Ubique Systems

TRCD-26-04228

Incident Response (IR) Consultant / Senior Security Analyst (DFIR)

Contract role in Mumbai (Airoli) for a 2–4 years Incident Response/DFIR professional to handle end-to-end incident investigations (triage through recovery and post-incident), perform digital forensics across endpoints/servers/network/cloud, conduct threat hunting, map activity to MITRE ATT&CK, and support detection engineering (SIEM use cases/rule optimization). The role also involves IR readiness/cyber resilience assessments and producing technical and executive reports; candidates must be available for a face-to-face interview drive at the Airoli office.

Position summary

Location
India
Workplace
On-site
Employment
Contract
Experience
Minimum 2 years and Maximum 4 years
Apply now

Role overview

Why This Role Matters.

Contract role in Mumbai (Airoli) for a 2–4 years Incident Response/DFIR professional to handle end-to-end incident investigations (triage through recovery and post-incident), perform digital forensics across endpoints/servers/network/cloud, conduct threat hunting, map activity to MITRE ATT&CK, and support detection engineering (SIEM use cases/rule optimization). The role also involves IR readiness/cyber resilience assessments and producing technical and executive reports; candidates must be available for a face-to-face interview drive at the Airoli office.

Your Impact

Deliver Enterprise Value

Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.

Collaboration

Work Across Teams

Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.

Growth

Learn Continuously

Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.

Career Path

Grow With Ubique

Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.

Responsibilities

What You'll Be Doing.

Every role at Ubique contributes directly to solving meaningful business challenges for our clients.

01

End-to-end Incident Response investigations including triage, containment, eradication, recovery, and post-incident analysis.

02

Digital Forensics across endpoints, servers, network devices, cloud platforms, and applications.

03

Threat Hunting using intelligence-driven and hypothesis-based methodologies.

04

Mapping threats and adversary activities to the MITRE ATT&CK framework.

05

Detection Engineering, SIEM use case development, and rule optimization.

06

Incident Response Readiness Assessments and Cyber Resilience evaluations.

07

Preparation of technical and executive-level reports.

08

SOC Operations, Incident Response (IR), DFIR, and Threat Hunting.

09

Windows, Linux, Unix, Networking, Cloud Security, APIs.

10

SIEM, EDR, Firewalls, Proxies, Identity Systems, Email Security, and Cloud Platform logs.

11

NIST, CERT-In, SANS Frameworks.

12

MITRE ATT&CK, Cyber Kill Chain, Diamond Model.

Technology stack

Tools & Technologies.

The platforms and technologies you'll use to build modern, enterprise-grade solutions.

01

Incident Response

02

IR

03

SOC

04

DFIR

05

Digital Forensics

06

Threat Hunting

07

MITRE ATT&CK

08

Detection Engineering

09

SIEM

10

EDR

11

Firewall

12

Proxy

13

Identity Systems

14

Email Security

15

Cloud Platform Logs

16

Windows

17

Linux

18

Unix

19

Networking

20

Cloud Security

Requirements

Skills & Experience.

We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.

Essential

Required Qualifications

Incident Response (IR) lifecycle: triage, containment, eradication, recovery, post-incident analysis

SOC operations / security monitoring

DFIR (Digital Forensics & Incident Response) fundamentals

Digital forensics across endpoints/servers/network/cloud/applications

Threat hunting (intelligence-driven and hypothesis-based)

MITRE ATT&CK mapping

Detection engineering: SIEM use case development and rule optimization

Working knowledge of Windows and Linux/Unix

Networking fundamentals

Cloud security and cloud platform logs

Log sources: SIEM, EDR, firewalls, proxies, identity systems, email security

Security frameworks: NIST, CERT-In, SANS

Threat models: Cyber Kill Chain, Diamond Model

OWASP Top 10 and application security concepts

Cybersecurity risk assessment and mitigation planning

Technical and executive reporting

Preferred

Nice to Have

CHFI certification

Microsoft SC-200 certification

Microsoft SC-100 certification

ISO 27001 knowledge/certification

ISO 31000 knowledge/certification

What you'll gain

More Than Just A Job.

We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.

Global Exposure

Collaborate with international clients and multicultural teams on enterprise programmes.

Continuous Learning

Expand your expertise through mentoring, certifications and hands-on project experience.

Career Growth

Take ownership, develop leadership skills and grow your consulting career over time.

Flexible Working

Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.

People First

Join a supportive culture where collaboration, respect and long-term relationships come first.

Enterprise Projects

Work on meaningful technology initiatives for leading organisations across industries.

Apply

Apply for Incident Response (IR) Consultant / Senior Security Analyst (DFIR)

One page, about two minutes. We only ask for what we actually need to have a first conversation.

Your CV

Optional. A line or two is plenty.