Senior Forensic Analyst
areteir · Hyderabad, India · On-site
Posted Aug 27, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
SUMMARY
The Senior Forensic Analyst leads forensic analysis for projects assigned to the respective Tiger Team, collaborating with the Tiger Team and forensic leads to perform triage-level analysis of collected data (e.g., operating system files, images, SentinelOne, Logs, etc.) and perform deep-dive advanced forensic analysis. The team focuses on identifying threat actor behavior and activity, using a tailored, detailed analysis approach to identify unauthorised access and how the cyber intrusion occurred. The DFIR team operates as an industry leader in Incident Response and a trusted advisor to breach coaches and Insurance Carriers working to support Clients and help restore business operations.
ROLES & RESPONSIBILITIES
Leads the Forensics analysis to support the Forensic lead on engagements for Ransomware/compromise investigations
Works with the tiger team analysts to perform Forensic analysis of artifacts, including (but not limited to) the analysis of operating system artifacts and the recovery of deleted items from multiple operating systems including Windows, Linux, Mac, and RAM/memory forensics
Analyzes network and operating system log files including Windows Event logs, Unified Audit Logs, Firewall logs, VPN logs, etc
Works with the Security Operations Center (SOC) to leverage data from alerts provided by existing and deployed Endpoint Detection and Response (EDR) solutions to identify Indicators of Compromise (IOCs) or Tactics, Techniques, and Procedures (TTPs) for variants related to the case
Internally prepares Forensics findings and updates in a clear, concise manner through a narrative story outlining the timeline of events - modifies delivery in line with the call’s audience and technical capabilities
Employs the usage of incident-mapping frameworks while developing the attack map, such as MITRE’s ATT&CK and Lockheed Martin’s Cyber Kill Chain, to help contextualize IOCs
Reviews and drafts written incident, investigative updates, reports, and appendices as the explicit direction of counsel and partners based on the findings using the standard report templates. Performs Peer reviews of reports written by team members
Delivers on the Forensic Investigations plan & works with the lead to manage the timeline, delivery, and execution of the forensic analysis across projects
May perform other duties as assigned by management
SKILLS AND KNOWLEDGE
Thorough knowledge of: Windows disk, Unix or Linux disk, and memory forensics
Network Security Monitoring (NSM), network traffic analysis, and log analysis
Experience and understanding of enterprise security controls
Experienced with EnCase, Axiom, FTK, X-Ways, SIFT, Splunk, Redline, Volatility, WireShark, TCPDump, and open-source forensic tools
Experience delivering technical findings to a non-technical audience, preferred
Experience leading teams of analysts, preferred
Provide findings in a confident, factual manner, preferred
Knowledge and experience in…