+2
Manager - Cybersecurity Operations
Manager - Cybersecurity Operations

Tata Communications Limited • Maharashtra

On-site
INR 1,800,000 - 3,200,000