Sonata Software, with over $1.2 Billion Revenue, is a leading AI-first Modernization Engineering company, powered by our unique PlatformationTM framework. Our 6400+ AI Engineers are helping enterprises transform from systems to intelligent business platforms leveraging partner ecosystem to drive speed, efficiency and growth. Our bouquet of Modernization Engineering Services with AI -first approach cuts across Cloud, Data, AI, Dynamics, Test Automation, and Managed Services.
Sonata’s AI-led modernization is enabled by a powerful suite of proprietary tools and assets. At the core is the Harmoni.AI Enterprise Platform, which includes Agent Bridge-a governance and observability framework; Agent Builder-a development toolkit for fungible agents integrated into enterprise systems; and the Agent Marketplace-an internal ecosystem for modular, reusable agents.
Headquartered in Bengaluru, India, Sonata Software has a strong global presence, including key regions US, UK, India, Malaysia, Mexico, Australia, DACH (Germany/Switzerland) & Nordics (Finland). We are a trusted partner of Fortune 500 companies in Banking, Financial Services and Insurance; Healthcare and Lifesciences; Telecom, Media, and Technology; and Retail, Manufacturing and Distribution space.
JJob Title :Digital Forensics & Incident Response Engineer
Experience: 8+ years
Location :Sanjose CA(Onsite from Day 1)
Level: Senior/Staff Digital Forensics and IR Engineer
Function: Cybersecurity / Digital Forensics
Job Type: Contract
About the Role
We are seeking a highly experienced Senior Unix/Linux Infrastructure Forensics & Incident Response Engineer to join our Cybersecurity Incident Response and Digital Forensics team. The ideal candidate will have 6+ years of hands‑on experience in cybersecurity, computer forensics, infrastructure security, and incident response, preferably within a large-scale high-tech or technology enterprise.
This role will lead complex investigations involving Linux/Unix servers, cloud infrastructure, enterprise networks, applications, containers, identity systems, and production environments. The engineer will be responsible for identifying, containing, investigating, and remediating sophisticated security incidents while preserving forensic evidence and developing detection and response capabilities.
The successful candidate will be comfortable operating in high-pressure situations, conducting deep technical investigations, collaborating with engineering and security teams, and communicating findings to both technical and executive audiences.
Key Responsibilities
- Lead complex digital forensic investigations involving Unix/Linux servers, infrastructure, endpoints, cloud workloads, and enterprise applications.
- Perform forensic acquisition, preservation, analysis, and documentation of compromised systems.
- Investigate security incidents including:
- Account compromise and credential theft
- Malware and rootkits
- Lateral movement
- Persistence mechanisms
- Insider threats
- Cloud infrastructure attacks
- Analyze system artifacts including filesystem metadata, logs, processes, memory, network connections, authentication records, scheduled tasks, services, SSH activity, shell history, and persistence mechanisms.
- Conduct timeline analysis and attack reconstruction to determine initial access, attacker activity, persistence, lateral movement, and impact.
- Develop and maintain forensic playbooks, investigation procedures, and incident response methodologies.
- Perform deep forensic analysis of Linux/Unix operating systems, including RHEL, CentOS, Ubuntu, Debian, SUSE, and other enterprise distributions.
- Investigate compromised infrastructure including:
- Web servers
- Application servers
- Database servers
- DNS/DHCP infrastructure
- CI/CD infrastructure
- Build systems
- Source-code repositories
- Network infrastructure
- Analyze Linux artifacts such as /var/log, /etc, /proc, /sys, systemd, cron, SSH configuration, authentication logs, bash history, package databases, filesystem metadata, and kernel/process information.
- Investigate rootkits, kernel-level persistence, malicious binaries, unauthorized users, SSH keys, modified system services, and privilege escalation.
- Perform live-response investigations while minimizing evidence contamination.
- Participate in and lead high‑severity incident response investigations across global enterprise infrastructure.
- Develop hypotheses and conduct proactive threat hunting across Linux, cloud, identity, network, and application environments.
- Correlate forensic evidence with SIEM, EDR, network telemetry, cloud logs, authentication data, and threat intelligence.
- Identify attacker TTPs and map activity to frameworks such as MITRE ATT&CK.
- Develop indicators of compromise (IOCs), behavioral detections, and threat‑hunting queries.
- Work with SOC and detection engineering teams to convert forensic findings into scalable detection capabilities.
Cloud, Containers & Modern Infrastructure
- Investigate incidents involving AWS, Azure, GCP, and hybrid environments.
- Perform forensic analysis of cloud workloads, virtual machines, containers, Kubernetes clusters, and cloud control‑plane activity.
- Investigate compromised containers, images, orchestration infrastructure, CI/CD pipelines, and software supply chains.
- Understand cloud‑native logging, identity, networking, storage, and workload telemetry.
Malware & Artifact Analysis
- Analyze suspicious files, scripts, binaries, and system artifacts.
- Perform basic static and dynamic analysis of malware and attacker tooling.
- Identify malicious scripts involving Bash, Python, Perl, PowerShell, and other scripting languages.
- Collaborate with malware reverse engineers when deeper binary analysis is required.
- Develop Python, Bash, or other automation tools to accelerate forensic collection, triage, evidence analysis, and incident response.
- Build scalable forensic collection and investigation capabilities across thousands of enterprise systems.
- Automate IOC searches, log analysis, timeline generation, artifact collection, and evidence correlation.
- Evaluate and integrate modern DFIR and AI‑assisted investigation technologies.
- Serve as a technical lead during critical security incidents.
- Coordinate with Security Operations, Infrastructure, Cloud, Networking, IAM, Engineering, Legal, Privacy, and other stakeholders.
- Produce high‑quality forensic investigation reports, root‑cause analyses, and remediation recommendations.
- Clearly communicate technical findings, business impact, risk, and recommended actions to senior leadership.
Required Qualifications
- 6+ years of professional experience in cybersecurity, digital forensics, incident response, infrastructure security, or a related discipline.
- Strong hands‑on experience with Unix/Linux operating systems and enterprise infrastructure.
- Proven experience conducting complex computer forensic investigations and security incident response.
- Strong understanding of Linux internals, filesystems, processes, memory, networking, authentication, and system services.
- Experience investigating compromised servers and enterprise infrastructure.
- Strong knowledge of TCP/IP, DNS, HTTP/HTTPS, SSH, TLS, VPN, firewalls, proxies, and network security.
- Experience with SIEM, EDR/XDR, network security monitoring, vulnerability management, and security telemetry.
- Experience with scripting/programming languages such as Python, Bash, Perl, or PowerShell.
- Understanding of MITRE ATT&CK and modern attacker TTPs.
- Experience working in large‑scale, high‑availability high‑tech or cloud environments.
- Strong analytical, problem‑solving, documentation, and communication skills.
- Ability to work effectively during high‑severity incidents and under time‑sensitive conditions.
Preferred Qualifications
- Experience with AWS, Azure, or GCP forensics.
- Experience with Kubernetes, Docker, containers, and cloud‑native infrastructure.
- Experience with memory forensics using tools such as Volatility.
- Experience with forensic platforms and tools such as EnCase, FTK, Autopsy, Sleuth Kit, Velociraptor, KAPE, or equivalent technologies.
- Experience with Linux forensic frameworks and live‑response tooling.
Certifications
Preferred certifications include:
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Examiner (GCFE)
- GIAC Advanced Incident Response, Threat Hunting & Digital Forensics (GAIA)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Reverse Engineering Malware (GREM)
- GCFA or equivalent advanced DFIR certification
- CISSP
Core Competencies
Technical
- Threat Hunting
- Malware Analysis
- Infrastructure Security
- Identity & Authentication
- SIEM/EDR/XDR
- Detection Engineering
- Security Automation
Why join Sonata Software?
At Sonata, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build never seen before solutions to some of the world’s toughest problems. You´ll be challenged, but you will not be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
Sonata Software is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity, age, religion, disability, sexual orientation, veteran status, marital status, or any other characteristics protected by law.