Digital Forensics & Incident Response Engineer

Darwinbox Digital Solutions Pvt. Ltd.

San Jose (CA)

On-site

USD 130,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Sonata Software in San Jose, CA seeks a Senior/Staff Digital Forensics and Incident Response Engineer to lead complex investigations, preserve evidence, and develop robust IR playbooks across Linux/Unix, cloud, containers, and enterprise networks.

You will coordinate with SOC and detection engineering teams, translate findings for technical and executive audiences, and drive proactive threat hunting and incident response improvements.

Qualifications

  • 6+ years of professional experience in cybersecurity, digital forensics, incident response, or a related discipline.
  • Strong hands-on experience with Unix/Linux operating systems and enterprise infrastructure.
  • Proven ability to conduct complex computer forensic investigations and security incident response.
  • Understanding of MITRE ATT&CK and modern attacker TTPs.
  • Experience working in large-scale, high-availability cloud environments.

Responsibilities

  • Lead complex digital forensic investigations involving Unix/Linux servers, infrastructure, endpoints, cloud workloads, and enterprise applications.
  • Perform forensic acquisition, preservation, analysis, and documentation of compromised systems.
  • Investigate security incidents including account compromise, malware, privilege escalation, data exfiltration, and insider threats.
  • Develop and maintain forensic playbooks, procedures, and incident response methodologies.
  • Coordinate with SOC and engineering teams to translate findings into scalable detections.

Skills

Unix/Linux
Incident response
Digital forensics
Security analytics
Scripting (Python/Bash)

Tools

EnCase
FTK
Autopsy
SleuthKit
Velociraptor
KAPE

Job description

Job Description

San Jose, California, United States

8 - 14 Years

Permanent

About Sonata Software

Sonata Software, with over $1.2 Billion Revenue, is a leading AI-first Modernization Engineering company, powered by our unique PlatformationTM framework. Our 6400+ AI Engineers are helping enterprises transform from systems to intelligent business platforms leveraging partner ecosystem to drive speed, efficiency and growth. Our bouquet of Modernization Engineering Services with AI -first approach cuts across Cloud, Data, AI, Dynamics, Test Automation, and Managed Services.

Sonata’s AI-led modernization is enabled by a powerful suite of proprietary tools and assets. At the core is the Harmoni.AI Enterprise Platform, which includes Agent Bridge-a governance and observability framework; Agent Builder-a development toolkit for fungible agents integrated into enterprise systems; and the Agent Marketplace-an internal ecosystem for modular, reusable agents.

Headquartered in Bengaluru, India, Sonata Software has a strong global presence, including key regions US, UK, India, Malaysia, Mexico, Australia, DACH (Germany/Switzerland) & Nordics (Finland). We are a trusted partner of Fortune 500 companies in Banking, Financial Services and Insurance; Healthcare and Lifesciences; Telecom, Media, and Technology; and Retail, Manufacturing and Distribution space.

Job Title : Digital Forensics & Incident Response Engineer
Experience: 8+ years
Location : Sanjose CA (Onsite from Day 1)
Level: Senior/Staff Digital Forensics and IR Engineer
Function: Cybersecurity / Digital Forensics
Job Type: Contract
About the Role

We are seeking a highlyexperienced Senior Unix/Linux Infrastructure Forensics & Incident ResponseEngineer to join our Cybersecurity Incident Response and Digital Forensicsteam. The ideal candidate will have 6+ years of hands-on experience in cybersecurity,computer forensics, infrastructure security, and incident response, preferablywithin a large-scale high-tech or technology enterprise.

This role will lead complexinvestigations involving Linux/Unix servers, cloud infrastructure, enterprisenetworks, applications, containers, identity systems, and productionenvironments. The engineer will be responsible for identifying, containing, investigating,and remediating sophisticated security incidents while preserving forensicevidence and developing detection and response capabilities.

The successful candidatewill be comfortable operating in high-pressure situations, conducting deeptechnical investigations, collaborating with engineering and security teams,and communicating findings to both technical and executive audiences.

Key Responsibilities
  • Leadcomplex digital forensic investigations involving Unix/Linux servers,infrastructure, endpoints, cloud workloads, and enterprise applications.
  • Performforensic acquisition, preservation, analysis, and documentation ofcompromised systems.
  • Investigatesecurity incidents including:
    • Accountcompromise and credential theft
    • Malwareand rootkits
    • Privilegeescalation
    • Lateralmovement
    • Persistencemechanisms
    • Dataexfiltration
    • Insiderthreats
    • Supply-chaincompromises
    • Web/applicationserver compromises
    • Cloudinfrastructure attacks
  • Analyzesystem artifacts including filesystem metadata, logs, processes, memory,network connections, authentication records, scheduled tasks, services,SSH activity, shell history, and persistence mechanisms.
  • Conducttimeline analysis and attack reconstruction to determine initial access,attacker activity, persistence, lateral movement, and impact.
  • Developand maintain forensic playbooks, investigation procedures, and incidentresponse methodologies.
  • Performdeep forensic analysis of Linux/Unix operating systems, including RHEL,CentOS, Ubuntu, Debian, SUSE, and other enterprise distributions.
  • Investigatecompromised infrastructure including:
    • Webservers
    • Applicationservers
    • Databaseservers
    • DNS/DHCPinfrastructure
    • Authenticationservices
    • Kubernetes/containerhosts
    • CI/CDinfrastructure
    • Buildsystems
    • Source-coderepositories
    • Networkinfrastructure
  • AnalyzeLinux artifacts such as /var/log, /etc, /proc, /sys, systemd, cron, SSHconfiguration, authentication logs, bash history, package databases,filesystem metadata, and kernel/process information.
  • Investigaterootkits, kernel-level persistence, malicious binaries, unauthorizedusers, SSH keys, modified system services, and privilege escalation.
  • Performlive-response investigations while minimizing evidence contamination.
  • Participatein and lead high-severity incident response investigations across globalenterprise infrastructure.
  • Develophypotheses and conduct proactive threat hunting across Linux, cloud,identity, network, and application environments.
  • Correlateforensic evidence with SIEM, EDR, network telemetry, cloud logs,authentication data, and threat intelligence.
  • Identifyattacker TTPs and map activity to frameworks such as MITRE ATT&CK.
  • Developindicators of compromise (IOCs), behavioral detections, and threat-huntingqueries.
  • Workwith SOC and detection engineering teams to convert forensic findings intoscalable detection capabilities.
Cloud, Containers & ModernInfrastructure
  • Investigateincidents involving AWS, Azure, GCP, and hybrid environments.
  • Performforensic analysis of cloud workloads, virtual machines, containers,Kubernetes clusters, and cloud control-plane activity.
  • Investigatecompromised containers, images, orchestration infrastructure, CI/CDpipelines, and software supply chains.
  • Understandcloud-native logging, identity, networking, storage, and workloadtelemetry.
Malware & Artifact Analysis
  • Analyzesuspicious files, scripts, binaries, and system artifacts.
  • Performbasic static and dynamic analysis of malware and attacker tooling.
  • Identifymalicious scripts involving Bash, Python, Perl, PowerShell, and otherscripting languages.
  • Collaboratewith malware reverse engineers when deeper binary analysis is required.
  • DevelopPython, Bash, or other automation tools to accelerate forensic collection,triage, evidence analysis, and incident response.
  • Buildscalable forensic collection and investigation capabilities acrossthousands of enterprise systems.
  • AutomateIOC searches, log analysis, timeline generation, artifact collection, andevidence correlation.
  • Evaluateand integrate modern DFIR and AI-assisted investigation technologies.
  • Serveas a technical lead during critical security incidents.
  • Coordinatewith Security Operations, Infrastructure, Cloud, Networking, IAM,Engineering, Legal, Privacy, and other stakeholders.
  • Producehigh-quality forensic investigation reports, root-cause analyses, andremediation recommendations.
  • Clearlycommunicate technical findings, business impact, risk, and recommendedactions to senior leadership.
Required Qualifications
  • 6+years of professional experience in cybersecurity, digital forensics,incident response, infrastructure security, or a related discipline.
  • Stronghands-on experience with Unix/Linux operating systems and enterpriseinfrastructure.
  • Provenexperience conducting complex computer forensic investigations andsecurity incident response.
  • Strongunderstanding of Linux internals, filesystems, processes, memory,networking, authentication, and system services.
  • Experienceinvestigating compromised servers and enterprise infrastructure.
  • Strongknowledge of TCP/IP, DNS, HTTP/HTTPS, SSH, TLS, VPN, firewalls, proxies,and network security.
  • Experiencewith SIEM, EDR/XDR, network security monitoring, vulnerability management,and security telemetry.
  • Experiencewith scripting/programming languages such as Python, Bash, Perl, orPowerShell.
  • Understandingof MITRE ATT&CK and modern attacker TTPs.
  • Experienceworking in large-scale, high-availability high-tech or cloud environments.
  • Stronganalytical, problem-solving, documentation, and communication skills.
  • Abilityto work effectively during high-severity incidents and undertime-sensitive conditions.
Preferred Qualifications
  • Experiencewith AWS, Azure, or GCP forensics.
  • Experiencewith Kubernetes, Docker, containers, and cloud-native infrastructure.
  • Experiencewith memory forensics using tools such as Volatility.
  • Experiencewith forensic platforms and tools such as EnCase, FTK, Autopsy, SleuthKit, Velociraptor, KAPE, or equivalent technologies.
  • Experiencewith Linux forensic frameworks and live-response tooling.
  • Experiencewith malware analysis and reverse engineering.
  • Knowledgeof identity attacks involving Active Directory, LDAP, Kerberos, SSO,OAuth, and cloud identity.
  • Experienceinvestigating software supply-chain and CI/CD compromises.
  • Experiencewith threat intelligence and adversary tracking.
  • Experiencebuilding automated DFIR capabilities at enterprise scale.
  • Experienceusing AI/ML technologies to enhance threat hunting, forensic analysis, andincident response.
Certifications

Preferred certifications include:

  • GIACCertified Incident Handler (GCIH)
  • GIACCertified Forensic Examiner (GCFE)
  • GIACAdvanced Incident Response, Threat Hunting & Digital Forensics (GAIA)
  • GIACCertified Intrusion Analyst (GCIA)
  • GIACReverse Engineering Malware (GREM)
  • GCFAor equivalent advanced DFIR certification
  • CISSP
Core Competencies
Technical
  • ThreatHunting
  • MalwareAnalysis
  • InfrastructureSecurity
  • SIEM/EDR/XDR
  • DetectionEngineering
  • SecurityAutomation
Leadership
  • Crisismanagement
  • Securityinvestigation strategy
Why join Sonata Software?

At Sonata, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build never seen before solutions to some of the world’s toughest problems. You´ll be challenged, but you will not be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.

Sonata Software is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity, age, religion, disability, sexual orientation, veteran status, marital status, or any other characteristics protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Digital Forensics & Incident Response Engineer
Digital Forensics & Incident Response Engineer

Sonata Software North America Inc. • San Jose (CA)

On-site
USD 165,000 - 276,000
Unix/Linux Infrastructure Forensics & Incident Engineer
Unix/Linux Infrastructure Forensics & Incident Engineer

Hallmark Global Technologies Limited • San Jose (CA)

On-site
USD 180,000 - 240,000
Infrastructure Penetration tester
Infrastructure Penetration tester

Darwinbox Digital Solutions Pvt. Ltd. • San Jose (CA)

On-site
USD 120,000 - 170,000
Unix/Linux Infrastructure Forensics & Incident Engineer
Unix/Linux Infrastructure Forensics & Incident Engineer

Canvendor • San Jose (CA)

On-site
USD 120,000 - 180,000
Senior Security Engineer - Digital Forensics and Incident Response (DFIR)
Senior Security Engineer - Digital Forensics and Incident Response (DFIR)

Intuit • Frisco (TX)

On-site
USD 140,000 - 190,000
Senior DFIR Engineer - Linux Forensics & Incident Response
Senior DFIR Engineer - Linux Forensics & Incident Response

Sonata Software North America Inc. • San Jose (CA)

On-site
USD 165,000 - 276,000
DFIR Analyst
DFIR Analyst

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 120,000
RSUs
Employee Stock Purchase Plan (ESPP)
Flexible time off
+6
AI DevOps Engineer
AI DevOps Engineer

Sonata Software • Westlake Village (CA)

On-site
USD 100,000 - 140,000
Infrastructure Associate Engineer
Infrastructure Associate Engineer

Sonata Software • Phoenix (AZ)

On-site
USD 55,000 - 75,000
Consultant, DFIR, Reactive Services (Unit 42) – LATAM
Consultant, DFIR, Reactive Services (Unit 42) – LATAM

Palo Alto Networks • United States

Remote
USD 110,000 - 160,000