Digital Forensics and Incident Response (DFIR) Specialist

Zoho

India

Remote

INR 1,400,000 - 2,400,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Zoho is seeking an experienced DFIR Specialist to lead post-breach investigations, containment lifecycles, and digital forensics operations on a remote/offshore basis.

The ideal candidate will isolate compromised systems, perform memory and disk analysis, reconstruct attack timelines, and preserve legally admissible evidence to guide business recovery from advanced cyber incidents. GCFA/GCIH/CCE certifications are required.

Qualifications

  • 5–8 years in core cybersecurity systems engineering.
  • 4+ dedicated years in post-breach digital forensic track assessments.
  • Strong mastery of forensic software environments (EnCase, FTK, Volatility, X-Ways).
  • Deep understanding of file systems (NTFS, EXT4, FAT) and OS log architectures.
  • Mandatory certification: GCFA, GCIH, or CCE.

Responsibilities

  • Direct high-severity incident response lifecycles, rapid threat hunting sweeps, and containment across the global network.
  • Perform deep digital forensic investigations on memory dumps, MFTs, registries, and kernel memory.
  • Reconstruct attack timelines, track persistence, C2 patterns, lateral movement, data exfiltration markers.
  • Preserve chain‑of‑custody by collecting drive images and network captures per evidentiary standards.
  • Analyze malware behaviors and scripts, reverse engineering and translating findings into IOCs.
  • Author runbooks and expert reports detailing breach roots, assets impacted, and recovery steps.
  • Collaborate with GRC and legal teams to ensure data breach notification in line with GDPR/HIPAA.

Skills

Post-breach forensics
Incident response
Memory analysis
Threat hunting
Chain of custody

Tools

EnCase
FTK
Volatility
X-Ways Forensics

Job description

Digital Forensics and Incident Response (DFIR) Specialist

Digital Forensics and Incident Response (DFIR) Specialist

  • Employment Type: Contract
  • Work Mode: Remote
  • Location: Offshore
  • Total Experience Required: 5 to 8 years
  • Relevant Experience Required: 4+ years of dedicated experience conducting digital forensics investigations and deep incident response execution
  • Mandatory Certification: GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), or Certified Computer Examiner (CCE)
Job Summary

We are seeking an experienced DFIR Specialist to lead our post-breach investigation pipelines, threat containment lifecycles, and digital forensics operations. The ideal candidate will isolate compromised systems, perform low-level disk and memory trace analyses, reconstruct complex attack timelines, and preserve legally admissible digital evidence to help the business understand and recover from advanced cyber incidents.

Key Responsibilities
  • Direct high-severity incident response lifecycles, spearheading rapid threat hunting sweeps, system isolations, and malicious compromise containment operations across the global network.
  • Perform deep digital forensic investigations, analyzing live volatile host memory dumps, master file tables (MFT), system registries, and volatile kernel memory layers.
  • Reconstruct chronological threat attack timelines, tracing advanced persistence methods, command-and-control (C2) callback patterns, lateral network movements, and data exfiltration markers.
  • Enforce rigid chain‑of‑custody data preservation parameters, collecting digital image snapshots of target drives and network captures in compliance with international legal and evidentiary standards.
  • Analyze complex malware behaviors and payload scripts, reverse engineering malicious scripts, unpacking obfuscated code loops, and translating findings into actionable local indicator blocks (IOCs).
  • Author detailed forensic investigation runbooks and expert reports, presenting clear summaries of breach roots, compromised asset matrices, data exposure volumes, and recovery steps to legal and executive stakeholders.
  • Collaborate with GRC and legal compliance teams, evaluating data breach notification requirements in accordance with corporate mandates and regional privacy laws (e.g., GDPR, HIPAA).
Requirements
  • 5 to 8 years of core cybersecurity systems engineering experience, with 4+ dedicated years actively running complex post-breach digital forensic track assessments.
  • Strong technical mastery of advanced forensic software environments (e.g., EnCase, FTK, Volatility, X-Ways Forensics), memory acquisition tools, and packet analysis suites.
  • Deep structural understanding of file system layout matrices (NTFS, EXT4, FAT), operating system log architectures, network layer packet capture parsing, and malware persistence mechanics.
  • Mandatory certification: GCFA, GCIH, or CCE.
Preferred Qualifications
  • Prior experience dealing with ransomware negotiations or navigating high-stakes ransomware containment events under tight timeline expectations.
  • Scripting background in Python or Perl used to build custom string searching queries or parse non-standard database application trace files.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager - Cybersecurity Operations
Manager - Cybersecurity Operations

Tata Communications Limited • Pune District

On-site
INR 900,000 - 1,700,000
Digital Forensics and Incident Response (DFIR) Specialist
Digital Forensics and Incident Response (DFIR) Specialist

Forensic Focus Limited • Jaipur

On-site
INR 1,800,000 - 3,200,000
Digital Forensic Analyst
Digital Forensic Analyst

Quess IT Staffing • Mumbai

On-site
INR 1,000,000 - 1,500,000
Manager - Cybersecurity Operations
Manager - Cybersecurity Operations

Tata Communications Limited • Maharashtra

On-site
INR 1,800,000 - 3,200,000
Incident Responder
Incident Responder

KPMG Assurance and Consulting Services LLP • Mumbai

On-site
INR 800,000 - 1,200,000
Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

UltraViolet Cyber • Hyderabad

On-site
INR 2,800,000 - 4,200,000
Digital Forensics and Incident Response (DFIR) Analyst
Digital Forensics and Incident Response (DFIR) Analyst

Mizuho • Chennai District

On-site
INR 2,500,000 - 4,500,000
Forensics Discovery Consultant
Forensics Discovery Consultant

EY • Gurugram District

On-site
INR 1,800,000 - 2,500,000
Incident Response & Forensics Specialist
Incident Response & Forensics Specialist

Lonvec Technologies Private Limited • Chennai District

On-site
INR 1,500,000 - 2,100,000
Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

Forensic Focus Limited • Hyderabad

On-site
INR 2,500,000 - 4,000,000