Digital Forensic Analyst

Quess IT Staffing

Mumbai

On-site

INR 1,000,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Quess IT Staffing is looking for an experienced cybersecurity professional to analyze security incidents primarily focusing on Digital Forensics and Incident Response.

The successful candidate will investigate complex incidents, improve SIEM detection logic, and support threat-hunting activities. A strong foundation in cloud security and familiarity with various SIEM platforms is essential for this role.

The ideal applicant will have a relevant engineering degree and preferred certifications such as GCED or CEH.

Qualifications

  • Strong understanding of Digital Forensics and Incident Response methodologies.
  • Hands-on experience with file system forensics including deleted file recovery.
  • Ability to analyze and improve SIEM detection logic.

Responsibilities

  • Analyze Microsoft Entra ID events and AzureActivity for security incidents.
  • Create and fine-tune use-case dashboards across multiple consoles.
  • Conduct deep-dive log analysis to identify indicators of compromise.

Skills

Digital Forensics
Incident Response
SIEM tuning
Threat Hunting
Linux Scripting
Windows Scripting
Cloud Security

Education

BE/B Tech in Computer Science/Information Technology or MCA

Tools

Azure Sentinel
LogRhythm
XSIAM
Wazuh

Job description

Responsibilities
  • Analyze Microsoft Entra ID events such as SigninLogs and Risky users.
  • Analyze AzureActivity, AuditLogs.
  • Create and fine‑tune use‑case dashboards across multiple consoles.
  • Investigate and analyze complex security incidents to determine root cause, attack progression, and remediation steps.
  • Perform advanced analysis and tuning of SIEM detection and correlation rules across platforms such as Microsoft Sentinel, LogRhythm, and Palo Alto XSIAM.
  • Conduct deep‑Dive log analysis to identify advanced indicators of compromise (IOCs) and attacker techniques across endpoint, network, cloud, and identity logs.
  • Execute advanced triage, validation, and investigation of alerts from Microsoft Sentinel, Microsoft Defender XDR, GCP, and other integrated security tools.
  • Perform detailed timeline reconstruction and cross‑source correlation to identify lateral movement, persistence, and data exfiltration activities.
  • Support and execute incident response activities including containment recommendations, evidence acquisition, chain‑of‑custody handling, and post‑incident analysis.
  • Develop and execute structured threat‑hunting activities using hypotheses aligned with MITRE ATT&CK and emerging threat intelligence.
  • Gather forensic artifacts of disk images, memory dumps, and log artifacts from compromised systems.
Qualifications
  • Strong understanding of Digital Forensics and Incident Response (DFIR) methodologies.
  • Hands‑on experience with file system forensics (NTFS, EXT, FAT32) including deleted file recovery, metadata, and artifact analysis.
  • Ability to analyze and improve SIEM detection logic and reduce false positives through tuning and validation.
  • Ability to perform Threat Hunting aligned with MITRE ATT&CK standards.
  • Proficiency in Linux and Windows environments with scripting capabilities in Python, PowerShell, and Bash for automation and analysis.
  • In‑depth understanding of security threats (preferably OWASP Top 10 vulnerabilities.
  • Basic experience with SIEM platforms such as Azure Sentinel, LogRhythm, XSIAM and Wazuh.
  • Understanding of security tools like HIPS/NIPS, Network Monitoring tools, Cloud Security, AV, EDR, WAF.
  • Strong understanding of Cloud Security for cloud such Azure, GCP and AWS.
  • BE/B Tech in Computer Science/Information Technology, or MCA.
  • Certifications such as GCED, GCIA, CEH, OSCP, or equivalent DFIR-focused certifications preferred.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Digital Forensic Lead
Digital Forensic Lead

Sisainfosec • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Digital Forensics Consultant
Digital Forensics Consultant

Pylon Management Consulting • Bengaluru, Mumbai

On-site
INR 1,200,000 - 1,800,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Dun & Bradstreet India • Hyderabad

On-site
INR 2,500,000 - 4,000,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Dun & Bradstreet • Hyderabad

Hybrid
INR 2,500,000 - 4,500,000
Forensic Analyst
Forensic Analyst

Insight Global • Chennai District

Hybrid
INR 1,400,000 - 2,100,000
Cyber Security Analyst
Cyber Security Analyst

Dun & Bradstreet • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Openings For Senior Digital Forensics Consultant_WFO
Openings For Senior Digital Forensics Consultant_WFO

Ampcus Cyber • Bengaluru

On-site
INR 4,000,000 - 6,000,000
Expert IT Cyber Defense Analyst
Expert IT Cyber Defense Analyst

Jobtailor • Pune District

On-site
INR 900,000 - 1,500,000
Cyber Security Specialist
Cyber Security Specialist

Terralogic • Bengaluru

On-site
INR 2,800,000 - 4,600,000
Analyst
Analyst

CDW UK • Chennai District

On-site
INR 800,000 - 1,200,000