---
title: "Senior Cybersecurity Incident Response Specialist"
company: "UltraViolet Cyber"
company_url: "https://www.remjobs.works/companies/ultraviolet-cyber"
url: "https://www.remjobs.works/job/ultraviolet-cyber-senior-cybersecurity-incident-response-specialist-27103cab-b858-4691-9e07-a807340128fc"
apply_url: "https://jobs.lever.co/uvcyber/b287a1a5-49c4-40b6-b974-f2a151c58915"
workplace: onsite
location: "Hyderabad"
employment_type: full-time
seniority: senior
role: other
region: india
skills: ["aws", "azure", "gcp", "linux", "python"]
date_posted: 2026-09-02T12:23:24.349Z
first_seen_by_remjobs: 2026-09-15T16:27:42.785Z
---

# Senior Cybersecurity Incident Response Specialist

**UltraViolet Cyber** · Hyderabad

Apply: https://jobs.lever.co/uvcyber/b287a1a5-49c4-40b6-b974-f2a151c58915

## About the role

Experience: 8–10 Years

**Function:** Cybersecurity – Incident Response / DFIR
**Role Level:** Senior

**Role Overview**

We are looking for an experienced Cybersecurity Incident Response Specialist with 8–10 years of hands-on cybersecurity experience to manage and investigate security incidents across enterprise environments.
The candidate will be responsible for end-to-end ownership of cybersecurity incidents, including triage, investigation, containment, eradication, recovery, Root Cause Analysis (RCA), malware analysis, and digital forensic analysis. The role also requires strong customer-facing skills to lead incident discussions, provide regular updates, explain technical findings, and present investigation outcomes and recommendations.

**Key Responsibilities**

Incident Response & Investigation
• Take end-to-end ownership of cybersecurity incidents from initial detection through closure.
• Lead investigation of Critical, High, and complex security incidents and coordinate response activities across relevant teams.
• Perform incident triage, scoping, containment, eradication, recovery, and post-incident analysis.
• Investigate incidents involving ransomware, malware, phishing, account compromise, credential theft, data exfiltration, insider threats, web attacks, lateral movement, privilege escalation, and other advanced threats.
• Analyze security alerts and correlate information across EDR, SIEM, network, identity, cloud, email, and other security technologies.
• Develop incident timelines and determine the attack vector, affected assets, compromised accounts, attacker activity, persistence mechanisms, and overall impact.
• Identify Indicators of Compromise (IOCs), attacker Tactics, Techniques, and Procedures (TTPs), and map findings to the MITRE ATT&CK framework.
• Coordinate with SOC, Threat Hunting, Threat Intelligence, IT, Cloud, Network, IAM, Application, Legal, and other stakeholders during major incidents.
Root Cause Analysis (RCA)
• Perform detailed Root Cause Analysis for security incidents.
• Determine the initial attack vector, contributing factors, security/control gaps, and reasons existing preventive or detective controls did not stop or detect the activity earlier.
• Conduct post-incident reviews and lessons-learned sessions.
• Develop clear corrective and preventive actions based on investigation findings.
• Track remediation recommendations with relevant stakeholders through closure.
• Prepare comprehensive RCA reports suitable for technical teams, management, and customers.
Malware Analysis
• Perform static and dynamic malware analysis to understand malicious file behaviour and capabilities.
• Analyze suspicious executables, scripts, PowerShell commands, documents, URLs, and other artifacts.
• Identify malware persistence mechanisms, command-and-control activity, network indicators, file-system changes, registry modifications, and related behaviors.
• Extract IOCs and behavioral indicators for threat hunting and detection engineering.
• Perform malware sandboxing and behavioral analysis where required.
• Provide recommendations for detection, containment, and prevention based on malware-analysis findings.
Digital Forensics
• Perform digital forensic investigations on endpoints and other relevant systems.
• Analyze Windows/Linux artifacts, event logs, file systems, registry artifacts, browser artifacts, authentication logs, memory artifacts, and other forensic evidence.
• Perform disk and memory analysis where required.
• Collect and preserve digital evidence following appropriate forensic procedures and chain-of-custody requirements.
• Build forensic timelines and reconstruct attacker activities.
• Determine the scope and impact of compromise using forensic evidence.
• Document forensic findings clearly and maintain investigation evidence appropriately.
Customer & Stakeholder Management
• Act as a key technical point of contact for customers during cybersecurity incidents.
• Lead incident calls and communicate investigation progress, impact, containment status, risks, and next steps.
• Provide timely and accurate incident updates to customers and internal leadership.
• Translate complex technical investigation findings into clear business-level communication.
• Manage customer expectations during high-severity and time-sensitive incidents.
• Present RCA and forensic investigation findings to customers and senior stakeholders.
• Handle technical questions and confidently explain investigation methodology, evidence, conclusions, and recommendations.
• Coordinate with multiple internal and customer teams to drive incidents toward timely resolution.
Incident Reporting & Documentation
• Prepare detailed incident investigation reports, including: 
o Executive summary
o Incident timeline
o Scope and impact
o Root cause
o Attack vector
o IOCs and TTPs
o Investigation findings
o Containment and remediation actions
o Control gaps
o Corrective and preventive recommendations
o Lessons learned
• Maintain accurate incident records, evidence, investigation notes, and supporting documentation.
• Contribute to the development and improvement of Incident Response playbooks, SOPs, investigation procedures, and escalation processes.
Required Technical Skills
The candidate should have strong hands-on experience in:
• Cybersecurity Incident Response / DFIR
• Security Incident Investigation
• Root Cause Analysis (RCA)
• Digital Forensics
• Malware Analysis
• Threat Hunting
• Endpoint and Network Investigation
• Windows and Linux Forensics
• Disk and Memory Analysis
• Log Analysis and Timeline Reconstruction
• IOC and TTP Analysis
• MITRE ATT&CK Framework
• SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, or similar
• EDR/XDR platforms such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Cortex XDR, or similar
• Network security technologies including Firewall, IDS/IPS, Proxy, DNS, VPN, and WAF
• Cloud security investigation across AWS, Azure, and/or GCP environments
• Identity and authentication-related investigations
• Email and phishing investigations
• Forensic and malware-analysis tools such as Volatility, Autopsy, FTK, EnCase, Wireshark, Sysinternals, YARA, Ghidra, IDA, or equivalent tools
• Scripting/automation using Python, PowerShell, or similar technologies would be an advantage.
**Required Experience**
• 8–10 years of overall cybersecurity experience, with significant hands-on experience in Incident Response, DFIR, SOC, Threat Hunting, or related security domains.
• Demonstrated experience independently handling complex and high-severity cybersecurity incidents.
• Strong experience conducting RCA and presenting investigation findings.
• Hands-on experience with malware and forensic investigations.
• Experience handling customer-facing security incidents and leading technical/customer incident calls.
• Experience coordinating investigations involving multiple technical and business teams.
• Ability to work effectively under pressure during Critical/High-severity incidents.
• Strong analytical, troubleshooting, and problem-solving skills.
**Communication & Leadership Skills**
• Excellent verbal and written communication skills.
• Strong customer-facing and stakeholder-management capabilities.
• Ability to communicate effectively with both technical and non-technical stakeholders.
• Ability to lead incident bridges/calls during critical incidents.
• Strong documentation and report-writing skills.
• Ability to take ownership, make investigation decisions, and drive incidents to closure.
• Ability to mentor junior Incident Response/SOC analysts and provide technical guidance during investigations.

---

Source: UltraViolet Cyber's own career page, read by RemJobs. Canonical HTML version: https://www.remjobs.works/job/ultraviolet-cyber-senior-cybersecurity-incident-response-specialist-27103cab-b858-4691-9e07-a807340128fc
