DFIR Lead
UST
Trivandrum, Kerala
The Role
This lead-level position sits at the top of the escalation tier, conducting in-depth forensic investigations across file systems, memory, and network environments. Day-to-day responsibilities include containment, eradication, and recovery during active incidents, developing automation tools to accelerate triage, producing detailed incident reports, and collaborating with pre-sales and account teams to expand the DFIR service offering.
Skills & Experience
Candidates need 3+ years in DFIR, threat hunting, SOC, or information security, with deep knowledge of Windows and Linux internals, network communications, and compromise indicators. Proficiency in EDR, SIEM, and firewall datasets is expected, along with dynamic and static malware analysis skills. Certifications such as GCFE, GCFA, GNFA, GCIH, or GCIA are advantageous, as is experience with macOS forensics or cloud IR.
Who It Suits
This role suits an experienced DFIR practitioner ready to take technical and managerial ownership of a growing forensics service. Those comfortable with 24/7 on-call responsibility during critical incidents, who combine hands-on investigative depth with strong client communication skills, will thrive in this environment.
Typical advertised salary for Digital Forensics roles in India: ₹240,000–₹2,000,000 (median ₹550,000 — from 11 recent listings analysed by Forensic Focus).
Compare Digital Forensics salaries in India →
Certifications mentioned: GCFA · GCFE · GNFA · GCIH — find training for these on the DFIR Training Finder.





