> Markdown version of [/jobs/ext/158680-digital-forensics-and-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/158680-digital-forensics-and-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Digital Forensics and Incident Response Analyst - **Company:** Cybervance Inc. - **Location:** Portland, OR, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple IOS, Unix, CompTIA Security+, Cyber Security, Computer Engineering, Linux, Digital Forensics, Hard Disk Drives, Memory Card, Computer Networking Systems, Storage Devices, Malware, Information Technology, Cybercrime, Encase - **Published:** May 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e48f7fa82af71c61 ## About the Role Do you have experience in Technical report writing?, Do you have a Bachelor's degree?, * Bachelor's degree in Cybersecurity, Computer Science, IT, Computer Engineering, or other related field. * Five to ten (10) years of combined cybersecurity experience with three to seven years in digital forensics, incident response, threat hunting, malware analysis, and/or security operations. * Experience leading incident investigations, coordinating enterprise-wide response efforts, and presentation of findings., * Demonstrable performance track record including potential work samples, process development, proposal library management, and win rates versus bids. * Strong analytical thinking, high attention to detail, executive communication, report writing and documentation, and ability to work under pressure. * Desired certifications: Certified Ethical Hacker (CEH), CompTIA Security+, CompTIA CySA+. ## Description Position Title: Digital Forensics and Incident Response Analyst Location: Portland, OR | Full-Time, * Collect, examine, and perform thorough technical analyses of computer-related evidence/information such as media storage devices (floppy disks, hard disks, magnetic tapes, disks, memory cards, magnetic strip cards, etc.). * Use various forensic tools such as Encase, Axiom, Cellebrite, or FTK to search for and prepare information and evidence. * Perform searches and analysis of digital devices and computers with various operating systems such as Windows, iOS, Linux and UNIX. * Support investigative findings through documented, evidence-based analysis and maintain strict protection and integrity of all evidentiary materials. * Prepare accurate, clear and comprehensive reports of findings which can be understood by both technical and non-technical personnel. * Review operating practices and procedures to determine whether improvements can be made in areas such as workflow, reporting procedures, and/or expenditures. Communicate results of discussion, artifacts, and recommendations. Provide advice and guidance in implementing IT security policies and procedures in the development and operation of network systems. * * Interact with Federal agencies on forensics techniques to develop, implement, and coordinate forensics activities to protect systems and to monitor compliance. * Manage multiple threat analysis sources and their integration and use in the enterprise incident response teams. * Perform vulnerability research methodologies and sources. * Maintain and support all forensically related equipment and software. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)