Consultant - Forensics - National - ASU - Forensics - Discovery - Gurgaon
EY
EY
Join a global leader in assurance, tax, transaction, and advisory services to build a better working world. At EY, we foster a culture of continuous learning and development, providing unparalleled training, opportunities, and creative freedom. We are invested in your career growth, offering motivating experiences to help you achieve your professional aspirations.
This role is within the National Forensics team, specifically focusing on Discovery. In this capacity, you will help organizations safeguard and restore their financial and brand reputations by investigating facts, resolving disputes, and managing regulatory challenges. We help companies manage ethical and reputational risks, enhance governance, controls, and data insights, and implement robust organizational structures.
As a DFIR Analyst, you will lead investigations into security incidents, meticulously analyze digital evidence, and contribute to the containment and remediation of cyber security events. Your responsibilities include:
- Understanding incident specifics, affected systems, and business impact. - Identifying and collecting relevant evidence from logs, endpoints, and networks. - Reviewing alerts from SIEM, EDR, and other security platforms. - Validating suspicious activities and reconstructing attack paths. - Supporting containment actions like endpoint isolation and IOC blocking. - Acquiring forensic images and volatile data using approved methods. - Preserving evidence integrity and maintaining chain-of-custody. - Analyzing forensic artifacts such as event logs, registry entries, and browser data. - Investigating endpoints, malware, and network indicators to determine persistence, lateral movement, and root cause. - Enriching indicators with threat intelligence and mapping attacker techniques. - Preparing comprehensive investigation reports with findings and recommendations.
To excel in this role, you will need hands-on experience with forensic tools like Autopsy, Sleuth Kit, FTK Imager, EnCase, Cellebrite, and Volatility. Familiarity with EDR and incident response platforms such as Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, and Carbon Black is essential. You should be adept at analyzing logs using SIEM platforms like Splunk, Elastic, Microsoft Sentinel, and QRadar, with a basic understanding of network and packet analysis tools (e.g., Wireshark).
Key competencies include a strong grasp of Windows and Linux internals, Active Directory, and cloud platforms (AWS, Azure). Knowledge of common cyber-attack techniques and basic scripting skills in PowerShell or Python are required. You must possess strong analytical, troubleshooting, and communication skills, with the ability to maintain meticulous attention to detail under pressure.
We seek candidates with 2–4 years of experience in DFIR investigations. A Bachelor’s degree in IT/CS or equivalent experience is necessary. Preferred certifications include GIAC GCIH/GCFA, CEH/CHFI, or tool-specific certifications.
EY Global Delivery Services ( EY GDS)
Advisory