DFIR Analyst
Innefu Labs
Delhi
The Role
The analyst investigates cybersecurity incidents across Windows, Linux, and macOS endpoints, analysing platform-specific forensic artifacts, performing memory forensics using tools such as Volatility, extracting and correlating IOCs, building attack timelines, and supporting threat hunting and remediation activities in collaboration with SOC and IR teams.
Skills & Experience
Candidates need 2–3 years of DFIR or SOC experience, familiarity with file systems including NTFS, ext4, and APFS, and hands-on use of tools such as Magnet AXIOM, KAPE, Velociraptor, EnCase, or FTK. Scripting in Python, PowerShell, or Bash and knowledge of MITRE ATT&CK TTPs are expected. Certifications such as GCFE, GCFA, or GCIH are advantageous.
Who It Suits
This role suits a mid-level cybersecurity professional with practical forensic investigation experience who is comfortable working across multiple operating systems, communicating findings to both technical and non-technical stakeholders, and contributing to playbook development and detection engineering improvements.
Typical advertised salary for Digital Forensics roles in India: ₹240,000–₹2,000,000 (median ₹550,000 — from 11 recent listings analysed by Forensic Focus).
Compare Digital Forensics salaries in India →
Certifications mentioned: GCFA · GCFE · GCIH — find training for these on the DFIR Training Finder.





