Padmi

Cyber Incident Management Specialist

IndiaPosted 3 months ago
CybersecuritySeniorFull Time; Regular
Apply at Endava

Opens the source posting on shine.com

Source description

About the role

View original

As an Incident Response Analyst at Endava, you will be a crucial part of the Cyber Threat Intelligence and Incident Response team, where your primary responsibility will be to provide the company with high fidelity, actionable cyber threat intelligence and specialized incident response capabilities. You are expected to have a strong understanding of the latest security threats, industry-standard incident response methodologies, and investigation techniques. Additionally, your adaptability and eagerness to learn emerging threat actor tactics, tools, and techniques will be highly valued. Responsibilities: - Act as a key responder during security incidents, supporting containment, eradication, and recovery activities. - Perform detailed investigation and analysis of security alerts, intrusions, and malware using EDR, SIEM, and forensic tooling. - Support post-incident reviews, identifying root cause, control gaps, and lessons learned. - Coordinate with SOC, CTI, IT, legal, and third-party providers during incidents to ensure timely and effective response. - Support evidence collection and documentation to meet legal, regulatory, and internal reporting requirements. - During periods without active incident response activity, actively support Cyber Threat Intelligence operations and initiatives. Qualifications: - Degree in Cyber Security, Computer Science, Information Technology, or a related discipline, or equivalent practical experience. - Relevant incident response, blue team, or security operations certification (e.g., GCIH, GCED, or equivalent). - Demonstrated experience responding to security incidents, labs, or realistic tabletop exercises. Experience: - 6-10 years of incident management experience. - 3+ years in cybersecurity, with at least 2 years in SOC/CTI/Incident Response. - Hands-on experience in malware analysis, memory forensics, and log analysis. - Solid understanding of network protocols, secure configurations, and common attack techniques (MITRE ATT&CK). - Experience supporting or participating in security incident response activities, including investigation and containment. Technical Skills: - Hands-on experience with SIEM and EDR tools for alert investigation and incident analysis. - Ability to analyze endpoint, network, and log data to identify malicious activity. - Familiarity with incident response processes, including triage, containment, and recovery. - Basic malware analysis and investigation skills, such as analyzing file hashes, URLs, and suspicious processes. - Understanding of common attack vectors, vulnerabilities, and exploitation techniques. At Endava, we value strong problem-solving and analytical skills, the ability to remain calm and decisive during high-pressure incidents, excellent communication skills (both technical and non-technical), and a continuous learning mindset with a willingness to explore new tools and methods. We encourage applications from individuals of all backgrounds, experiences, and perspectives. As an Incident Response Analyst at Endava, you will be a crucial part of the Cyber Threat Intelligence and Incident Response team, where your primary responsibility will be to provide the company with high fidelity, actionable cyber threat intelligence and specialized incident response capabilities. You are expected to have a strong understanding of the latest security threats, industry-standard incident response methodologies, and investigation techniques. Additionally, your adaptability and eagerness to learn emerging threat actor tactics, tools, and techniques will be highly valued. Responsibilities: - Act as a key responder during security incidents, supporting containment, eradication, and recovery activities. - Perform detailed investigation and analysis of security alerts, intrusions, and malware using EDR, SIEM, and forensic tooling. - Support post-incident reviews, identifying root cause, control gaps, and lessons learned. - Coordinate with SOC, CTI, IT, legal, and third-party providers during incidents to ensure timely and effective response. - Support evidence collection and documentation to meet legal, regulatory, and internal reporting requirements. - During periods without active incident response activity, actively support Cyber Threat Intelligence operations and initiatives. Qualifications: - Degree in Cyber Security, Computer Science, Information Technology, or a related discipline, or equivalent practical experience. - Relevant incident response, blue team, or security operations certification (e.g., GCIH, GCED, or equivalent). - Demonstrated experience responding to security incidents, labs, or realistic tabletop exercises. Experience: - 6-10 years of incident management experience. - 3+ years in cybersecurity, with at least 2 years in SOC/CTI/Incident Response. - Hands-on experience in malware analysis, memory forensics, and log analysis. - Solid understanding of network protocols, secure configuratio

One address, no account. We’ll tell you when matching roles go live.

More at Endava

Related open roles

View all roles