Cyber Incident Response and Recovery Investigator Digital Forensics

3 days ago


Bengaluru Karnataka, India SAP Full time

**We help the world run better**

At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from.

**Summary**

**An SAP Global Cyber Incident Response and Recovery Investigator** plays a critical role in safeguarding SAP’s digital enterprise. As a front-line defender, the Investigator is responsible for triaging security events identified by monitoring tools, analyzing data to assess severity and urgency, and conducting initial evaluations to determine whether a cyberattack is underway. When a potential incident is identified, the Investigator works closely with Global Security Operations to scope the impact, coordinate containment efforts, and support forensic investigations to uncover the nature and details of the attack.

**What you'll do**

Our Global Cyber Security Incident Response and Recovery Investigator are our first line of response for security event and incidents with a global scope. They are responsible for triaging security alerts detected by Enterprise Detection and SIEM, analyzing available data to determine scope, severity, and priority to determine follow on actions, which could include escalation to a IR Investigator. In escalation cases, they then work in a supportive capacity to further validate if a cyber-attack is occurring, scoping the extent of a suspected attack, coordinating efforts to contain attacks, supporting forensic investigations to determine the details around an attack, and providing guidance on remediation actions.

In this role, you will:

- Conduct initial assessments and help drive root cause analysis.
- Contribute to the development of attack remediation and response strategies.
- Coordinate escalation handling and communication across teams.
- Triage operational security processes, including phishing response.
- Assist in maintaining and improving incident handling documentation—such as playbooks, runbooks, and standard operating procedures.
- Collaborate with Detection and SIEM teams to enhance detection logic and alert accuracy.
- Support forensic investigations with technical insights and evidence collection.
- Analysing cloud logs and telemetry for signs of compromise (e.g., CloudTrail, VPC Flow Logs, Azure Activity Logs).
- Leverage your offensive knowledge to identify gaps, simulate attacks, and drive improvements in detection, response, and hardening strategies.
- We value hands-on practitioners—our environment includes sandboxing, red vs. blue testing, or adversary emulation frameworks (e.g., MITRE ATT&CK, CALDERA, Atomic Red Team) and opportunities to build tooling or simulate attack chains.

**What you bring**

**Preferred Technical Skills and Experience**:

- ** Experience**:
7-10+ years in a cyber incident investigation role or equivalent combination of education, certifications, and relevant training.
- ** Certifications -**Industry-recognized certifications such as **Security+, GCIA, GCIH, CISSP (or equivalent).**:

- Strong understanding of Advanced Persistent Threat (APT) actors, their tools, techniques, and procedures (TTPs), as well as threat modelling frameworks.
- ** Operating Systems & Forensics**:
In-depth knowledge of forensic artifacts across one or more platforms:

- Windows/Active Directory (file systems, registry, memory artifacts)
- Unix/Linux (file systems, memory artifacts)
- macOS (file systems, memory artifacts)
- ** Specialized Domains (any of the following)**:

- Cybersecurity automation and orchestration
- ** Cloud Platforms**:

- Deep familiarity with AWS, Azure, and/or GCP — with an emphasis on security posture, logging, and IR tooling.
- Experience conducting incident response and post-incident forensics in cloud environments.
- Understanding of cloud-native service abuse and misconfigurations (IAM, serverless, container runtime attacks).
- Security Infrastructure Tools: (SIEM, IDS, EDR, DNS, other Deception technologies)
- Proficiency in scripting languages such as **PowerShell, Python, or Bash**.

**Bring out your best**

**We win with inclusion**

SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone - regardless of background - feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better and more equitable world.

**E



  • Bengaluru, Karnataka, India SAP Full time

    **We help the world run better** At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and...


  • Bengaluru, Karnataka, India SAP Full time

    **We help the world run better** At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and...


  • Bengaluru, Karnataka, India SAP Full time

    **We help the world run better** At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and...


  • Bengaluru, Karnataka, India b312d2b8-7ab1-49e9-949a-00deb5c23278 Full time ₹ 4,00,000 - ₹ 7,00,000 per year

    We're Hiring – DFIR Specialist | Ssquad GlobalLocation: Whitefield, BangaloreType: Full-time,Salary : As per Market Standard , 5 days Work from OfficeInterview Mode : First Round Virtual , 2nd Round Face to Face in Bangalore OfficeSsquad Global is looking for an experienced Digital Forensics & Incident Response (DFIR) Specialist to join our cybersecurity...


  • Bengaluru, Karnataka, India Careernet Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Job Overview:Incident Response: Respond to and manage cybersecurity incidents, including threat detection, containment, eradication, recovery, and post-incident activitiesThreat Hunting: Proactively hunt for threats within our environment, utilizing tools such as Anomali ThreatStream to identify potential security risks.Digital Forensics: Conduct digital...


  • Bengaluru, Karnataka, India Ssquad Global Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    We're Hiring – DFIR Specialist | Ssquad GlobalLocation: Whitefield, BangaloreType: Full-time,Salary : As per Market Standard , 5 days Work from OfficeInterview Mode : First Round Virtual , 2nd Round Face to Face in Bangalore OfficeSsquad Global is looking for an experienced Digital Forensics & Incident Response (DFIR) Specialist to join our...


  • Bengaluru, India SAP Full time

    We help the world run better At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your...


  • Bengaluru, Karnataka, India Unilever Full time

    **Job Title: Cyber Security Forensics SME** **Location: UniOps Bangalore** **ABOUT UNILEVER**: Be part of the world’s most successful, purpose-led business. Work with brands that are well-loved around the world, that improve the lives of our consumers and the communities around us. We promote innovation, big and small, to make our business win and grow;...


  • Bengaluru, India 5100 Kyndryl Solutions Private Limited Full time

    Who We Are At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. The Role We...


  • Bengaluru, India Proaxis Scitech Private Limited Full time

    **Associate - Digital Forensics** **Responsibilities** - Conduct remote, on-site, and in-lab forensic collections of digital evidence using best practices. - Conduct preliminary investigations and manage case intake. - Provide technical guidance and assistance to the team involved in the investigation. - Provide operational and administrative support. -...