Skip to content
Jobsearch.ing

Senior Cybersecurity Incident Response Specialist

UvcyberHyderabad, IN

Security and safetySeniorFull time8+ yrs
Source-verified: read directly from this employer's own lever job board, not a repost.On-sitePosted (4 days ago)Last verified (today)

At a glance

Location
Hyderabad, IN
Workplace
On-site
Pay
Not published by the employer
Employment type
Full time
Experience
8+ years
Education
No degree requirement stated
Job family
Security and safety
Seniority
Senior
Posted by employer
2 September 2026
Last verified open
7 September 2026
Region and country
IN
Team
Commercial
Listed via
Lever

What the employer wrote

Experience: 8–10 Years

Function: Cybersecurity – Incident Response / DFIR Role Level: Senior

Role Overview

We are looking for an experienced Cybersecurity Incident Response Specialist with 8–10 years of hands-on cybersecurity experience to manage and investigate security incidents across enterprise environments. The candidate will be responsible for end-to-end ownership of cybersecurity incidents, including triage, investigation, containment, eradication, recovery, Root Cause Analysis (RCA), malware analysis, and digital forensic analysis. The role also requires strong customer-facing skills to lead incident discussions, provide regular updates, explain technical findings, and present investigation outcomes and recommendations.

Key Responsibilities

Incident Response & Investigation •    Take end-to-end ownership of cybersecurity incidents from initial detection through closure. •    Lead investigation of Critical, High, and complex security incidents and coordinate response activities across relevant teams. •    Perform incident triage, scoping, containment, eradication, recovery, and post-incident analysis. •   Investigate incidents involving ransomware, malware, phishing, account compromise, credential theft, data exfiltration, insider threats, web attacks, lateral movement, privilege escalation, and other advanced threats. •    Analyze security alerts and correlate information across EDR, SIEM, network, identity, cloud, email, and other security technologies. •    Develop incident timelines and determine the attack vector, affected assets, compromised accounts, attacker activity, persistence mechanisms, and overall impact. •    Identify Indicators of Compromise (IOCs), attacker Tactics, Techniques, and Procedures (TTPs), and map findings to the MITRE ATT&CK framework. •  Coordinate with SOC, Threat Hunting, Threat Intelligence, IT, Cloud, Network, IAM, Application, Legal, and other stakeholders during major incidents. Root Cause Analysis (RCA) •    Perform detailed Root Cause Analysis for security incidents. •  Determine the initial attack vector, contributing factors, security/control gaps, and reasons existing preventive or detective controls did not stop or detect the activity earlier. •    Conduct post-incident reviews and lessons-learned sessions. •    Develop clear corrective and preventive actions based on investigation findings. •    Track remediation recommendations with relevant stakeholders through closure. •    Prepare comprehensive RCA reports suitable for technical teams, management, and customers. Malware Analysis •    Perform static and dynamic malware analysis to understand malicious file behaviour and capabilities. •    Analyze suspicious executables, scripts, PowerShell commands, documents, URLs, and other artifacts. •  Identify malware persistence mechanisms, command-and-control activity, network indicators, file-system changes, registry modifications, and related behaviors. •    Extract IOCs and behavioral indicators for threat hunting and detection engineering. •    Perform malware sandboxing and behavioral analysis where required. •    Provide recommendations for detection, containment, and prevention based on malware-analysis findings. Digital Forensics •    Perform digital forensic investigations on endpoints and other relevant systems. •  Analyze Windows/Linux artifacts, event logs, file systems, registry artifacts, browser artifacts, authentication logs, memory artifacts, and other forensic evidence. •    Perform disk and memory analysis where required. •    Collect and preserve digital evidence following appropriate forensic procedures and chain-of-custody requirements. •    Build forensic timelines and reconstruct attacker activities. •    Determine the scope and impact of compromise using forensic evidence. •    Document forensic findings clearly and maintain investigation evidence appropriately. Customer & Stakeholder Management •    Act as a key technical point of contact for customers during cybersecurity incidents. •    Lead incident calls and communicate investigation progress, impact, containment status, risks, and next steps. •    Provide timely and accurate incident updates to customers and internal leadership. •    Translate complex technical investigation findings into clear business-level communication. •    Manage customer expectations during high-severity and time-sensitive incidents. •    Present RCA and forensic investigation findings to customers and senior stakeholders. •    Handle technical questions and confidently explain investigation methodology, evidence, conclusions, and recommendations. •    Coordinate with multiple internal and customer teams to drive incidents toward timely resolution. Incident Reporting & Documentation •    Prepare detailed incident investigation reports, including:  o    Executive summary o    Incident timeline o    Scope and impact o    Root cause o    Attack vector o    IOCs and TTPs o    Investigation findings o    Containment and remediation actions o    Control gaps o    Corrective and preventive recommendations o    Lessons learned •    Maintain accurate incident records, evidence, investigation notes, and supporting documentation. •    Contribute to the development and improvement of Incident Response playbooks, SOPs, investigation procedures, and escalation processes. Required Technical Skills The candidate should have strong hands-on experience in: •    Cybersecurity Incident Response / DFIR •    Security Incident Investigation •    Root Cause Analysis (RCA) •    Digital Forensics •    Malware Analysis •    Threat Hunting •    Endpoint and Network Investigation •    Windows and Linux Forensics •    Disk and Memory Analysis •    Log Analysis and Timeline Reconstruction •    IOC and TTP Analysis •    MITRE ATT&CK Framework •    SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, or similar •    EDR/XDR platforms such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Cortex XDR, or similar •    Network security technologies including Firewall, IDS/IPS, Proxy, DNS, VPN, and WAF •    Cloud security investigation across AWS, Azure, and/or GCP environments •    Identity and authentication-related investigations •    Email and phishing investigations •    Forensic and malware-analysis tools such as Volatility, Autopsy, FTK, EnCase, Wireshark, Sysinternals, YARA, Ghidra, IDA, or equivalent tools •    Scripting/automation using Python, PowerShell, or similar technologies would be an advantage. Required Experience •    8–10 years of overall cybersecurity experience, with significant hands-on experience in Incident Response, DFIR, SOC, Threat Hunting, or related security domains. •    Demonstrated experience independently handling complex and high-severity cybersecurity incidents. •    Strong experience conducting RCA and presenting investigation findings. •    Hands-on experience with malware and forensic investigations. •    Experience handling customer-facing security incidents and leading technical/customer incident calls. •    Experience coordinating investigations involving multiple technical and business teams. •    Ability to work effectively under pressure during Critical/High-severity incidents. •    Strong analytical, troubleshooting, and problem-solving skills. Communication & Leadership Skills •    Excellent verbal and written communication skills. •    Strong customer-facing and stakeholder-management capabilities. •    Ability to communicate effectively with both technical and non-technical stakeholders. •    Ability to lead incident bridges/calls during critical incidents. •    Strong documentation and report-writing skills. •    Ability to take ownership, make investigation decisions, and drive incidents to closure. •    Ability to mentor junior Incident Response/SOC analysts and provide technical guidance during investigations.

Where this record came from

Read from Uvcyber's own Lever job board on , and last confirmed still open on . The employer published it on 2 September 2026. Jobsearch.ing did not write, edit or rank this posting, and does not vet the employer. View the original posting.

More roles like this one