UltraViolet Cyber

Senior Cybersecurity Incident Response Specialist

UltraViolet Cyber · Hyderabad, India
Hyderabad, India Posted 2026-09-02
Type
Full-time
Experience
8+ yr

Experience: 8–10 Years

Function: Cybersecurity – Incident Response / DFIR
Role Level: Senior

Role Overview

We are looking for an experienced Cybersecurity Incident Response Specialist with 8–10 years of hands-on cybersecurity experience to manage and investigate security incidents across enterprise environments.
The candidate will be responsible for end-to-end ownership of cybersecurity incidents, including triage, investigation, containment, eradication, recovery, Root Cause Analysis (RCA), malware analysis, and digital forensic analysis. The role also requires strong customer-facing skills to lead incident discussions, provide regular updates, explain technical findings, and present investigation outcomes and recommendations.

Key Responsibilities

Incident Response & Investigation

  • Take end-to-end ownership of cybersecurity incidents from initial detection through closure.
  • Lead investigation of Critical, High, and complex security incidents and coordinate response activities across relevant teams.
  • Perform incident triage, scoping, containment, eradication, recovery, and post-incident analysis.
  • Investigate incidents involving ransomware, malware, phishing, account compromise, credential theft, data exfiltration, insider threats, web attacks, lateral movement, privilege escalation, and other advanced threats.
  • Analyze security alerts and correlate information across EDR, SIEM, network, identity, cloud, email, and other security technologies.
  • Develop incident timelines and determine the attack vector, affected assets, compromised accounts, attacker activity, persistence mechanisms, and overall impact.
  • Identify Indicators of Compromise (IOCs), attacker Tactics, Techniques, and Procedures (TTPs), and map findings to the MITRE ATT&CK framework.
  • Coordinate with SOC, Threat Hunting, Threat Intelligence, IT, Cloud, Network, IAM, Application, Legal, and other stakeholders during major incidents.

Root Cause Analysis (RCA)

  • Perform detailed Root Cause Analysis for security incidents.
  • Determine the initial attack vector, contributing factors, security/control gaps, and reasons existing preventive or detective controls did not stop or detect the activity earlier.
  • Conduct post-incident reviews and lessons-learned sessions.
  • Develop clear corrective and preventive actions based on investigation findings.
  • Track remediation recommendations with relevant stakeholders through closure.
  • Prepare comprehensive RCA reports suitable for technical teams, management, and customers.

Malware Analysis

  • Perform static and dynamic malware analysis to understand malicious file behaviour and capabilities.
  • Analyze suspicious executables, scripts, PowerShell commands, documents, URLs, and other artifacts.
  • Identify malware persistence mechanisms, command-and-control activity, network indicators, file-system changes, registry modifications, and related behaviors.
  • Extract IOCs and behavioral indicators for threat hunting and detection engineering.
  • Perform malware sandboxing and behavioral analysis where required.
  • Provide recommendations for detection, containment, and prevention based on malware-analysis findings.

Digital Forensics

  • Perform digital forensic investigations on endpoints and other relevant systems.
  • Analyze Windows/Linux artifacts, event logs, file systems, registry artifacts, browser artifacts, authentication logs, memory artifacts, and other forensic evidence.
  • Perform disk and memory analysis where required.
  • Collect and preserve digital evidence following appropriate forensic procedures and chain-of-custody requirements.
  • Build forensic timelines and reconstruct attacker activities.
  • Determine the scope and impact of compromise using forensic evidence.
  • Document forensic findings clearly and maintain investigation evidence appropriately.

Customer & Stakeholder Management

  • Act as a key technical point of contact for customers during cybersecurity incidents.
  • Lead incident calls and communicate investigation progress, impact, containment status, risks, and next steps.
  • Provide timely and accurate incident updates to customers and internal leadership.
  • Translate complex technical investigation findings into clear business-level communication.
  • Manage customer expectations during high-severity and time-sensitive incidents.
  • Present RCA and forensic investigation findings to customers and senior stakeholders.
  • Handle technical questions and confidently explain investigation methodology, evidence, conclusions, and recommendations.
  • Coordinate with multiple internal and customer teams to drive incidents toward timely resolution.

Incident Reporting & Documentation

  • Prepare detailed incident investigation reports, including:

o    Executive summary
o    Incident timeline
o    Scope and impact
o    Root cause
o    Attack vector
o    IOCs and TTPs
o    Investigation findings
o    Containment and remediation actions
o    Control gaps
o    Corrective and preventive recommendations
o    Lessons learned

  • Maintain accurate incident records, evidence, investigation notes, and supporting documentation.
  • Contribute to the development and improvement of Incident Response playbooks, SOPs, investigation procedures, and escalation processes.

Required Technical Skills
The candidate should have strong hands-on experience in:

  • Cybersecurity Incident Response / DFIR
  • Security Incident Investigation
  • Root Cause Analysis (RCA)
  • Digital Forensics
  • Malware Analysis
  • Threat Hunting
  • Endpoint and Network Investigation
  • Windows and Linux Forensics
  • Disk and Memory Analysis
  • Log Analysis and Timeline Reconstruction
  • IOC and TTP Analysis
  • MITRE ATT&CK Framework
  • SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, or similar
  • EDR/XDR platforms such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Cortex XDR, or similar
  • Network security technologies including Firewall, IDS/IPS, Proxy, DNS, VPN, and WAF
  • Cloud security investigation across AWS, Azure, and/or GCP environments
  • Identity and authentication-related investigations
  • Email and phishing investigations
  • Forensic and malware-analysis tools such as Volatility, Autopsy, FTK, EnCase, Wireshark, Sysinternals, YARA, Ghidra, IDA, or equivalent tools
  • Scripting/automation using Python, PowerShell, or similar technologies would be an advantage.

Required Experience

  • 8–10 years of overall cybersecurity experience, with significant hands-on experience in Incident Response, DFIR, SOC, Threat Hunting, or related security domains.
  • Demonstrated experience independently handling complex and high-severity cybersecurity incidents.
  • Strong experience conducting RCA and presenting investigation findings.
  • Hands-on experience with malware and forensic investigations.
  • Experience handling customer-facing security incidents and leading technical/customer incident calls.
  • Experience coordinating investigations involving multiple technical and business teams.
  • Ability to work effectively under pressure during Critical/High-severity incidents.
  • Strong analytical, troubleshooting, and problem-solving skills.

Communication & Leadership Skills

  • Excellent verbal and written communication skills.
  • Strong customer-facing and stakeholder-management capabilities.
  • Ability to communicate effectively with both technical and non-technical stakeholders.
  • Ability to lead incident bridges/calls during critical incidents.
  • Strong documentation and report-writing skills.
  • Ability to take ownership, make investigation decisions, and drive incidents to closure.
  • Ability to mentor junior Incident Response/SOC analysts and provide technical guidance during investigations.
AWSAzureGCPPython
E
AWS Cloud Security Architect
Springfield, VA Hybrid
Engineering
$170K–$240K
O
Associate Principal Red Team Consultant
Remote Remote
Operations
$165K–$195K
E
AWS Cloud Security Engineer
Springfield, VA Hybrid
Engineering
$150K–$180K
See all 20+ roles at UltraViolet Cyber →
A
Senior Penetration Testing Specialist
Aprio, LLP Atlanta, GA Remote
Operations
$100K–$130K
A
Senior Consultant CPM
Accordion Partners Atlanta, GA Hybrid
Operations
$95K–$140K
A
AI & Machine Learning Senior Vice President
AlixPartners United States Hybrid
Operations
$160K–$310K
A
Senior AI Scientist – Transportation & Logistics
Avathon Pleasanton, CA
Operations
$160K–$240K
See all Operations roles →

Interested in this role?

Apply directly on the company site — no recruiter middleman, no account required.

Apply now →
Apply on company site