Cyber Forensics Analyst

Everforth Ecs
Portland, OR, United States
15 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Microsoft Windows Cyber Security Computer Forensics Data Centers Linux Digital Forensics File Systems Forensics Tools (Digital Forensics Software) Windows Servers Open Source Technology Reverse Engineering
+3 more
Wireshark Forensic Toolkit Malware

Job description

The Forensics Analyst Mid performs hands-on forensic analysis and malware investigation activities in support of SOC security investigations, incident response, routine memory checks, and advanced threat hunting. This role uses industry-standard forensic tools and strong investigative skills to collect, analyze, and document technical evidence., Digital Forensics and Investigation

  • Perform forensic analysis using industry-standard forensic tools and open-source DFIR utilities.

  • Assist with forensic investigations involving endpoints, servers, malware, and cyber incidents.

  • Analyze Windows Registry, Windows System Calls, Linux artifacts, file system data, logs, and memory artifacts.

  • Create findings and technical notes that support investigative conclusions and remediation actions.

Malware Analysis and IOC Development

  • Analyze malware in a lab environment using standard malware analysis techniques.

  • Create IOCs based on forensic and malware findings for sharing with SOC and security teams.

  • Support Java code de-obfuscation and technical analysis activities within the analyst skill level.

  • Escalate complex malware or reverse-engineering requirements to senior analysts or the FMAT Lead.

SOC and Incident Response Support

  • Assist the SOC with security investigations and incident response activities.

  • Conduct routine memory checks on Linux and Windows servers as directed.

  • Support proactive malware analysis, incident response, and advanced threat hunting activities.

  • Communicate with different teams and data centers during investigations.

Reporting and Collaboration

  • Create clear investigation reports, forensic summaries, and supporting documentation.

  • Communicate findings effectively to SOC analysts, incident responders, data center teams, and leadership.

  • Apply strong investigative, research, and problem-solving skills to ambiguous technical issues.

  • Contribute to repeatable forensic procedures, knowledge sharing, and continuous process improvement.

Requirements

The ideal candidate has solid cybersecurity experience, strong written communication skills, and the ability to operate resourcefully and independently while coordinating with SOC teams, data centers, and senior forensic personnel during investigations., * U.S. Citizenship with ability to obtain and maintain a DOE “L” clearance after start.

  • 5 to 8 years of experience in cybersecurity, digital forensics, incident response, or related cyber investigation work.

  • Experience performing forensic analysis using industry-standard forensic tools and open-source tools.

  • Familiarity with Windows Registry, Windows System Calls, Linux operating systems, and Java code de-obfuscation.

  • Hands-on experience with Volatility or other memory forensics tools, FTK, and Wireshark.

  • Ability to create IOCs based on forensic analysis and share them with other security teams.

  • Ability to analyze malware in a lab environment using standard malware analysis techniques.

  • Experience performing or supporting forensic investigations and incident response activities.

  • Excellent written communication, resourcefulness, investigative ability, research skills, and problem-solving skills.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:19 min

Setting up a vulnerable test application and monitoring environment

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC 2024

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:48 min

Analyzing network packets with database protocol tools

Daniël van Eeden Daniël van Eeden · WWC Europe 2026

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all