Consultant – Forensics – National – ASU – Forensics – Discovery – Gurgaon
EY
Gurugram, Haryana
The Role
The consultant conducts end-to-end digital forensics and incident response investigations, collecting and preserving forensic images, memory captures and logs, analysing artifacts such as registry hives, prefetch files and EDR telemetry, mapping attacker behaviour to MITRE ATT&CK, and producing detailed investigation reports with timelines and remediation recommendations.
Skills & Experience
Candidates should have hands-on experience with forensic tools including FTK Imager, EnCase, Autopsy, Sleuth Kit and Volatility, plus working knowledge of EDR platforms such as CrowdStrike Falcon, Microsoft Defender XDR and SentinelOne, SIEM platforms including Splunk and Microsoft Sentinel, and triage utilities such as KAPE and VirusTotal.
Who It Suits
This role suits a mid-level forensics or DFIR professional with practical investigation experience who is comfortable working across endpoint, network and malware domains within a fast-paced advisory environment, and who wants to develop within a structured professional services practice serving corporate and legal clients.
Typical advertised salary for Digital Forensics roles in India: ₹240,000–₹2,000,000 (median ₹550,000 — from 11 recent listings analysed by Forensic Focus).
Learn More/Apply





