Consultant - Forensics - National - ASU - Forensics - Discovery - Gurgaon
EY
- Location
- Gurugram, HR, IN, 122003
- Work model
- On-Site
- Level
- Mid
Skills
About this role
Requisition Id: 1739229 As a global leader in assurance, tax, transaction and advisory services, we hire and develop the most passionate people in their field to help build a better working world. This starts with a culture that believes in giving you the training, opportunities and creative freedom. At EY, we don't just focus on who you are now, but who you can become. We believe that it’s your career and ‘It’s yours to build’ which means potential here is limitless and we'll provide you with motivating and fulfilling experiences throughout your career to help you on the path to becoming your best professional self. The opportunity : Consultant-National-Forensics-ASU - Forensics - Discovery - Gurgaon National : National comprises of sector agnostic teams working across industries for a well rounded experience. ASU - Forensics - Discovery : Successful organizations depend on their reputation for keeping promises, respecting laws and behaving ethically to maintain stakeholder trust. EY Forensic & Integrity Services professionals help organizations protect and restore enterprise and financial reputation. We assist companies and their legal counsel to investigate facts, resolve disputes and manage regulatory challenges. We put integrity at the heart of compliance programs to help better manage ethical and reputational risks. Our integrated approach ranges from enhancements in areas of perceived weakness or issues — including governance, controls, culture and data insights — to full organizational design and structural implementation. We want to help companies safeguard and restore financial and brand reputations. The insights and quality services we deliver help build trust and confidence in the capital markets and in economies the world over. Your key responsibilities Technical Excellence
DFIR Analyst is responsible for investigating security incidents, analysing digital evidence and helping in containment and remediation of cyber security incident. The Analyst should be having experience on hands-on investigations, triage, evidence collection and documentation of complex cyber security incidents. 1. Key Responsibilities Understand incident details, affected systems, business impact and available infrastructure context. Identify relevant evidence sources, including logs, endpoint data, network data and security platform telemetry. Review alerts and logs from SIEM, EDR, SOAR, IDS/IPS, email security and other available sources. Validate suspicious activity and correlate events to reconstruct the probable attack path. Support initial containment actions such as endpoint isolation, IOC blocking and access restriction. Acquire forensic images, memory captures, logs and volatile data using approved procedures and tools. Preserve evidence integrity by minimizing contamination and maintaining proper chain-of-custody records. Analyse forensic artifacts such as event logs, registry, prefetch, LNK files, browser artifacts, metadata and EDR telemetry. Investigate endpoint, malware, email and network indicators to identify persistence, lateral movement, exfiltration and root cause. Enrich indicators using threat intelligence sources and map attacker behaviour to MITRE ATT&CK techniques. Prepare triage and investigation reports covering timelines, findings, impact, corrective actions and recommendations. 2. Tools & Technology Knowledge Hands-on knowledge of forensic tools such as Autopsy, Sleuth Kit, FTK Imager, EnCase, Cellebrite and Volatility. Working familiarity with EDR and incident response platforms including Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne and Carbon Black. Ability to analyze logs using SIEM and log analytics platforms such as Splunk, Elastic, Microsoft Sentinel and QRadar. Basic understanding of network and packet analysis tools including Wireshark, NetFlow analyzers and related investigation utilities. Awareness of malware analysis and triage