Role Overview:
Hiring for a Big 4 consulting firm in Mumbai. The primary focus of the role will be to lead cybercrime, cyber fraud, BEC, endpoint/cloud/email forensic investigations and technically complex incident reconstruction. Own evidence strategy, client-facing forensic conclusions and technical quality control.
Key Responsibilities:
- Own cyber forensic investigation planning for laptops, servers, cloud accounts, email systems and endpoints including evidence preservation and chain-of-custody discipline.
- Supervise and review endpoint, cloud, mailbox and system artefact analysis.
- Connect technical artefacts with fraud narrative, timeline, impact and root cause inputs.
- Coordinate with client IT, legal, incident response teams and, where relevant, law enforcement stakeholders.
- Create reusable playbooks for BEC, cloud compromise, data leakage kind of matters.
- Ensure AI-assisted triage is validated and not treated as independent evidence.
- Support scoping, effort estimation and client presentation of technical findings.
- Support AI model deployment and agentic AI tool design.
Qualifications and Skills:
- BE/B.Tech/MCA/MSc IT or equivalent technical qualification (CS/IT/Telecom).
- 7-10 years in DFIR, cybercrime investigation, IR, forensic lab, cyber cell or Big 4 consulting.
- Strong hands-on experience with Windows, Linux, endpoint, server and cloud artefacts.
- Strong Microsoft 365/Google Workspace investigation exposure.
- Ability to design evidence acquisition plans across all assets and data sources.
- Experience in BEC, account compromise, data theft, insider threat, payment diversion or ransomware cases.
- Tool exposure to Intella, Nuix, EnCase, X-Ways, FTK, Magnet, Velociraptor, KAPE, Autopsy, Splunk, Defender or Purview.
- Ability to write forensic reports and RCA inputs in regulator-safe language.
- Strong client communication, team review and pressure-handling skills.
- Strong exposure to AI copilots, scripts and automation for triage while preserving defensibility.
- Well versed with Sigma, YARA, KQL, Splunk SPL, Detection engineering tools and GCFA, GCFE, GCIH, EnCE, SC-200, AZ-500 or equivalent active/valid certifications preferred.
Role Expectations:
- Lead technical investigation strategy and evidence collection plan.
- Approve acquisition approach and validate evidence integrity.
- Review timelines, artefact interpretation and technical conclusions.
- Guide seniors on tool selection, documentation and limits of analysis.
- Identify evidence gaps and recommend further collection or ring-fencing steps.
- Translate technical findings into business, fraud and impact narratives.
- Maintain court and regulator defensibility across working papers and reports.
- Mentor team members on forensic methodology and quality review.
- Support field collection at client locations when required.
- Ensure AI outputs are corroborated, caveated and documented.
- Proficiency in Microsoft Copilot, ChatGPT, Claude, Gemini models.
- Comfortable with Prompt engineering, RAG concepts, AI validation techniques, AI hallucination controls.
- Knowledge of Multi-agent systems, MCP servers, AI governance, Knowledge graph investigations.
- Ability to create and use Investigation copilots, Investigation automation and Cross-case intelligence.
(ref:iimjobs.com)