Rakuten
Staff Engineer, Digital Forensics & Incident Response
RSIN_Bangalore
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Role family
- Engineering
- Seniority
- Lead / management
- Country
- IN
- Work mode
- On-site / unstated
- First seen by hirly
- 2 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Job Description:
Description:
The Security Engineering & Operations Supervisory Department at Rakuten Mobile is seeking a Senior DFIR Lead to join a growing cyber defense organization. The candidate will serve as a lead responder for complex security incidents, performing deep-dive forensic investigations, root cause analysis, and containment activities. This role is ideal for a seasoned investigator who thrives under pressure, possesses a forensic mindset, and can turn incident findings into strategic improvements that harden our environment against future threats.
Responsibilities:
- Lead and execute end-to-end incident response investigations, from initial triage and scoping to containment, eradication, and recovery.
- Perform deep-dive forensic analysis of endpoints, network traffic, and cloud environments to reconstruct intrusion chains and identify the scope of compromise.
- Conduct advanced malware analysis (static and dynamic) to understand adversary capabilities, persistence mechanisms, and command-and-control (C2) infrastructure.
- Develop and maintain incident response playbooks and standard operating procedures (SOPs) for various threat scenarios, ensuring alignment with industry best practices.
- Collaborate with the Threat Hunting and Detection Engineering teams to provide "lessons learned" from investigations, ensuring that incident findings are converted into permanent detection logic.
- Partner with Legal, Privacy, and IT stakeholders during high-stakes incidents to ensure proper evidence handling, chain-of-custody, and regulatory compliance.
- Utilize advanced forensic tools (e.g., EnCase, FTK, Magnet AXIOM, Volatility) and SIEM/EDR platforms to conduct investigations and validate findings.
- Automate forensic collection and analysis processes using scripting languages (e.g., Python, PowerShell) to reduce time-to-respond during critical incidents.
- Provide mentorship to junior analysts, conducting peer reviews of forensic reports and overseeing the technical quality of investigations.
- Maintain a high level of readiness for 24/7 incident response support, providing expert guidance during major security breaches.
Requirements:
Qualifications:
- Minimum of 10-12 years of experience in cybersecurity, with significant expertise in Digital Forensics and Incident Response.
- Bachelor’s degree in computer science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience.
- Industry certifications such as SANS GCFA, GCFE, GNFA, or CISSP are highly preferred.
Required Skills & Knowledge:
- Expertise in forensic artifacts across major Operating Systems (Windows, Linux, macOS), including file system analysis, memory forensics, and registry/log analysis.
- Deep expertise in investigating security incidents within telecommunications environments. Ability to perform forensic analysis on mobile core network elements, identifying anomalies in signaling protocols (e.g., 4G/5G, SS7, Diameter, GTP, HTTP/2). Experience in tracing malicious activity across complex, high-throughput telecom traffic flows.
- Proven experience conducting incident response in containerized environments. Ability to perform runtime forensics within Kubernetes (K8s) clusters, including container breakout analysis, pod-level log correlation, and forensic inspection of ephemeral storage. Deep understanding of K8s API audit logs, etcd integrity, and the forensic implications of container orchestration
- In-depth knowledge of the MITRE ATT&CK framework for mapping adversary behavior during investigations and identifying gaps in current security controls.
- Strong understanding of enterprise network architecture and protocols, with the ability to perform full-packet capture analysis to identify malicious traffic patterns.
- Deep understanding of cloud-native environments, including Kubernetes and container orchestration; proven experience performing incident response within AWS, Azure, or GCP.
- Experience leveraging advanced AI/ML capabilities, including LLMs, to assist in log correlation, code analysis, and the summarization of complex incident timelines.
- Exceptional analytical expertise, critical thinking, and the ability to remain calm and methodical under high-pressure, time-sensitive situations.
- Excellent written and verbal communication skills, with the ability to produce high-quality, court-admissible forensic reports for both technical and executive audiences.
- Demonstrated strong documentation discipline, capable of maintaining strict chain-of-custody and producing repeatable, defensible investigation results.
- Ability to work effectively in a fast-paced environment, with flexibility for non-standard work hours during active incident response operations.
- Strong aptitude for continuous learning, particularly regarding emerging attacker tradecraft and new forensic methodologies.
Similar jobs
- Lead Firmware Quality Assurance EngineerCopeland · Pune, IndiaFirst seen today
- Lead QA Engineer (AI native)Jobgether · IndiaFirst seen todayremote
- Platform Engineer( On-Premises)Datamatics Technologies · Richmond Town, Bangalore, Karnataka, IndiaFirst seen today
- Software Engineer 3eBay · Bangalore, Karnataka, IndiaFirst seen today
- Devops Engineer - AzureEpam Systems · Hyderabad, Telangana, IndiaFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job