Senior Cybersecurity Incident Response Specialist

Metmox

Hyderabad

On-site

INR 2,400,000 - 3,800,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Metmox is seeking an experienced Cybersecurity Incident Response Specialist in Hyderabad to own end‑to‑end incident management across enterprise environments. You will lead triage, investigation, containment, eradication, recovery, RCA, malware analysis, and digital forensics.

You will communicate findings to customers and senior stakeholders, coordinate with SOC, IT, Cloud, and Legal teams, and drive lessons learned and preventive actions.

Qualifications

  • 8-10 years of cybersecurity experience, with hands‑on IR/DFIR work.
  • Experience leading complex, high‑severity incidents and RCA.
  • Strong customer‑facing and incident‑communication skills.
  • Must be able to coordinate across multiple teams during major incidents.

Responsibilities

  • Take end‑to‑end ownership of cybersecurity incidents from detection to closure.
  • Lead investigations of critical/high incidents and coordinate across teams.
  • Perform triage, containment, eradication, recovery, and post‑incident analysis.
  • Analyze alerts from EDR/SIEM and correlate across networks, clouds, identities, and apps.
  • Develop incident timelines, map attack vectors, and determine impact.
  • Identify IOCs/TTPs and align with MITRE ATT&CK.
  • Prepare RCA reports and post‑incident reviews for customers and management.
  • Mentor junior analysts and drive incident response playbooks.

Skills

Cybersecurity Incident Response
DFIR
Threat Hunting
RCAs
Malware Analysis
Digital Forensics
Incident Management
Customer Liaison
TIMELINE Reconstruction
MITRE ATT&CK
SIEM (Splunk, Sentinel, QRadar)
EDR/XDR (CrowdStrike, Defender, Cortex
Windows/Linux Forensics
PowerShell/Python Scripting

Tools

Volatility
Autopsy
FTK
EnCase
Wireshark
Sysinternals
YARA
Ghidra
IDA

Job description

Experience: 8-10 Years


Function: Cybersecurity - Incident Response / DFIR


Role Level: Senior


We are looking for an experienced Cybersecurity Incident Response Specialist with 8-10 years of hands‑on cybersecurity experience to manage and investigate security incidents across enterprise environments. The candidate will be responsible for end‑to‑end ownership of cybersecurity incidents, including triage, investigation, containment, eradication, recovery, Root Cause Analysis (RCA), malware analysis, and digital forensic analysis. The role also requires strong customer‑facing skills to lead incident discussions, provide regular updates, explain technical findings, and present investigation outcomes and recommendations.


Key Responsibilities

Incident Response Investigation


  • Take end‑to‑end ownership of cybersecurity incidents from initial detection through closure.

  • Lead investigation of Critical, High, and complex security incidents and coordinate response activities across relevant teams.

  • Perform incident triage, scoping, containment, eradication, recovery, and post‑incident analysis.

  • Investigate incidents involving ransomware, malware, phishing, account compromise, credential theft, data exfiltration, insider threats, web attacks, lateral movement, privilege escalation, and other advanced threats.

  • Analyze security alerts and correlate information across EDR, SIEM, network, identity, cloud, email, and other security technologies.

  • Develop incident timelines and determine the attack vector, affected assets, compromised accounts, attacker activity, persistence mechanisms, and overall impact.

  • Identify Indicators of Compromise (IOCs), attacker Tactics, Techniques, and Procedures (TTPs), and map findings to the MITRE ATTCK framework.

  • Coordinate with SOC, Threat Hunting, Threat Intelligence, IT, Cloud, Network, IAM, Application, Legal, and other stakeholders during major incidents.


Root Cause Analysis (RCA)


  • Perform detailed Root Cause Analysis for security incidents.

  • Determine the initial attack vector, contributing factors, security/control gaps, and reasons existing preventive or detective controls did not stop or detect the activity earlier.

  • Conduct post‑incident reviews and lessons‑learned sessions.

  • Develop clear corrective and preventive actions based on investigation findings.

  • Track remediation recommendations with relevant stakeholders through closure.

  • Prepare comprehensive RCA reports suitable for technical teams, management, and customers.


Malware Analysis


  • Perform static and dynamic malware analysis to understand malicious file behaviour and capabilities.

  • Analyze suspicious executables, scripts, PowerShell commands, documents, URLs, and other artifacts.

  • Identify malware persistence mechanisms, command-and‑control activity, network indicators, file‑system changes, registry modifications, and related behaviors.

  • Extract IOCs and behavioral indicators for threat hunting and detection engineering.

  • Perform malware sandboxing and behavioral analysis where required.

  • Provide recommendations for detection, containment, and prevention based on malware‑analysis findings.


Digital Forensics


  • Perform digital forensic investigations on endpoints and other relevant systems.

  • Analyze Windows/Linux artifacts, event logs, file systems, registry artifacts, browser artifacts, authentication logs, memory artifacts, and other forensic evidence.

  • Perform disk and memory analysis where required.

  • Collect and preserve digital evidence following appropriate forensic procedures and chain‑of‑custody requirements.

  • Build forensic timelines and reconstruct attacker activities.

  • Determine the scope and impact of compromise using forensic evidence.

  • Document forensic findings clearly and maintain investigation evidence appropriately.


Customer Stakeholder Management


  • Act as a key technical point of contact for customers during cybersecurity incidents.

  • Lead incident calls and communicate investigation progress, impact, containment status, risks, and next steps.

  • Provide timely and accurate incident updates to customers and internal leadership.

  • Translate complex technical investigation findings into clear business‑level communication.

  • Manage customer expectations during high‑severity and time‑sensitive incidents.

  • Present RCA and forensic investigation findings to customers and senior stakeholders.

  • Handle technical questions and confidently explain investigation methodology, evidence, conclusions, and recommendations.

  • Coordinate with multiple internal and customer teams to drive incidents toward timely resolution.


Incident Reporting Documentation


  • Prepare detailed incident investigation reports, including:

    • o Executive summary

    • o Incident timeline

    • o Scope and impact

    • o Root cause

    • o Attack vector

    • o IOCs and TTPs

    • o Investigation findings

    • o Containment and remediation actions

    • o Control gaps

    • o Corrective and preventive recommendations

    • o Lessons learned



  • Maintain accurate incident records, evidence, investigation notes, and supporting documentation.

  • Contribute to the development and improvement of Incident Response playbooks, SOPs, investigation procedures, and escalation processes.


Required Technical Skills


  • Cybersecurity Incident Response / DFIR

  • Security Incident Investigation

  • Root Cause Analysis (RCA)

  • Digital Forensics

  • Malware Analysis

  • Threat Hunting

  • Endpoint and Network Investigation

  • Windows and Linux Forensics

  • Disk and Memory Analysis

  • Log Analysis and Timeline Reconstruction

  • IOC and TTP Analysis

  • MITRE ATTCK Framework

  • SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, or similar

  • EDR/XDR platforms such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Cortex XDR, or similar

  • Network security technologies including Firewall, IDS/IPS, Proxy, DNS, VPN, and WAF

  • Cloud security investigation across AWS, Azure, and/or GCP environments

  • Identity and authentication‑related investigations

  • Email and phishing investigations

  • Forensic and malware‑analysis tools such as Volatility, Autopsy, FTK, EnCase, Wireshark, Sysinternals, YARA, Ghidra, IDA, or equivalent tools

  • Scripting/automation using Python, PowerShell, or similar technologies would be an advantage.


Required Experience


  • 8-10 years of overall cybersecurity experience, with significant hands‑on experience in Incident Response, DFIR, SOC, Threat Hunting, or related security domains.

  • Demonstrated experience independently handling complex and high‑severity cybersecurity incidents.

  • Strong experience conducting RCA and presenting investigation findings.

  • Hands‑on experience with malware and forensic investigations.

  • Experience handling customer‑facing security incidents and leading technical/customer incident calls.

  • Experience coordinating investigations involving multiple technical and business teams.

  • Ability to work effectively under pressure during Critical/High‑severity incidents.

  • Strong analytical, troubleshooting, and problem‑solving skills.


Communication Leadership Skills


  • Excellent verbal and written communication skills.

  • Strong customer‑facing and stakeholder‑management capabilities.

  • Ability to communicate effectively with both technical and non‑technical stakeholders.

  • Ability to lead incident bridges/calls during critical incidents.

  • Strong documentation and report‑writing skills.

  • Ability to take ownership, make investigation decisions, and drive incidents to closure.

  • Ability to mentor junior Incident Response/SOC analysts and provide technical guidance during investigations.


We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.


Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

UltraViolet Cyber • Hyderabad

On-site
INR 2,800,000 - 4,200,000
Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

Uvcyber • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Sr SUPPORT ENGINEER - Cyber Security
Sr SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 800,000 - 1,500,000
Senior Cyber Security Analyst (R-19638)
Senior Cyber Security Analyst (R-19638)

Eyeota • Hyderabad

On-site
INR 1,100,000 - 2,400,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,500,000 - 2,800,000
Cybersecurity Incident Response Specialist
Cybersecurity Incident Response Specialist

Achieve Cybersecurity Solutions • Hyderabad

On-site
INR 2,500,000 - 4,200,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

On-site
INR 1,500,000 - 2,100,000
Flexible/Remote work
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Dun & Bradstreet • Hyderabad

Hybrid
INR 2,500,000 - 4,500,000
SENIOR SUPPORT ENGINEER - Cyber Security
SENIOR SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 2,400,000 - 4,200,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000