I
I

DFIR Analyst

Innefu Labs
Remote - India
Full-time2 - 3 yrs
16hrs ago0 view0 clicked apply

Build, Review & Tailor Your Resume with AI (Create an ATS-friendly resume, improve it, and tailor it for this job instantly.)


DFIR Analyst – Digital Forensics s Incident Response


Experience: 2–3 Years | Full-time | Cybersecurity / DFIR


Job Summary

We are seeking a motivated and hands-on DFIR Analyst with 2–3 years of experience in digital forensics, incident response, security operations, or related cybersecurity functions. The candidate will investigate security incidents across Windows, Linux, and macOS environments, perform endpoint and log analysis, correlate forensic evidence with SIEM/EDR telemetry, identify indicators of compromise, and support containment and remediation activities.


Key Responsibilities

  • Perform triage, investigation, and analysis of cybersecurity incidents across Windows, Linux, and macOS endpoints and servers.
  • Analyze Windows artifacts including EVTX, Registry, Prefetch, AmCache, ShimCache, SRUM, Scheduled Tasks, Services, Autoruns, browser artifacts, PowerShell logs, and other relevant artifacts.
  • Analyze Linux artifacts including system/authentication logs, shell history, cron jobs, systemd services, SSH activity, user accounts, processes, network configuration, and persistence mechanisms.
  • Analyze macOS artifacts including Unified Logs, plist files, LaunchAgents, LaunchDaemons, login items, browser artifacts, user activity, and APFS-related evidence.
  • Perform basic memory forensics and volatile-data analysis using tools such as Volatility or equivalent tooling.
  • Investigate suspicious files, scripts, processes, persistence mechanisms, and malware behavior; perform basic static and dynamic malwaretriage.
  • Extract, validate, and correlate IOCs including hashes, domains, URLs, IP addresses, filenames, registry keys, user accounts, and process indicators.
  • Build investigation timelines and reconstruct attack activity by correlating endpoint, network, authentication, and security telemetry.
  • Support threat hunting activities using SIEM, EDR, threat intelligence, forensic artifacts, and MITRE ATTCCK-based hypotheses.
  • Contribute to the development and improvement of DFIR playbooks, investigation procedures, detection use cases, and automation opportunities.


Technical Skills s Qualifications

  • 2–3 years of hands-on experience in DFIR, incident response, SOC, threat hunting, cybersecurity operations, or digital forensics.
  • Strong understanding of digital forensics and file systems, including NTFS, FAT/exFAT, ext4, and APFS, with practical knowledge of forensic artifacts and metadata.
  • Hands-on experience with forensic and security tools such as Magnet AXIOM, FTK, EnCase, X-Ways, KAPE, Velociraptor, Autopsy, EDR/XDR, or equivalent platforms.
  • Strong understanding of incident response, malware, IOCs, MITRE ATTCCK, and attacker TTPs, including persistence, credential theft, lateral movement, C2, and data exfiltration.
  • Good analytical, investigative, communication, and problem-solving skills, with basic scripting/querying knowledge in Python, PowerShell, Bash, KQL, SPL, SQL, or equivalent.


Stakeholder s Communication Responsibilities

  • Collaborate with SOC, Incident Response, IT, Security Engineering, and management teams during investigations.
  • Clearly communicate incident severity, impact, forensic findings, evidence, and recommended next steps to technical and non-technical stakeholders.
  • Participate in client/customer calls, investigation briefings, technical discussions, and post-incident reviews as required.


Education s Certifications

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, Electronics, or a related discipline, or equivalent practical experience.
  • Relevant certifications are preferred but not mandatory, such as Security+, CEH, CHFI, GCIH, GCFE, GCFA, SC-200, or equivalent.
  • Practical hands-on DFIR experience, labs, projects, or relevant professional experience may be considered in place of certifications.

Preferred Additional Exposure

  • Threat intelligence platforms and IOC enrichment.
  • Cloud security and incident response involving AWS, Azure, or Microsoft 365.
  • SOAR platforms and security automation.
  • YARA, Sigma, or other detection-rule concepts.
  • Vulnerability and exposure-management concepts.
  • Container or server forensics.
  • Experience with ransomware, phishing, credential compromise, insider-threat, or data-exfiltration investigations.


RESUME BUILDER

Build Your Resume for Free in Minutes

Create ATS-friendly resumes with modern templates and AI-powered suggestions.

ATS Friendly
Rohan SharmaMarketing Manager

Professional Summary

Experience

ATS Friendly
RESUME REVIEW

Get Your Resume
Reviewed for Free

Discover missing skills, ATS issues, and get personalized suggestions to improve your chances.

Secure
92%
ATS Score
Review SummaryGood keywordsWell-structuredAdd metrics
Improve your score with the suggestions.
RESUME TAILORING

Tailor Your Resume for This Job

Match your resume to this job's requirements in one click.

96%Match