Senior Forensic Analyst

Arete IR LLP

Hyderabad

On-site

INR 1,400,000 - 2,600,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Arete Incident Response in Hyderabad, India seeks a Senior Forensic Analyst to lead forensic analyses across engagements, triage data, and identify threat actor activity. You will work with tiger teams, perform in-depth OS/memory forensics, and leverage log data to uncover IOCs and TTPs.

You will mentor analysts, prepare concise narrative findings, and deliver high-quality reports to clients and counsel. 4+ years in IR/digital forensics and relevant certifications are required.

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, Digital Forensics or related field.
  • 4+ years of incident response or digital forensics experience (or 3+ with an advanced degree).
  • Two or more certifications: Security+, Network+, GCFE/GCFA, GCIH, CEH, CHFI, EnCe.

Responsibilities

  • Lead forensic analysis to support engagements for ransomware/compromise investigations.
  • Perform forensics across OS artifacts, memory, and RAM forensics on Windows/Linux/macOS.
  • Analyze network and OS logs (Windows Event Logs, NSM, firewall, VPN).
  • Collaborate with SOC to identify IOCs and TTPs using EDR data.
  • Prepare clear, narrative findings and timelines for counsel and partners.
  • Develop attack maps using MITRE ATT&CK and Cyber Kill Chain.
  • Draft incident reports and perform peer reviews.

Skills

Windows/Linux disk forensics
Memory forensics
NSM & log analysis
Incident response
Strong communication
Team leadership

Education

Bachelor’s degree in Information Security / Computer Science / Digital Forensics

Tools

EnCase
Axiom
FTK
X-Ways
SIFT
Splunk
Volatility
Wireshark
TCPDump

Job description

SUMMARY

The Senior Forensic Analyst leads forensic analysis for projects assigned to the respective Tiger Team, collaborating with the Tiger Team and forensic leads to perform triage-level analysis of collected data (e.g., operating system files, images, SentinelOne, Logs, etc.) and perform deep-dive advanced forensic analysis. The team focuses on identifying threat actor behavior and activity, using a tailored, detailed analysis approach to identify unauthorised access and how the cyber intrusion occurred. The DFIR team operates as an industry leader in Incident Response and a trusted advisor to breach coaches and Insurance Carriers working to support Clients and help restore business operations.

ROLES & RESPONSIBILITIES
  • Leads the Forensics analysis to support the Forensic lead on engagements for Ransomware/compromise investigations
  • Works with the tiger team analysts to perform Forensic analysis of artifacts, including (but not limited to) the analysis of operating system artifacts and the recovery of deleted items from multiple operating systems including Windows, Linux, Mac, and RAM/memory forensics
  • Analyzes network and operating system log files including Windows Event logs, Unified Audit Logs, Firewall logs, VPN logs, etc
  • Works with the Security Operations Center (SOC) to leverage data from alerts provided by existing and deployed Endpoint Detection and Response (EDR) solutions to identify Indicators of Compromise (IOCs) or Tactics, Techniques, and Procedures (TTPs) for variants related to the case
  • Internally prepares Forensics findings and updates in a clear, concise manner through a narrative story outlining the timeline of events - modifies delivery in line with the call’s audience and technical capabilities
  • Employs the usage of incident-mapping frameworks while developing the attack map, such as MITRE’s ATT&CK and Lockheed Martin’s Cyber Kill Chain, to help contextualize IOCs
  • Reviews and drafts written incident, investigative updates, reports, and appendices as the explicit direction of counsel and partners based on the findings using the standard report templates.
  • Performs Peer reviews of reports written by team members
  • Delivers on the Forensic Investigations plan & works with the lead to manage the timeline, delivery, and execution of the forensic analysis across projects
  • May perform other duties as assigned by management
SKILLS AND KNOWLEDGE

Thorough knowledge of: Windows disk, Unix or Linux disk, and memory forensics Network Security Monitoring (NSM), network traffic analysis, and log analysis Experience and understanding of enterprise security controls Experienced with EnCase, Axiom, FTK, X-Ways, SIFT, Splunk, Redline, Volatility, WireShark, TCPDump, and open-source forensic tools Experience delivering technical findings to a non-technical audience, preferred Experience leading teams of analysts, preferred Provide findings in a confident, factual manner, preferred Knowledge and experience in handling PII, PHI, sensitive, confidential, and proprietary datasets, preferred Experience with Cyber insurance investigations, preferred Ability to establish priorities, work independently and proceed with objectives with minimal supervision Strong problem-solving and critical-thinking skills to identify and resolve compliance-related issues effectively Excellent verbal and written communication skills to prepare clear and concise reports and collaborate effectively with cross-functional teams Proficient in Microsoft Suite products

JOB REQUIREMENTS
  • Bachelor’s degree in Information Security, Computer Science, Digital Forensics, Cyber Security or related field and 4+ years of incident response or digital forensics experience or Master's or Advanced Degree and 3+ years related experience
  • Possess two or more of the following Certifications: Security +, Network+, SANS GCED, GCIH, GCFE, GCFA, CEH, CHFI, EnCe
DISCLAIMER

The above statements are intended to describe the general nature and level of work being performed. They are not intended to be an exhaustive list of all responsibilities, duties, and skills required by personnel so classified.

WORK ENVIRONMENT

While performing the responsibilities of this position, the work environment characteristics listed below are representative of the environment the employee will encounter: Usual office working conditions. Reasonable accommodations may be made to enable people with disabilities to perform the essential functions of this job.

TERMS OF EMPLOYMENT

Salary and benefits shall be paid consistent with Arete salary and benefit policy.

DECLARATION

The Arete Incident Response Human Resources Department retains the sole right and discretion to make changes to this job description.

EQUAL EMPLOYMENT OPPORTUNITY

We are proud to be an equal opportunity employer- and celebrate our employees’ differences, regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or Veteran status. Different makes us better. Arete Incident Response is an outstanding (and growing) company with a very dedicated, fun team.

We offer competitive salaries, fully paid benefits including Medical/Digital, Life/Disability Insurance, 401(k) and the opportunity to work with some of the latest and greatest in the fast-growing cyber security industry.

When you join Arete… You’ll be doing work that matters alongside other talented people, transforming the way people, businesses, and things connect with each other. Of course, we will offer you great pay and benefits, but we’re about more than that. Arete is a place where you can craft your own path to greatness. Whether you think in code, words, pictures or numbers, find your future at Arete, where experience matters.

Equal Employment Opportunity

We’re proud to be an equal opportunity employer- and celebrate our employees’ differences, regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or Veteran status. Different makes us better.

Arete Incident Response is an elite team of the world’s leading cybersecurity and digital forensics experts who combat today’s sophisticated cyberattacks. We work tirelessly to provide unparalleled capabilities and solutions throughout the entire cyber incident life cycle. These include incident response readiness assessments and penetration tests as well as post-incident response, remediation, containment, and eradication services. We work in close collaboration with industry leaders and government agencies along with leading cybersecurity technology platforms to deliver an innovative, intelligence-based approach to solving our client’s toughest challenges.

If you want to work with the most talented and experienced people in the industry with the desire to be a cyber hunter and industry expert, we want you to be a part of our team.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Analyst-GSOC
Senior Security Analyst-GSOC

Arete IR LLP • Hyderabad

On-site
INR 1,400,000 - 2,100,000
Senior Threat Research Consultant
Senior Threat Research Consultant

Arete IR LLP • Hyderabad

On-site
INR 2,500,000 - 4,000,000
MSS Tech Support Engineer - Intern
MSS Tech Support Engineer - Intern

Arete Advisors, LLC • Hyderabad

On-site
INR 450,000 - 750,000
Medical/Dental benefits
Life/Disability Insurance
401(k)
Regional Sales Manager III
Regional Sales Manager III

Arete IR LLP • Chennai District

Hybrid
INR 900,000 - 1,500,000
Medical/Dental
Life/Disability Insurance
401(k)
MSS Tech Support Engineer - Intern
MSS Tech Support Engineer - Intern

Arete IR LLP • Hyderabad

On-site
INR 600,000 - 1,000,000
Senior Security Analyst-GSOC
Senior Security Analyst-GSOC

Arete Advisors • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Medical/Dental benefits
Life/Disability Insurance
401(k) and retirement benefits
Senior Threat Research Consultant
Senior Threat Research Consultant

Arete • Hyderabad

Hybrid
INR 3,500,000 - 6,000,000
Sales Director – Insurance Channel
Sales Director – Insurance Channel

Arete IR LLP • Hyderabad

On-site
INR 3,000,000 - 6,000,000
Regional Sales Manager III - Remote
Regional Sales Manager III - Remote

Arete • Chennai District

On-site
INR 6,000,000 - 12,000,000
Sales Director – Insurance Channel
Sales Director – Insurance Channel

Arete • Hyderabad

On-site
INR 900,000 - 1,600,000