Senior Incident Response Forensic Investigator

Posted:
1/18/2026, 3:32:03 PM

Location(s):
Sofia, Sofia-City, Bulgaria ⋅ Sofia-City, Bulgaria

Experience Level(s):
Senior

Field(s):
Software Engineering

Workplace Type:
On-site

Job Description:

About DXC Bulgaria  

We are DXC – a Fortune 500 global IT services leader.

In Bulgaria, we are among the largest IT employers, delivering the full spectrum of the company’s diverse technical portfolio. Our teams work across cutting-edge technologies, contributing to projects that span industries and geographies.

We foster continuous learning and professional growth, offering access to targeted training and certifications aligned with individual interests and career aspirations.

Our culture of collaboration, innovation, and shared values empowers professionals to grow and succeed.

The Senior Incident Response Forensic Investigator is responsible for delivering operational cybersecurity services to DXC accounts on time, on target, and with quality. This role focuses on delivery of incident response services by providing cybersecurity forensic investigation in emergency situations, along with detection, containment, and emergency remediation advice, across supported accounts.

Daily challenge

  • Act as a senior responder for high-severity security incidents, coordinating with the Security Incident Response Control Centre.

  • Perform rapid identification, containment, and remediation of threats across enterprise environments.

  • Collect, preserve, and analyze digital evidence from endpoints, servers, cloud platforms, and network devices in compliance with legal and regulatory standards.

  • Conduct root cause analysis and produce detailed forensic reports for internal and external stakeholders.

  • Design and maintain custom forensic tools (e.g., triage scripts, memory acquisition utilities) to enhance investigation efficiency.

  • Automate repetitive tasks using programming languages such as Python, PowerShell, or C++ to improve response times and accuracy.

  • Perform malware reverse engineering and memory analysis to uncover sophisticated attack techniques.

eXperience and skills required

  • University Degree/Diploma in Computer Science, Computer Engineering, Electrical Engineering, Management Information Systems or equivalent certifications (CHFI, CISSP, CEH, CompTIA Security +, GCIH, GREM, GCFA).

  • 3+years of experience within Security Services or infrastructure services support (Systems NT, UX, Storage, Backups, DB’s or Network management), operations monitoring and end user support.

  • Minimum of 2+ years’ hands-on technical knowledge of analyzing event logs/system logs, from Windows Operating Systems, Unix/Linux Operating Systems, Cisco PIX/Switches/Routers, Wireshark/Ethereal network dumps.

  • Excellent knowledge of IT Operations, infrastructure services support (Systems NT, UX, Storage, Backups, DB’s or Network management), security incident and security processes

  • Excellent understanding of ITSM/ITIL processes

  • 3+ years of production experience building RESTful APIs with Node.js/Express/Socket.io, experience with TypeScript: type safety, generics, advanced types and PostgreSQL, Sequelize ORM, Git/Docker.

Company benefits

At DXC Technology, we don’t just offer jobs - we build careers. Here’s what you can look forward to when you join us:

  • Enjoy competitive compensation and grow your career in a fast-paced, international environment.

  • Benefit from 24 days of paid vacation to rest, explore, and recharge - plus comprehensive medical and life insurance, and monthly food vouchers to support your lifestyle.

  • Access premium learning platforms, get company-sponsored certifications, and grow your skills with continuous development opportunities tailored to you.

  • Get recognized through our Employee Recognition Program - your contributions deserve the spotlight.

  • Refer great talent through our Employee Referral Program and get rewarded for helping shape our future.

  • Enjoy discounts and special offers with your employee badge - it pays to be part of the team.

  • Access 24/7 support for you and your family, with a wide range of wellbeing resources to help you thrive.

  • Join meaningful initiatives that give back to the community and connect you with like-minded colleagues through fun and impactful experiences.


At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive.

If you feel comfortable with the above-mentioned requirements, please send us your CV in English.

Please note only shortlisted candidates will be contacted.

DXC Technology stands for equal opportunities, namely, we do not discriminate on the basis of race, religion, color, sex, age, disability, or sexual orientation.  All recruitment decisions are based solely on qualifications, skills, knowledge and experience, and relevant business requirements.

At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive.

Recruitment fraud is a scheme in which fictitious job opportunities are offered to job seekers typically through online services, such as false websites, or through unsolicited emails claiming to be from the company. These emails may request recipients to provide personal information or to make payments as part of their illegitimate recruiting process. DXC does not make offers of employment via social media networks and DXC never asks for any money or payments from applicants at any point in the recruitment process, nor ask a job seeker to purchase IT or other equipment on our behalf. More information on employment scams is available here.

iOSCM

Website: https://ioscm.com/

Headquarter Location: Newcastle Upon Tyne, Newcastle upon Tyne, United Kingdom

Year Founded: 2012

Industries: E-Learning ⋅ Education ⋅ Logistics ⋅ Procurement ⋅ Supply Chain Management ⋅ Warehousing