Cyber Incident Response and Recovery Investigator Digital Forensics

16 hours ago


Bengaluru Karnataka, India SAP Full time

**We help the world run better**

At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from.

**Summary**

**An SAP Global Cyber Senior Incident Response and Recovery Investigator** plays a critical role in safeguarding SAP’s digital enterprise. As a front-line defender, the Investigator is responsible for triaging security events identified by monitoring tools, analysing data to assess severity and urgency, and conducting initial evaluations to determine whether a cyberattack is underway. When a potential incident is identified, the Investigator works closely with Global Security Operations to scope the impact, coordinate containment efforts, and support forensic investigations to uncover the nature and details of the attack.

**What you'll do**

Our Global Cyber Security Incident Response and Recovery Investigator are our first line of response for security event and incidents with a global scope. They are responsible for triaging security alerts detected by Enterprise Detection and SIEM, analysing available data to determine scope, severity, and priority to determine follow on actions, which could include escalation to a IR Investigator. In escalation cases, they then work in a supportive capacity to further validate if a cyber-attack is occurring, scoping the extent of a suspected attack, coordinating efforts to contain attacks, supporting forensic investigations to determine the details around an attack, and providing guidance on remediation actions.

In this role, you will:

- Conduct initial assessments and help drive root cause analysis.
- Contribute to the development of attack remediation and response strategies.
- Coordinate escalation handling and communication across teams.
- Triage operational security processes, including phishing response.
- Assist in maintaining and improving incident handling documentation—such as playbooks, runbooks, and standard operating procedures.
- Collaborate with Detection and SIEM teams to enhance detection logic and alert accuracy.
- Support forensic investigations with technical insights and evidence collection.
- Analysing cloud logs and telemetry for signs of compromise (e.g., CloudTrail, VPC Flow Logs, Azure Activity Logs).
- Leverage your offensive knowledge to identify gaps, simulate attacks, and drive improvements in detection, response, and hardening strategies.
- We value hands-on practitioners—our environment includes sandboxing, red vs. blue testing, or adversary emulation frameworks (e.g., MITRE ATT&CK, CALDERA, Atomic Red Team) and opportunities to build tooling or simulate attack chains.

**What you bring**

**Preferred Technical Skills and Experience**:

- ** Experience**:
8-14+ years in a cyber incident investigation role or equivalent combination of education, certifications, and relevant training.
- ** Certifications -**Industry-recognized certifications such as **Security+, GCIA, GCIH, GCFA, GCFE, GREM, CISSP (or equivalent).**:

- Strong understanding of Advanced Persistent Threat (APT) actors, their tools, techniques, and procedures (TTPs), as well as threat modelling frameworks.
- Security Infrastructure Tools: (SIEM, IDS, EDR, DNS, other Deception technologies)
- Proficiency in scripting languages such as **PowerShell, Python, or Bash.**:

- ** Core Forensic Competencies**:

- Expertise in memory, disk, and file system forensics across multiple OS platforms (Windows, Linux, macOS).
- Experience performing volatile memory acquisition and analysis (e.g., using Volatility, Plaso, Sleuth Kit, Velociraptor, KAPE).
- Proficient in analyzing logs, timelines, and system artifacts to reconstruct attacker activity.
- Proficiency in forensic toolsets such as EnCase, FTK, X-Ways, Autopsy.
- Knowledge of file carving, metadata analysis, and data recovery.
- ** Cloud Forensics & Logging**:

- Experience analyzing cloud logs (e.g., CloudTrail, Azure Activity Logs, GCP Audit Logs).
- Familiarity with cloud storage and compute forensics (e.g., EC2, Lambda, S3, Blob Storage).
- Ability to investigate container and orchestration layers (e.g., Docker, Kubernetes, EKS/AKS/GKE).

**Bring out your best**

**We win with inclusion**

SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone - regardless of background - feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confi



  • Bengaluru, Karnataka, India Haleon Full time

    Description The Investigative Support Forensics Services Examiner will be a member of the Global Cyber Defense team and will be responsible for assisting with the delivery of digital forensics services to customers across the Haleon. The successful applicant will provide support to the Forensic Services Manager for various incident types by following...


  • Bengaluru, Karnataka, India Careernet Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Job Overview:Incident Response: Respond to and manage cybersecurity incidents, including threat detection, containment, eradication, recovery, and post-incident activitiesThreat Hunting: Proactively hunt for threats within our environment, utilizing tools such as Anomali ThreatStream to identify potential security risks.Digital Forensics: Conduct digital...


  • Bengaluru, Karnataka, India beBeeDigitalForensics Full time ₹ 10,00,000 - ₹ 15,00,000

    Forensic Investigation ProfessionalA highly skilled specialist is required to perform in-depth analysis of digital evidence and ensure integrity. The ideal candidate must have hands-on experience in RAID recovery, data extraction, and digital investigations.Main Responsibilities:Perform thorough examination of digital evidence and maintain a secure chain of...

  • Scientific Officer

    1 week ago


    Bengaluru, India Group cyber ID Full time

    Company - Group Cyber ID **Formal position title: Forensics and Cyber Security Analyst** (Digital forensics / Cyber Security) **Job Overview**: **Responsibilities and Duties**: - To develop, manage and monitor all the internship programmes. This includes associated operational administration, curriculum and lab development and quality management and...


  • Bengaluru, Karnataka, India beBeeCybersecurity Full time ₹ 20,00,000 - ₹ 25,00,000

    We are seeking a highly skilled and experienced Information Security Engineer to join our cybersecurity team.Key ResponsibilitiesLead high-severity security incident investigations and coordinate response efforts across internal stakeholders.Perform endpoint, network, and cloud-based forensics to determine root cause, scope, and impact of cyber...


  • Bengaluru, Karnataka, India beBeeCyberSecurityForensics Full time ₹ 1,50,00,000 - ₹ 2,00,00,000

    Cyber Security Forensics Expertise: A Key Asset for Your Organization As a seasoned cybersecurity forensics professional, you will be responsible for leading all in-house investigations and coordinating with external investigators/specialists in major incidents. Your expertise will be crucial in generating leads for timely containment and response actions,...


  • Bengaluru, Karnataka, India Finastra USA Corporation Full time

    **Responsibilities**: **Job Summary** **Responsibilities** Acts as Security Incident Handler for high-impact cyber security incidents and advanced attacks in accordance with Cyber Kill Chain methodology and incident response process. Understands Incident Response processes and participate in analysis, containment, and eradication/remediation of security...


  • Bengaluru, India Hindustan Unilever Full time

    Job Description Job Title: Cyber Security Forensics SME Location: UniOps Bangalore ABOUT UNILEVER: Be part of the world's most successful, purpose-led business. Work with brands that are well-loved around the world, that improve the lives of our consumers and the communities around us. We promote innovation, big and small, to make our business win and...


  • Bengaluru, Karnataka, India beBeeCyberSecurity Full time ₹ 12,00,000 - ₹ 36,00,000

    Cybersecurity Incident Response RoleAs a member of our Cyber Team, you will be responsible for building and maintaining positive working relationships with teams and clients to deliver exceptional results.You will have a deep understanding of computer intrusion activities, incident response techniques, tools, and procedures.Knowledge of Windows, Active...


  • Bengaluru, India Group cyber ID Full time

    Company - Group Cyber ID **Formal position title: Scientific Assistance** (Digital forensics / Cyber Security) **Job Overview**: **Responsibilities and Duties**: - To develop, manage and monitor all the internship programmes. This includes associated operational administration, curriculum and lab development and quality management and enhancement...