412,258open jobs
14,281companies
71,283added this week
Browse all
Salary
$23k – $51k per year (Estimated)
Location
In office (Hyderabad)
Seniority
Senior · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Ultraviolet Cyber is an enterprise cybersecurity company that provides unified, automated security operations and threat management solutions. The firm offers managed detection and response (MDR), threat intelligence, and security automation services designed to help organizations streamline their security operations centers (SOCs). By synthesizing telemetry across diverse IT environments, it enables enterprises to detect, investigate, and neutralize complex cyber threats in real time.

Experience: 8-10 Years

Function: Cybersecurity - Incident Response / DFIR

Role Level: Senior

Role Overview

We are looking for an experienced Cybersecurity Incident Response Specialist with 8-10 years of hands-on cybersecurity experience to manage and investigate security incidents across enterprise environments.

The candidate will be responsible for end-to-end ownership of cybersecurity incidents, including triage, investigation, containment, eradication, recovery, Root Cause Analysis (RCA), malware analysis, and digital forensic analysis. The role also requires strong customer-facing skills to lead incident discussions, provide regular updates, explain technical findings, and present investigation outcomes and recommendations.

Key Responsibilities

Incident Response & Investigation

  • Take end-to-end ownership of cybersecurity incidents from initial detection through closure.
  • Lead investigation of Critical, High, and complex security incidents and coordinate response activities across relevant teams.
  • Perform incident triage, scoping, containment, eradication, recovery, and post-incident analysis.
  • Investigate incidents involving ransomware, malware, phishing, account compromise, credential theft, data exfiltration, insider threats, web attacks, lateral movement, privilege escalation, and other advanced threats.
  • Analyze security alerts and correlate information across EDR, SIEM, network, identity, cloud, email, and other security technologies.
  • Develop incident timelines and determine the attack vector, affected assets, compromised accounts, attacker activity, persistence mechanisms, and overall impact.
  • Identify Indicators of Compromise (IOCs), attacker Tactics, Techniques, and Procedures (TTPs), and map findings to the MITRE ATT&CK framework.
  • Coordinate with SOC, Threat Hunting, Threat Intelligence, IT, Cloud, Network, IAM, Application, Legal, and other stakeholders during major incidents.

Root Cause Analysis (RCA)

  • Perform detailed Root Cause Analysis for security incidents.
  • Determine the initial attack vector, contributing factors, security/control gaps, and reasons existing preventive or detective controls did not stop or detect the activity earlier.
  • Conduct post-incident reviews and lessons-learned sessions.
  • Develop clear corrective and preventive actions based on investigation findings.
  • Track remediation recommendations with relevant stakeholders through closure.
  • Prepare comprehensive RCA reports suitable for technical teams, management, and customers.

Malware Analysis

  • Perform static and dynamic malware analysis to understand malicious file behaviour and capabilities.
  • Analyze suspicious executables, scripts, PowerShell commands, documents, URLs, and other artifacts.
  • Identify malware persistence mechanisms, command-and-control activity, network indicators, file-system changes, registry modifications, and related behaviors.
  • Extract IOCs and behavioral indicators for threat hunting and detection engineering.
  • Perform malware sandboxing and behavioral analysis where required.
  • Provide recommendations for detection, containment, and prevention based on malware-analysis findings.

Digital Forensics

  • Perform digital forensic investigations on endpoints and other relevant systems.
  • Analyze Windows/Linux artifacts, event logs, file systems, registry artifacts, browser artifacts, authentication logs, memory artifacts, and other forensic evidence.
  • Perform disk and memory analysis where required.
  • Collect and preserve digital evidence following appropriate forensic procedures and chain-of-custody requirements.
  • Build forensic timelines and reconstruct attacker activities.
  • Determine the scope and impact of compromise using forensic evidence.
  • Document forensic findings clearly and maintain investigation evidence appropriately.

Customer & Stakeholder Management

  • Act as a key technical point of contact for customers during cybersecurity incidents.
  • Lead incident calls and communicate investigation progress, impact, containment status, risks, and next steps.
  • Provide timely and accurate incident updates to customers and internal leadership.
  • Translate complex technical investigation findings into clear business-level communication.
  • Manage customer expectations during high-severity and time-sensitive incidents.
  • Present RCA and forensic investigation findings to customers and senior stakeholders.
  • Handle technical questions and confidently explain investigation methodology, evidence, conclusions, and recommendations.
  • Coordinate with multiple internal and customer teams to drive incidents toward timely resolution.

Incident Reporting & Documentation

  • Prepare detailed incident investigation reports, including:

o Executive summary

o Incident timeline

o Scope and impact

o Root cause

o Attack vector

o IOCs and TTPs

o Investigation findings

o Containment and remediation actions

o Control gaps

o Corrective and preventive recommendations

o Lessons learned

  • Maintain accurate incident records, evidence, investigation notes, and supporting documentation.
  • Contribute to the development and improvement of Incident Response playbooks, SOPs, investigation procedures, and escalation processes.

Required Technical Skills

The candidate should have strong hands-on experience in:

  • Cybersecurity Incident Response / DFIR
  • Security Incident Investigation
  • Root Cause Analysis (RCA)
  • Digital Forensics
  • Malware Analysis
  • Threat Hunting
  • Endpoint and Network Investigation
  • Windows and Linux Forensics
  • Disk and Memory Analysis
  • Log Analysis and Timeline Reconstruction
  • IOC and TTP Analysis
  • MITRE ATT&CK Framework
  • SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, or similar
  • EDR/XDR platforms such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Cortex XDR, or similar
  • Network security technologies including Firewall, IDS/IPS, Proxy, DNS, VPN, and WAF
  • Cloud security investigation across AWS, Azure, and/or GCP environments
  • Identity and authentication-related investigations
  • Email and phishing investigations
  • Forensic and malware-analysis tools such as Volatility, Autopsy, FTK, EnCase, Wireshark, Sysinternals, YARA, Ghidra, IDA, or equivalent tools
  • Scripting/automation using Python, PowerShell, or similar technologies would be an advantage.

Required Experience

  • 8-10 years of overall cybersecurity experience, with significant hands-on experience in Incident Response, DFIR, SOC, Threat Hunting, or related security domains.
  • Demonstrated experience independently handling complex and high-severity cybersecurity incidents.
  • Strong experience conducting RCA and presenting investigation findings.
  • Hands-on experience with malware and forensic investigations.
  • Experience handling customer-facing security incidents and leading technical/customer incident calls.
  • Experience coordinating investigations involving multiple technical and business teams.
  • Ability to work effectively under pressure during Critical/High-severity incidents.
  • Strong analytical, troubleshooting, and problem-solving skills.

Communication & Leadership Skills

  • Excellent verbal and written communication skills.
  • Strong customer-facing and stakeholder-management capabilities.
  • Ability to communicate effectively with both technical and non-technical stakeholders.
  • Ability to lead incident bridges/calls during critical incidents.
  • Strong documentation and report-writing skills.
  • Ability to take ownership, make investigation decisions, and drive incidents to closure.
  • Ability to mentor junior Incident Response/SOC analysts and provide technical guidance during investigations.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
412,258 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Hyderabad
In office • 3+ years exp
Python
SQL
Databases
Snowflake
Google BigQuery
Amazon Redshift
Microsoft Fabric
BigQuery
AI/ML
Spark
dbt
DevOps
GCP
AWS
Analytics
Power BI
ETL/ELT
Apply
$22k – $53k per year (Estimated) • Remote/Hybrid • 8+ years exp • Bachelor's Degree • Noida
Python
DevOps
Terraform
Ansible
GCP
Helm
Istio
CircleCI
CloudFormation
Dynatrace
Prometheus
GitLab CI
Azure
CI/CD
Jenkins
AWS
Docker
Kubernetes
Grafana
Service Mesh
Configuration Management
GitLab
Apply
In office • 5+ years exp
DevOps
GCP
Azure
AWS
FinOps
Analytics
Power BI
Apply
$26k – $66k per year (Estimated) • Remote/Hybrid • 11+ years exp • Noida
Python
JavaScript
Java
TypeScript
SQL
Node JS
Java
Hibernate
Spring MVC
Databases
PostgreSQL
Frontend
React.js
JQuery
DevOps
Rest API
CI/CD
Jenkins
AWS
Docker
Kubernetes
Platform Engineering
AWS Lambda
Amazon S3
IAM
Amazon CloudWatch
Apply
In office • 10+ years exp • Bachelor's Degree
Python
SQL
Databases
Snowflake
DevOps
Azure
Analytics
Power BI
ETL/ELT
Apply
$100k – $110k per year • Remote • 4+ years exp
Cybersecurity
MITRE ATT&CK
Cyber Kill Chain
Apply
$15k – $37k per year (Estimated) • In office • Full-Time • 2+ years exp • Hyderabad
Python
AI/ML
Red Teaming
DevOps
Azure
AWS
Cybersecurity
Burp Suite
MITRE ATT&CK
OWASP Top 10
CVSS
Apply
$101k – $197k per year (Estimated) • Remote/Hybrid • Secret • 8+ years exp • Bachelor's Degree • Washington
Python
SQL
AI/ML
Airflow
Prefect
DevOps
Terraform
GCP
GitHub Actions
CloudFormation
Azure
CI/CD
Jenkins
AWS
Self-Healing
GitHub
GitLab
Analytics
ETL/ELT
Apply
$160k – $210k per year • Remote/Hybrid • 12+ years exp • Bachelor's Degree
DevOps
Splunk
Cybersecurity
Qualys Cloud Platform
Zero Trust
Apply
$90k – $130k per year • In office • Secret • 4+ years exp • Herndon
Python
PowerShell
DevOps
Splunk
Ansible
Azure
AWS
Apply
Remote/Hybrid • 8+ years exp • Bachelor's Degree • Hyderabad
AI/ML
AI Agents
DevOps
AWS
Kubernetes
Amazon EKS
Cybersecurity
ISO 27001
SOC 2
CVSS
Apply
Remote/Hybrid • 5+ years exp • Hyderabad
Python
Go
JavaScript
TypeScript
C#
AI/ML
AI Agents
LLM
DevOps
Terraform
GCP
Helm
GitHub Actions
CloudFormation
Azure
CI/CD
Jenkins
AWS
Kubernetes
GitHub
IAM
Cybersecurity
Trivy
Checkmarx
Checkov
OWASP Top 10
Threat Modeling
Veracode
Apply
Remote • 8+ years exp • Bachelor's Degree • Hyderabad
Python
Java
PowerShell
AI/ML
MLFlow
AI Agents
EU AI Act
NIST AI RMF
DevOps
GCP
Azure
AWS
Cybersecurity
SOC 2
GDPR
Threat Modeling
Apply
Remote • 8+ years exp • Hyderabad
JavaScript
TypeScript
AI/ML
AI Agents
Frontend
Angular
Angular Material
Mobile
Material Design
Design
Figma
Apply
Remote/Hybrid • 8+ years exp • Bachelor's Degree • Hyderabad
JavaScript
TypeScript
C#
C#
ASP.NET Core
AI/ML
AI Agents
Frontend
Webpack
RxJS
Angular
esbuild
NgRx
DevOps
CI/CD
QA
Cypress
Playwright
Jest
Apply
See all jobs
This is one of many
412,258 more open roles from verified company boards, updated every day.