
Incident Responder (L3 / CSIRT Lead) (RARR Job 6260)
For Cybersecurity Consulting And Information Security Services
7 - 10 Years
Full Time
Up to 30 Days
Up to 24 LPA
1 Position(s)
New Delhi
Posted By : RARR Technologies Pvt Ltd
Posted 23 Days Ago
Job Skills
Job Description
Key Responsibilities
- Lead end-to-end incident response activities for high-severity cybersecurity incidents, ransomware attacks, advanced persistent threats (APTs), insider threats, and data breach investigations.
- Conduct forensic investigations involving memory, disk, network, cloud, endpoint, and application artifacts to determine attack vectors, scope, impact, and root cause.
- Perform malware triage, reverse engineering coordination, threat attribution, and analysis of attacker persistence mechanisms.
- Manage evidence preservation, chain-of-custody procedures, forensic acquisition, timeline reconstruction, and incident documentation in accordance with legal and regulatory requirements.
- Coordinate containment, eradication, and recovery activities while minimizing business impact and ensuring operational continuity.
- Develop and maintain incident response playbooks, forensic procedures, escalation workflows, and crisis management processes.
- Conduct post-incident reviews, lessons learned exercises, and provide recommendations to strengthen organizational cyber resilience.
- Collaborate with CERT-In, law enforcement agencies, cyber intelligence partners, and other stakeholders during major cyber incidents when required.
- Support SOC and Detection Engineering teams by translating forensic findings into improved monitoring and detection capabilities.
Required Qualifications
- B.Tech / M.Tech in Computer Science, Information Security, Cybersecurity, or related discipline.
- Minimum 7 years of cybersecurity experience with at least 4 years in DFIR, Incident Response, or CSIRT operations.
- Demonstrated experience leading incident response investigations involving:
- Memory Forensics
- Disk Forensics
- Network Forensics
- Malware Analysis
- Intrusion Analysis
- Root Cause Analysis
- Strong experience with SIEM, SOAR, EDR, Threat Intelligence Platforms, and Incident Response tools.
- Hands-on experience with forensic tools and malware investigation methodologies.
Matching Jobs
No matching jobs found.