TRCD-26-04228
Incident Response (IR) Consultant / Senior Security Analyst (DFIR)
Contract role in Mumbai (Airoli) for a 2–4 years Incident Response/DFIR professional to handle end-to-end incident investigations (triage through recovery and post-incident), perform digital forensics across endpoints/servers/network/cloud, conduct threat hunting, map activity to MITRE ATT&CK, and support detection engineering (SIEM use cases/rule optimization). The role also involves IR readiness/cyber resilience assessments and producing technical and executive reports; candidates must be available for a face-to-face interview drive at the Airoli office.
Position summary
- Location
- India
- Workplace
- On-site
- Employment
- Contract
- Experience
- Minimum 2 years and Maximum 4 years
Role overview
Why This Role Matters.
Contract role in Mumbai (Airoli) for a 2–4 years Incident Response/DFIR professional to handle end-to-end incident investigations (triage through recovery and post-incident), perform digital forensics across endpoints/servers/network/cloud, conduct threat hunting, map activity to MITRE ATT&CK, and support detection engineering (SIEM use cases/rule optimization). The role also involves IR readiness/cyber resilience assessments and producing technical and executive reports; candidates must be available for a face-to-face interview drive at the Airoli office.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Digital Forensics across endpoints, servers, network devices, cloud platforms, and applications.
Threat Hunting using intelligence-driven and hypothesis-based methodologies.
Mapping threats and adversary activities to the MITRE ATT&CK framework.
Detection Engineering, SIEM use case development, and rule optimization.
Incident Response Readiness Assessments and Cyber Resilience evaluations.
Preparation of technical and executive-level reports.
SOC Operations, Incident Response (IR), DFIR, and Threat Hunting.
Windows, Linux, Unix, Networking, Cloud Security, APIs.
SIEM, EDR, Firewalls, Proxies, Identity Systems, Email Security, and Cloud Platform logs.
NIST, CERT-In, SANS Frameworks.
MITRE ATT&CK, Cyber Kill Chain, Diamond Model.
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
Incident Response
IR
SOC
DFIR
Digital Forensics
Threat Hunting
MITRE ATT&CK
Detection Engineering
SIEM
EDR
Firewall
Proxy
Identity Systems
Email Security
Cloud Platform Logs
Windows
Linux
Unix
Networking
Cloud Security
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
Incident Response (IR) lifecycle: triage, containment, eradication, recovery, post-incident analysis
SOC operations / security monitoring
DFIR (Digital Forensics & Incident Response) fundamentals
Digital forensics across endpoints/servers/network/cloud/applications
Threat hunting (intelligence-driven and hypothesis-based)
MITRE ATT&CK mapping
Detection engineering: SIEM use case development and rule optimization
Working knowledge of Windows and Linux/Unix
Networking fundamentals
Cloud security and cloud platform logs
Log sources: SIEM, EDR, firewalls, proxies, identity systems, email security
Security frameworks: NIST, CERT-In, SANS
Threat models: Cyber Kill Chain, Diamond Model
OWASP Top 10 and application security concepts
Cybersecurity risk assessment and mitigation planning
Technical and executive reporting
Preferred
Nice to Have
CHFI certification
Microsoft SC-200 certification
Microsoft SC-100 certification
ISO 27001 knowledge/certification
ISO 31000 knowledge/certification
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Incident Response (IR) Consultant / Senior Security Analyst (DFIR)
One page, about two minutes. We only ask for what we actually need to have a first conversation.