
Cyber Incident Response and Recovery Investigator Digital Forensics
16 hours ago
**We help the world run better**
At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from.
**Summary**
**An SAP Global Cyber Senior Incident Response and Recovery Investigator** plays a critical role in safeguarding SAP’s digital enterprise. As a front-line defender, the Investigator is responsible for triaging security events identified by monitoring tools, analysing data to assess severity and urgency, and conducting initial evaluations to determine whether a cyberattack is underway. When a potential incident is identified, the Investigator works closely with Global Security Operations to scope the impact, coordinate containment efforts, and support forensic investigations to uncover the nature and details of the attack.
**What you'll do**
Our Global Cyber Security Incident Response and Recovery Investigator are our first line of response for security event and incidents with a global scope. They are responsible for triaging security alerts detected by Enterprise Detection and SIEM, analysing available data to determine scope, severity, and priority to determine follow on actions, which could include escalation to a IR Investigator. In escalation cases, they then work in a supportive capacity to further validate if a cyber-attack is occurring, scoping the extent of a suspected attack, coordinating efforts to contain attacks, supporting forensic investigations to determine the details around an attack, and providing guidance on remediation actions.
In this role, you will:
- Conduct initial assessments and help drive root cause analysis.
- Contribute to the development of attack remediation and response strategies.
- Coordinate escalation handling and communication across teams.
- Triage operational security processes, including phishing response.
- Assist in maintaining and improving incident handling documentation—such as playbooks, runbooks, and standard operating procedures.
- Collaborate with Detection and SIEM teams to enhance detection logic and alert accuracy.
- Support forensic investigations with technical insights and evidence collection.
- Analysing cloud logs and telemetry for signs of compromise (e.g., CloudTrail, VPC Flow Logs, Azure Activity Logs).
- Leverage your offensive knowledge to identify gaps, simulate attacks, and drive improvements in detection, response, and hardening strategies.
- We value hands-on practitioners—our environment includes sandboxing, red vs. blue testing, or adversary emulation frameworks (e.g., MITRE ATT&CK, CALDERA, Atomic Red Team) and opportunities to build tooling or simulate attack chains.
**What you bring**
**Preferred Technical Skills and Experience**:
- ** Experience**:
8-14+ years in a cyber incident investigation role or equivalent combination of education, certifications, and relevant training.
- ** Certifications -**Industry-recognized certifications such as **Security+, GCIA, GCIH, GCFA, GCFE, GREM, CISSP (or equivalent).**:
- Strong understanding of Advanced Persistent Threat (APT) actors, their tools, techniques, and procedures (TTPs), as well as threat modelling frameworks.
- Security Infrastructure Tools: (SIEM, IDS, EDR, DNS, other Deception technologies)
- Proficiency in scripting languages such as **PowerShell, Python, or Bash.**:
- ** Core Forensic Competencies**:
- Expertise in memory, disk, and file system forensics across multiple OS platforms (Windows, Linux, macOS).
- Experience performing volatile memory acquisition and analysis (e.g., using Volatility, Plaso, Sleuth Kit, Velociraptor, KAPE).
- Proficient in analyzing logs, timelines, and system artifacts to reconstruct attacker activity.
- Proficiency in forensic toolsets such as EnCase, FTK, X-Ways, Autopsy.
- Knowledge of file carving, metadata analysis, and data recovery.
- ** Cloud Forensics & Logging**:
- Experience analyzing cloud logs (e.g., CloudTrail, Azure Activity Logs, GCP Audit Logs).
- Familiarity with cloud storage and compute forensics (e.g., EC2, Lambda, S3, Blob Storage).
- Ability to investigate container and orchestration layers (e.g., Docker, Kubernetes, EKS/AKS/GKE).
**Bring out your best**
**We win with inclusion**
SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone - regardless of background - feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confi
-
Digital Forensic Investigator
1 week ago
Bengaluru, Karnataka, India Haleon Full timeDescription The Investigative Support Forensics Services Examiner will be a member of the Global Cyber Defense team and will be responsible for assisting with the delivery of digital forensics services to customers across the Haleon. The successful applicant will provide support to the Forensic Services Manager for various incident types by following...
-
Digital Forensics and Incident Response(DFIR)
2 weeks ago
Bengaluru, Karnataka, India Careernet Full time ₹ 9,00,000 - ₹ 12,00,000 per yearJob Overview:Incident Response: Respond to and manage cybersecurity incidents, including threat detection, containment, eradication, recovery, and post-incident activitiesThreat Hunting: Proactively hunt for threats within our environment, utilizing tools such as Anomali ThreatStream to identify potential security risks.Digital Forensics: Conduct digital...
-
Digital Forensics Investigator
1 week ago
Bengaluru, Karnataka, India beBeeDigitalForensics Full time ₹ 10,00,000 - ₹ 15,00,000Forensic Investigation ProfessionalA highly skilled specialist is required to perform in-depth analysis of digital evidence and ensure integrity. The ideal candidate must have hands-on experience in RAID recovery, data extraction, and digital investigations.Main Responsibilities:Perform thorough examination of digital evidence and maintain a secure chain of...
-
Scientific Officer
1 week ago
Bengaluru, India Group cyber ID Full timeCompany - Group Cyber ID **Formal position title: Forensics and Cyber Security Analyst** (Digital forensics / Cyber Security) **Job Overview**: **Responsibilities and Duties**: - To develop, manage and monitor all the internship programmes. This includes associated operational administration, curriculum and lab development and quality management and...
-
Senior Cyber Forensic Investigator
2 weeks ago
Bengaluru, Karnataka, India beBeeCybersecurity Full time ₹ 20,00,000 - ₹ 25,00,000We are seeking a highly skilled and experienced Information Security Engineer to join our cybersecurity team.Key ResponsibilitiesLead high-severity security incident investigations and coordinate response efforts across internal stakeholders.Perform endpoint, network, and cloud-based forensics to determine root cause, scope, and impact of cyber...
-
Expertise in Cyber Security Forensics
1 week ago
Bengaluru, Karnataka, India beBeeCyberSecurityForensics Full time ₹ 1,50,00,000 - ₹ 2,00,00,000Cyber Security Forensics Expertise: A Key Asset for Your Organization As a seasoned cybersecurity forensics professional, you will be responsible for leading all in-house investigations and coordinating with external investigators/specialists in major incidents. Your expertise will be crucial in generating leads for timely containment and response actions,...
-
Expert Cyber Security Incident Responder
4 days ago
Bengaluru, Karnataka, India Finastra USA Corporation Full time**Responsibilities**: **Job Summary** **Responsibilities** Acts as Security Incident Handler for high-impact cyber security incidents and advanced attacks in accordance with Cyber Kill Chain methodology and incident response process. Understands Incident Response processes and participate in analysis, containment, and eradication/remediation of security...
-
Cyber Security Forensics SME
1 day ago
Bengaluru, India Hindustan Unilever Full timeJob Description Job Title: Cyber Security Forensics SME Location: UniOps Bangalore ABOUT UNILEVER: Be part of the world's most successful, purpose-led business. Work with brands that are well-loved around the world, that improve the lives of our consumers and the communities around us. We promote innovation, big and small, to make our business win and...
-
Incident Response Professional
3 days ago
Bengaluru, Karnataka, India beBeeCyberSecurity Full time ₹ 12,00,000 - ₹ 36,00,000Cybersecurity Incident Response RoleAs a member of our Cyber Team, you will be responsible for building and maintaining positive working relationships with teams and clients to deliver exceptional results.You will have a deep understanding of computer intrusion activities, incident response techniques, tools, and procedures.Knowledge of Windows, Active...
-
Lecturer (Digital Forensic)
2 weeks ago
Bengaluru, India Group cyber ID Full timeCompany - Group Cyber ID **Formal position title: Scientific Assistance** (Digital forensics / Cyber Security) **Job Overview**: **Responsibilities and Duties**: - To develop, manage and monitor all the internship programmes. This includes associated operational administration, curriculum and lab development and quality management and enhancement...