Talent.com
DFIR & Endpoint Security Analyst
DFIR & Endpoint Security AnalystXcitium • Kolhapur, IN
No longer accepting applications
DFIR & Endpoint Security Analyst

DFIR & Endpoint Security Analyst

Xcitium • Kolhapur, IN
11 days ago
Job description

Lead hands-on Digital Forensics & Incident Response (DFIR) engagements for active security incidents in Microsoft-centric environments. In addition to DFIR, you will help deliver and mature our Managed Endpoint for Microsoft Defender service—owning policy, posture management, and security hardening across customer environments. You will run investigations end-to-end (scoping, containment, remediation, recovery) and act as the senior technical authority during high-severity incidents within our MDR operations.


Key Responsibilities

  • Lead high-severity incident response (ransomware, identity compromise, BEC, cloud intrusions)
  • Investigate and respond using Microsoft Defender (Endpoint, Identity, O365, Cloud Apps) and Entra ID
  • Perform deep endpoint, identity, email, and cloud investigations; build attacker timelines
  • Scope compromise, contain threats, and guide remediation and recovery
  • Deliver Managed Endpoint for Defender:
  • Own Defender policy design, deployment, tuning, and enforcement
  • Drive security posture management (baseline hardening, exposure reduction, ASR rules, device control, attack surface reduction)
  • Continuously assess Defender coverage gaps, misconfigurations, and security hygiene
  • Translate posture findings into prioritized remediation plans for customers
  • Use EDR/XDR telemetry for live containment (host isolation, process termination, IOC blocking)
  • Produce incident reports, root cause analysis, posture findings, and executive-level updates
  • Support SOC escalations and guide L1/L2 analysts during live incidents
  • Participate in on-call rotation for 24x7 MDR operations

Required Experience

  • 5+ years hands-on DFIR / incident response ownership (not SOC-only)
  • Proven experience leading ransomware and multi-stage intrusion investigations
  • Strong Windows forensics, endpoint telemetry analysis, and live containment experience
  • Deep hands-on experience with Microsoft security stack (Defender suite, Entra ID, M365)
  • Experience designing and managing Defender policies and endpoint security posture
  • Ability to lead customer-facing incidents independently under pressure

Nice to Have

  • Threat hunting and hypothesis-driven investigations
  • PowerShell/Python for investigation automation
  • MDR/MSSP or consulting background
  • DFIR certifications (GIAC, eCTHP, GCFA/GCED/GCFE, etc.)

Work Model

  • Remote contractor role, reporting to US office
  • On-call / after-hours availability based on incident demand

Why Join Us?

  • Work real incidents with real impact — ransomware, identity compromise, cloud intrusions, and advanced threats
  • Combine DFIR leadership + Managed Endpoint for Defender, shaping both response and prevention
  • High autonomy and technical ownership — you run investigations end-to-end
  • Global MDR environment with challenging, non-repetitive cases
  • Direct influence on how our DFIR and Managed Endpoint practices are built and matured
  • Close collaboration with SOC, engineering, and security leadership — your technical judgment matters

Create a job alert for this search

DFIR Endpoint Security Analyst • Kolhapur, IN

Similar jobs
SOAR Engineer - Contract

SOAR Engineer - Contract

Gravity Infosolutions, Inc. • kolhapur, maharashtra, in
The role focuses on building playbooks, integrating security tools, and automating response workflows within a Security Operations environment.SOAR playbooks and automation workflows.SIEM, EDR, thr...Show more
Last updated: 6 days ago • Promoted
Security Engineer (DevSecOps)

Security Engineer (DevSecOps)

Firstsource • kolhapur, maharashtra, in
Firstsource Solutions Limited, an RP-Sanjiv Goenka Group company (NSE: FSL, BSE: 532809, Reuters: FISO.BO, Bloomberg: FSOL:IN), is a specialized global business process services partner, providing ...Show more
Last updated: 11 days ago • Promoted
Information Security Architect

Information Security Architect

Altisource • kolhapur, maharashtra, in
Are you up to the challenge of working directly with the Executive leadership of a US NASDAQ company on developing and organizing the financial strategy for different lines of business? If yes, kee...Show more
Last updated: 5 days ago • Promoted
Cyber Risk Management Analyst

Cyber Risk Management Analyst

Microtalent is becoming INSPYR Global Solutions • kolhapur, maharashtra, in
The Cyber Risk Management Analyst will support risk assessments across business applications and services following an.RCSA and AI risk assessment model.This role is responsible for executing struc...Show more
Last updated: 4 days ago • Promoted
Soar Engineer - Contract

Soar Engineer - Contract

Gravity Infosolutions, Inc. • Kolhāpur, Republic Of India, IN
The role focuses on building playbooks, integrating security tools, and automating response workflows within a Security Operations environment.SOAR playbooks and automation workflows.SIEM, EDR, thr...Show more
Last updated: 6 days ago • Promoted
AppScan Product _Lead Security Expert _Remote Location

AppScan Product _Lead Security Expert _Remote Location

HCLSoftware • kolhapur, maharashtra, in
Remote
Greetings from “HCL Software” Is a Product Development Division of HCL Tech!!.HCL Software”: - Is a Product Development Division of HCL Tech: That operates its primary Software Business.At HCL Soft...Show more
Last updated: 30+ days ago • Promoted
Sap Basis Security Consultant

Sap Basis Security Consultant

YASH Technologies • kolhapur, maharashtra, in
Lead and manage shift operations for a team of 10–15 SAP Basis consultants.Deliver SAP Basis support across.Create and maintain shift rosters, ensure task allocation and productivity improvement.Co...Show more
Last updated: 20 days ago • Promoted
Sr. Lead - Cloud Security

Sr. Lead - Cloud Security

Sycamore Informatics Inc. • kolhapur, maharashtra, in
Cloud security framework; Strong scripting skills with PowerShell and.Solid understanding of version control tools, particularly Git.Experience with cloud platforms, including AWS, Azure and GCP.Pr...Show more
Last updated: 27 days ago • Promoted
Information Security Lead / Manager

Information Security Lead / Manager

TWO95 International, Inc • kolhapur, maharashtra, in
Information Security Lead / Manager.Position – Fulltime with our client.We are seeking an experienced Information Security Lead / Manager to lead the organization’s cybersecurity strategy, operatio...Show more
Last updated: 22 days ago • Promoted
Security Operations Center Analyst

Security Operations Center Analyst

Vista Applied Solutions Group Inc • kolhapur, maharashtra, in
Location: Remote anywhere in India.A Senior Associate will hold the following roles and responsibilities as part of their role:.Demonstrate proficiency in Schellman Methodology.Obtain certification...Show more
Last updated: 23 days ago • Promoted
Security Analyst

Security Analyst

Insight Global • kolhapur, maharashtra, in
Identity & Access Management (IAM), Cloud Security, Identity Governance, or Vulnerability Management.Hands-on experience with cloud IAM (AWS, Azure, GCP).Experience with Okta, Entra ID, Active Dire...Show more
Last updated: 2 days ago • Promoted
Senior Manager - Network Security

Senior Manager - Network Security

Vivriti Capital • kolhapur, maharashtra, in
Vivriti Group is a leading alternate debt provider to corporates, having deployed over $5bn of capital since its inception in 2017.The group operates through two firms:.An NBFC, rated A+ by CRISIL,...Show more
Last updated: 27 days ago • Promoted
Security and Network Engineer

Security and Network Engineer

BigHammer.ai • kolhapur, maharashtra, in
Job Description: Multi-Cloud Network & Security Engineer (AI-driven Data Platforms).Multi-Cloud Network & Security Engineer .Google Cloud Platform (GCP), Amazon Web Services (AWS), and Microsoft Az...Show more
Last updated: 22 days ago • Promoted
Senior Portfolio Risk Analyst

Senior Portfolio Risk Analyst

Arcana • kolhapur, maharashtra, in
Arcana is a portfolio intelligence platform used by hedge funds and asset managers to analyze performance and risk.We’re rethinking the tools institutional investors rely on—and we’re hiring analys...Show more
Last updated: 30+ days ago • Promoted
Security & Compliance Engineer (Dark Trace)

Security & Compliance Engineer (Dark Trace)

aecc - digital innovation hub • kolhapur, maharashtra, in
Support the organisation’s security posture through monitoring, incident response coordination, and compliance activities.Work closely with IT operations, engineering, and leadership to ensure syst...Show more
Last updated: 23 days ago • Promoted
D365 Security Solution Architect | Erp & Zero Trust Leader

D365 Security Solution Architect | Erp & Zero Trust Leader

SMAT INFOTECH • Kolhāpur, Republic Of India, IN
D365 Security Solution Architect (Remote).The D365 Security Solution Architect is responsible for designing and governing end-to-end enterprise security architecture across Microsoft Dynamics 365 F...Show more
Last updated: 8 days ago • Promoted
Information Security Architect

Information Security Architect

Altaa Vistaa Business Solutions Pvt Ltd • kolhapur, maharashtra, in
Certified Information Systems Security Professional.Remote Support (Work From Home).PM to 1:30 AM IST (Monday to Friday).Best in industry (Open for discussion).Preferred an immediate joiner).The fo...Show more
Last updated: 25 days ago • Promoted
Sap Basis Security Consultant

Sap Basis Security Consultant

NR Consulting • kolhapur, maharashtra, in
Provide 24x7 rotational support for critical SAP systems.Monitor SAP applications using Focused Run (FRUN) or Cloud ALM, identify issues, and provide recommendations.Perform system health checks (p...Show more
Last updated: 4 days ago • Promoted