Forensics Discovery Consultant

EY

Gurugram District

On-site

INR 1,800,000 - 2,500,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

EY in Gurgaon is seeking a Consultant-National-Forensics-ASU forensics discovery role. The person will investigate security incidents, perform digital forensics, and assist in containment and remediation across industries.

Strong DFIR expertise, scripting skills, and familiarity with leading forensic tools are required. The role emphasizes handling endpoint, network, and cloud data, documenting investigations, and preparing detailed reports for stakeholders.

Qualifications

  • 24 years of experience in DFIR investigations.
  • Bachelor's degree in IT/CS or equivalent experience.
  • Preferred certifications: GIAC GCIH / GCFA, CEH/ CHFI, Tool specific such as EnCE and FTK AccessData Certified Examiner, or in any SIEM tool related.

Responsibilities

  • DFIR Analyst is responsible for investigating security incidents, analysing digital evidence and helping in containment and remediation of cyber security incident.
  • Understand incident details, affected systems, business impact and available infrastructure context.
  • Identify relevant evidence sources, including logs, endpoint data, network data and security platform telemetry.
  • Review alerts and logs from SIEM, EDR, SOAR, IDS/IPS, email security and other available sources.
  • Validate suspicious activity and correlate events to reconstruct the probable attack path.
  • Support initial containment actions such as endpoint isolation, IOC blocking and access restriction.
  • Acquire forensic images, memory captures, logs and volatile data using approved procedures and tools.
  • Preserve evidence integrity by minimizing contamination and maintaining proper chain-of-custody records.
  • Analyse forensic artifacts such as event logs, registry, prefetch, LNK files, browser artifacts, metadata and EDR telemetry.
  • Investigate endpoint, malware, email and network indicators to identify persistence, lateral movement, exfiltration and root cause.
  • Enrich indicators using threat intelligence sources and map attacker behaviour to MITRE ATT&CK techniques.
  • Prepare triage and investigation reports covering timelines, findings, impact, corrective actions and recommendations.

Skills

Incident response
Forensic analysis
PowerShell or Python scripting
Log analysis
Endpoint investigation
Threat intelligence

Education

Bachelor of Technology in Computer Science
Bachelor's degree in IT/CS

Tools

Autopsy
Sleuth Kit
FTK Imager
EnCase
Cellebrite
Volatility
Microsoft Defender XDR
CrowdStrike Falcon
SentinelOne
Carbon Black
Splunk
Elastic
Microsoft Sentinel
QRadar
Wireshark

Job description

Job Summary

The opportunity: Consultant-National-Forensics-ASU - Forensics - Discovery - Gurgaon. National comprises of sector agnostic teams working across industries for a well rounded experience. ASU - Forensics - Discovery: Successful organizations depend on their reputation for keeping promises, respecting laws and behaving ethically to maintain stakeholder trust. EY Forensic & Integrity Services professionals help organizations protect and restore enterprise and financial reputation. We assist companies and their legal counsel to investigate facts, resolve disputes and manage regulatory challenges. We put integrity at the heart of compliance programs to help better manage ethical and reputational risks.

Your key responsibilities
  • DFIR Analyst is responsible for investigating security incidents, analysing digital evidence and helping in containment and remediation of cyber security incident. The Analyst should be having experience on hands-on investigations, triage, evidence collection and documentation of complex cyber security incidents.
  • Understand incident details, affected systems, business impact and available infrastructure context.
  • Identify relevant evidence sources, including logs, endpoint data, network data and security platform telemetry.
  • Review alerts and logs from SIEM, EDR, SOAR, IDS/IPS, email security and other available sources.
  • Validate suspicious activity and correlate events to reconstruct the probable attack path.
  • Support initial containment actions such as endpoint isolation, IOC blocking and access restriction.
  • Acquire forensic images, memory captures, logs and volatile data using approved procedures and tools.
  • Preserve evidence integrity by minimizing contamination and maintaining proper chain-of-custody records.
  • Analyse forensic artifacts such as event logs, registry, prefetch, LNK files, browser artifacts, metadata and EDR telemetry.
  • Investigate endpoint, malware, email and network indicators to identify persistence, lateral movement, exfiltration and root cause.
  • Enrich indicators using threat intelligence sources and map attacker behaviour to MITRE ATT&CK techniques.
  • Prepare triage and investigation reports covering timelines, findings, impact, corrective actions and recommendations.
Tools & Technology Knowledge
  • Hands-on knowledge of forensic tools such as Autopsy, Sleuth Kit, FTK Imager, EnCase, Cellebrite and Volatility.
  • Working familiarity with EDR and incident response platforms including Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne and Carbon Black.
  • Ability to analyze logs using SIEM and log analytics platforms such as Splunk, Elastic, Microsoft Sentinel and QRadar.
  • Basic understanding of network and packet analysis tools including Wireshark, NetFlow analyzers and related investigation utilities.
  • Awareness of malware analysis and triage tools such as KAPE, sandbox platforms, VirusTotal and OTX.
Required Skills and Competencies
  • Strong understanding of Windows and Linux internals, Active Directory and common cloud platforms such as AWS and Azure.
  • Knowledge of common cyber-attack techniques, including phishing, ransomware, credential theft and lateral movement.
  • Ability to review logs, identify anomalies and correlate suspicious activities across multiple evidence sources.
  • Basic scripting capability in PowerShell or Python to support investigation automation and data analysis.
  • Strong analytical, troubleshooting and communication skills during incident response activities.
  • Ability to work under pressure while maintaining attention to detail in evidence handling and documentation.
Experience & Qualifications
  • 24 years of experience in DFIR investigations.
  • Bachelors degree in IT/CS or equivalent experience.
  • Preferred certifications: GIAC GCIH / GCFA, CEH/ CHFI, Tool specific such as EnCE and FTK AccessData Certified Examiner, or in any SIEM tool related.
Qualifications
  • Bachelor of Technology in Computer Science
Experience
  • Frontend Development (2+ years)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Forensics Discovery Consultant
Forensics Discovery Consultant

EY • Hyderabad

On-site
INR 900,000 - 1,300,000
Senior Forensics Discovery Analyst
Senior Forensics Discovery Analyst

EY • Hyderabad

On-site
INR 800,000 - 1,200,000
Forensics Manager
Forensics Manager

EY • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Senior Forensics Consultant
Senior Forensics Consultant

EY • Bengaluru

On-site
INR 1,500,000 - 2,300,000
Consultant - Forensics - National - ASU - Forensics - Discovery - Gurgaon
Consultant - Forensics - National - ASU - Forensics - Discovery - Gurgaon

Ernst & Young Advisory Services Sdn Bhd • Gurugram District

On-site
INR 1,200,000 - 1,800,000
Consultant - Forensics - National - ASU - Forensics - Discovery - Gurgaon
Consultant - Forensics - National - ASU - Forensics - Discovery - Gurgaon

EY • Gurugram District

On-site
INR 900,000 - 1,300,000
Digital Forensic Analyst
Digital Forensic Analyst

Quess IT Staffing • Mumbai

On-site
INR 1,000,000 - 1,500,000
Forensics Consultant
Forensics Consultant

EY • Bengaluru

On-site
INR 2,000,000 - 2,800,000
Associate Consultant-Forensics-National-ASU
Associate Consultant-Forensics-National-ASU

EY • Gurugram District

On-site
INR 600,000 - 900,000
Consultant - Forensics - National - ASU - Forensics - Discovery - Hyderabad
Consultant - Forensics - National - ASU - Forensics - Discovery - Hyderabad

Ernst & Young Advisory Services Sdn Bhd • Hyderabad

On-site
INR 1,200,000 - 1,800,000