Job Description
San Jose, California, United States
8 - 14 Years
Permanent
About Sonata Software
Sonata Software, with over $1.2 Billion Revenue, is a leading AI-first Modernization Engineering company, powered by our unique PlatformationTM framework. Our 6400+ AI Engineers are helping enterprises transform from systems to intelligent business platforms leveraging partner ecosystem to drive speed, efficiency and growth. Our bouquet of Modernization Engineering Services with AI -first approach cuts across Cloud, Data, AI, Dynamics, Test Automation, and Managed Services.
Sonata’s AI-led modernization is enabled by a powerful suite of proprietary tools and assets. At the core is the Harmoni.AI Enterprise Platform, which includes Agent Bridge-a governance and observability framework; Agent Builder-a development toolkit for fungible agents integrated into enterprise systems; and the Agent Marketplace-an internal ecosystem for modular, reusable agents.
Headquartered in Bengaluru, India, Sonata Software has a strong global presence, including key regions US, UK, India, Malaysia, Mexico, Australia, DACH (Germany/Switzerland) & Nordics (Finland). We are a trusted partner of Fortune 500 companies in Banking, Financial Services and Insurance; Healthcare and Lifesciences; Telecom, Media, and Technology; and Retail, Manufacturing and Distribution space.
Job Title : Digital Forensics & Incident Response Engineer
Experience: 8+ years
Location : Sanjose CA (Onsite from Day 1)
Level: Senior/Staff Digital Forensics and IR Engineer
Function: Cybersecurity / Digital Forensics
Job Type: Contract
About the Role
We are seeking a highlyexperienced Senior Unix/Linux Infrastructure Forensics & Incident ResponseEngineer to join our Cybersecurity Incident Response and Digital Forensicsteam. The ideal candidate will have 6+ years of hands-on experience in cybersecurity,computer forensics, infrastructure security, and incident response, preferablywithin a large-scale high-tech or technology enterprise.
This role will lead complexinvestigations involving Linux/Unix servers, cloud infrastructure, enterprisenetworks, applications, containers, identity systems, and productionenvironments. The engineer will be responsible for identifying, containing, investigating,and remediating sophisticated security incidents while preserving forensicevidence and developing detection and response capabilities.
The successful candidatewill be comfortable operating in high-pressure situations, conducting deeptechnical investigations, collaborating with engineering and security teams,and communicating findings to both technical and executive audiences.
Key Responsibilities
- Leadcomplex digital forensic investigations involving Unix/Linux servers,infrastructure, endpoints, cloud workloads, and enterprise applications.
- Performforensic acquisition, preservation, analysis, and documentation ofcompromised systems.
- Investigatesecurity incidents including:
- Accountcompromise and credential theft
- Malwareand rootkits
- Privilegeescalation
- Lateralmovement
- Persistencemechanisms
- Dataexfiltration
- Insiderthreats
- Supply-chaincompromises
- Web/applicationserver compromises
- Cloudinfrastructure attacks
- Analyzesystem artifacts including filesystem metadata, logs, processes, memory,network connections, authentication records, scheduled tasks, services,SSH activity, shell history, and persistence mechanisms.
- Conducttimeline analysis and attack reconstruction to determine initial access,attacker activity, persistence, lateral movement, and impact.
- Developand maintain forensic playbooks, investigation procedures, and incidentresponse methodologies.
- Performdeep forensic analysis of Linux/Unix operating systems, including RHEL,CentOS, Ubuntu, Debian, SUSE, and other enterprise distributions.
- Investigatecompromised infrastructure including:
- Webservers
- Applicationservers
- Databaseservers
- DNS/DHCPinfrastructure
- Authenticationservices
- Kubernetes/containerhosts
- CI/CDinfrastructure
- Buildsystems
- Source-coderepositories
- Networkinfrastructure
- AnalyzeLinux artifacts such as /var/log, /etc, /proc, /sys, systemd, cron, SSHconfiguration, authentication logs, bash history, package databases,filesystem metadata, and kernel/process information.
- Investigaterootkits, kernel-level persistence, malicious binaries, unauthorizedusers, SSH keys, modified system services, and privilege escalation.
- Performlive-response investigations while minimizing evidence contamination.
- Participatein and lead high-severity incident response investigations across globalenterprise infrastructure.
- Develophypotheses and conduct proactive threat hunting across Linux, cloud,identity, network, and application environments.
- Correlateforensic evidence with SIEM, EDR, network telemetry, cloud logs,authentication data, and threat intelligence.
- Identifyattacker TTPs and map activity to frameworks such as MITRE ATT&CK.
- Developindicators of compromise (IOCs), behavioral detections, and threat-huntingqueries.
- Workwith SOC and detection engineering teams to convert forensic findings intoscalable detection capabilities.
Cloud, Containers & ModernInfrastructure
- Investigateincidents involving AWS, Azure, GCP, and hybrid environments.
- Performforensic analysis of cloud workloads, virtual machines, containers,Kubernetes clusters, and cloud control-plane activity.
- Investigatecompromised containers, images, orchestration infrastructure, CI/CDpipelines, and software supply chains.
- Understandcloud-native logging, identity, networking, storage, and workloadtelemetry.
Malware & Artifact Analysis
- Analyzesuspicious files, scripts, binaries, and system artifacts.
- Performbasic static and dynamic analysis of malware and attacker tooling.
- Identifymalicious scripts involving Bash, Python, Perl, PowerShell, and otherscripting languages.
- Collaboratewith malware reverse engineers when deeper binary analysis is required.
- DevelopPython, Bash, or other automation tools to accelerate forensic collection,triage, evidence analysis, and incident response.
- Buildscalable forensic collection and investigation capabilities acrossthousands of enterprise systems.
- AutomateIOC searches, log analysis, timeline generation, artifact collection, andevidence correlation.
- Evaluateand integrate modern DFIR and AI-assisted investigation technologies.
- Serveas a technical lead during critical security incidents.
- Coordinatewith Security Operations, Infrastructure, Cloud, Networking, IAM,Engineering, Legal, Privacy, and other stakeholders.
- Producehigh-quality forensic investigation reports, root-cause analyses, andremediation recommendations.
- Clearlycommunicate technical findings, business impact, risk, and recommendedactions to senior leadership.
Required Qualifications
- 6+years of professional experience in cybersecurity, digital forensics,incident response, infrastructure security, or a related discipline.
- Stronghands-on experience with Unix/Linux operating systems and enterpriseinfrastructure.
- Provenexperience conducting complex computer forensic investigations andsecurity incident response.
- Strongunderstanding of Linux internals, filesystems, processes, memory,networking, authentication, and system services.
- Experienceinvestigating compromised servers and enterprise infrastructure.
- Strongknowledge of TCP/IP, DNS, HTTP/HTTPS, SSH, TLS, VPN, firewalls, proxies,and network security.
- Experiencewith SIEM, EDR/XDR, network security monitoring, vulnerability management,and security telemetry.
- Experiencewith scripting/programming languages such as Python, Bash, Perl, orPowerShell.
- Understandingof MITRE ATT&CK and modern attacker TTPs.
- Experienceworking in large-scale, high-availability high-tech or cloud environments.
- Stronganalytical, problem-solving, documentation, and communication skills.
- Abilityto work effectively during high-severity incidents and undertime-sensitive conditions.
Preferred Qualifications
- Experiencewith AWS, Azure, or GCP forensics.
- Experiencewith Kubernetes, Docker, containers, and cloud-native infrastructure.
- Experiencewith memory forensics using tools such as Volatility.
- Experiencewith forensic platforms and tools such as EnCase, FTK, Autopsy, SleuthKit, Velociraptor, KAPE, or equivalent technologies.
- Experiencewith Linux forensic frameworks and live-response tooling.
- Experiencewith malware analysis and reverse engineering.
- Knowledgeof identity attacks involving Active Directory, LDAP, Kerberos, SSO,OAuth, and cloud identity.
- Experienceinvestigating software supply-chain and CI/CD compromises.
- Experiencewith threat intelligence and adversary tracking.
- Experiencebuilding automated DFIR capabilities at enterprise scale.
- Experienceusing AI/ML technologies to enhance threat hunting, forensic analysis, andincident response.
Certifications
Preferred certifications include:
- GIACCertified Incident Handler (GCIH)
- GIACCertified Forensic Examiner (GCFE)
- GIACAdvanced Incident Response, Threat Hunting & Digital Forensics (GAIA)
- GIACCertified Intrusion Analyst (GCIA)
- GIACReverse Engineering Malware (GREM)
- GCFAor equivalent advanced DFIR certification
- CISSP
Core Competencies
Technical
- ThreatHunting
- MalwareAnalysis
- InfrastructureSecurity
- SIEM/EDR/XDR
- DetectionEngineering
- SecurityAutomation
Leadership
- Crisismanagement
- Securityinvestigation strategy
Why join Sonata Software?
At Sonata, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build never seen before solutions to some of the world’s toughest problems. You´ll be challenged, but you will not be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
Sonata Software is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity, age, religion, disability, sexual orientation, veteran status, marital status, or any other characteristics protected by law.