Staff Engineer, Digital Forensics & Incident Response

Rakuten Kobo Inc.

Bengaluru

On-site

INR 4,000,000 - 7,000,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Rakuten Mobile seeks a Senior DFIR Lead to join its Security Engineering & Operations Supervisory Department in Bengaluru. You will lead investigations, perform deep-dive forensics across endpoints, networks, and cloud, and translate findings into persistent defenses.

The role requires 10–12 years in cybersecurity with a strong DFIR mindset and regulatory-compliant reporting.

Qualifications

  • 10–12 years of cybersecurity with emphasis on DFIR.
  • Bachelor’s degree or equivalent practical experience.
  • GCFA/GCFE/GNFA/CISSP or equivalent preferred.
  • Experience in telecom security incident response.

Responsibilities

  • Lead end-to-end incident response investigations.
  • Perform deep-dive forensic analysis of endpoints, networks, and cloud.
  • Develop incident response playbooks and SOPs for threat scenarios.
  • Collaborate with Legal, Privacy, and IT for evidence handling and regulatory compliance.
  • Mentor junior analysts and ensure report quality.
  • Maintain 24/7 readiness for major incidents.

Skills

Digital Forensics
Incident Response
Kubernetes Forensics
Container Forensics
Memory Forensics
Network Forensics
Threat Hunting
Python Scripting
Reporting Skills
MITRE ATT&CK

Education

Bachelor's in CS/Cybersecurity/IS
Equivalent practical experience
Certifications: GCFA/GCFE/GNFA/CISSP

Tools

EnCase
FTK
Magnet AXIOM
Volatility

Job description

Job Description: Description: The Security Engineering & Operations Supervisory Department at Rakuten Mobile is seeking a Senior DFIR Lead to join a growing cyber defense organization. The candidate will serve as a lead responder for complex security incidents, performing deep-dive forensic investigations, root cause analysis, and containment activities. This role is ideal for a seasoned investigator who thrives under pressure, possesses a forensic mindset, and can turn incident findings into strategic improvements that harden our environment against future threats.

Responsibilities

Lead and execute end-to-end incident response investigations, from initial triage and scoping to containment, eradication, and recovery. Perform deep-dive forensic analysis of endpoints, network traffic, and cloud environments to reconstruct intrusion chains and identify the scope of compromise. Conduct advanced malware analysis (static and dynamic) to understand adversary capabilities, persistence mechanisms, and command-and-control (C2) infrastructure. Develop and maintain incident response playbooks and standard operating procedures (SOPs) for various threat scenarios, ensuring alignment with industry best practices. Collaborate with the Threat Hunting and Detection Engineering teams to provide "lessons learned" from investigations, ensuring that incident findings are converted into permanent detection logic. Partner with Legal, Privacy, and IT stakeholders during high-stakes incidents to ensure proper evidence handling, chain-of-custody, and regulatory compliance. Utilize advanced forensic tools (e.g., EnCase, FTK, Magnet AXIOM, Volatility) and SIEM/EDR platforms to conduct investigations and validate findings. Automate forensic collection and analysis processes using scripting languages (e.g., Python, PowerShell) to reduce time-to-respond during critical incidents. Provide mentorship to junior analysts, conducting peer reviews of forensic reports and overseeing the technical quality of investigations. Maintain a high level of readiness for 24/7 incident response support, providing expert guidance during major security breaches.

Requirements
Qualifications

Minimum of 10-12 years of experience in cybersecurity, with significant expertise in Digital Forensics and Incident Response. Bachelor’s degree in computer science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience. Industry certifications such as SANS GCFA, GCFE, GNFA, or CISSP are highly preferred.

Required Skills & Knowledge

Expertise in forensic artifacts across major Operating Systems (Windows, Linux, macOS), including file system analysis, memory forensics, and registry/log analysis. Deep expertise in investigating security incidents within telecommunications environments. Ability to perform forensic analysis on mobile core network elements, identifying anomalies in signaling protocols (e.g., 4G/5G, SS7, Diameter, GTP, HTTP/2). Experience in tracing malicious activity across complex, high-throughput telecom traffic flows. Proven experience conducting incident response in containerized environments. Ability to perform runtime forensics within Kubernetes (K8s) clusters, including container breakout analysis, pod-level log correlation, and forensic inspection of ephemera storage. Deep understanding of K8s API audit logs, etcd integrity, and the forensic implications of container orchestration In-depth knowledge of the MITRE ATT&CK framework for mapping adversary behavior during investigations and identifying gaps in current security controls. Strong understanding of enterprise network architecture and protocols, with the ability to perform full-packet capture analysis to identify malicious traffic patterns. Deep understanding of cloud-native environments, including Kubernetes and container orchestration; proven experience performing incident response within AWS, Azure, or GCP. Experience leveraging advanced AI/ML capabilities, including LLMs, to assist in log correlation, code analysis, and the summarization of complex incident timelines. Exceptional analytical expertise, critical thinking, and the ability to remain calm and methodical under high-pressure, time-sensitive situations. Excellent written and verbal communication skills, with the ability to produce high-quality, court-admissible forensic reports for both technical and executive audiences. Demonstrated strong documentation discipline, capable of maintaining strict chain-of-custody and producing repeatable, defensible investigation results. Ability to work effectively in a fast-paced environment, with flexibility for non-standard work hours during active incident response operations. Strong aptitude for continuous learning, particularly regarding emerging attacker tradecraft and new forensic methodologies.

Rakuten Symphony is reimagining telecom, changing supply chain norms and disrupting outmoded thinking that threatens the industry’s pursuit of rapid innovation and growth. Based on proven modern infrastructure practices, its open interface platforms make it possible to launch and operate advanced mobile services in a fraction of the time and cost of conventional approaches, with no compromise to network quality or security. Rakuten Symphony has operations in Japan, the United States, Singapore, India, South Korea, Europe, and the Middle East Africa region. For more information, visit: https://symphony.rakuten.com Building on the technology Rakuten used to launch Japan’s newest mobile network, we are taking our mobile offering global. To support our ambitions to provide an innovative cloud-native telco platform for our customers, Rakuten Symphony is looking to recruit and develop top talent from around the globe. We are looking for individuals to join our team across all functional areas of our business – from sales to engineering, support functions to product development. Let’s build the future of mobile telecommunications together!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Threat Investigator
Cyber Threat Investigator

Rakuten Symphony • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Senior Engineer 2, DevOps
Senior Engineer 2, DevOps

Rakuten Kobo Inc. • Bengaluru

On-site
INR 900,000 - 1,500,000
Competitive salary and benefits
Sr. Engineer 2, DevOps
Sr. Engineer 2, DevOps

Rakuten Kobo Inc. • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Staff Engineer, RCS
Staff Engineer, RCS

Rakuten Kobo Inc. • Bengaluru

On-site
INR 2,500,000 - 4,200,000
Operational Specialist
Operational Specialist

Rakuten Symphony • Bengaluru

On-site
INR 900,000 - 1,500,000
Technical Lead, AI/ML
Technical Lead, AI/ML

Rakuten Symphony • Bengaluru

On-site
INR 2,500,000 - 4,200,000
Specialist, Core Network AI & Automation
Specialist, Core Network AI & Automation

Rakuten Kobo Inc. • India

On-site
INR 3,500,000 - 6,000,000
Automation Engineer
Automation Engineer

Rakuten Symphony • Bengaluru Urban

On-site
INR 1,000,000 - 1,500,000
Specialist - Core Network AI & Automation
Specialist - Core Network AI & Automation

Rakuten Symphony • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Software Engineer 2 Cloud
Software Engineer 2 Cloud

Rakuten Symphony • Indore District

On-site
INR 1,500,000 - 2,800,000