> Markdown version of [/jobs/ext/182313-forensics-incident-response-sme](https://www.wearedevelopers.com/jobs/ext/182313-forensics-incident-response-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Forensics / Incident Response SME - **Company:** Valiant Solutions, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $130,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Android Software Development, Macintosh Computers, Apple IOS, Software as a Service, Cyber Security, Linux, Digital Forensics, File Systems, Infrastructure as a Service (IaaS), Mainframes, Windows Mobile, Network Forensics, Platform as a Service (PAAS), Reverse Engineering, Security Information and Event Management, Cloud Platform System, Malware, Cyber Threat Analysis, Malware Detection, Encase - **Published:** May 14, 2026 - **Apply:** https://www.dice.com/job-detail/da2acdd3-ced8-484b-a067-8bc83754d610 ## About the Role Do you have experience in IT security and a strong background in Incident Response and Forensics? If so, you may be interested in this dual-focused position that requires active participation in all Incident Response activities, complemented by deep, specialized expertise in Forensic Analysis. This is your opportunity to join a busy Security Engineering team delivering cutting-edge solutions to a fantastic Government client. Specialized experience in incident response, managing APTs, forensic analysis, and handling evidentiary data is key for this challenging and rewarding role. This role will be responsible for all incident response and management activities, forensic analysis, and other emerging enterprise-wide IT challenges. We are seeking a motivated individual to join this team, which is constantly evolving and currently developing cloud security solutions in AWS. You'll be passionate about what you do and will be able to work autonomously to engineer your way out of problems. The IR/Forensics SME shall be responsible for all incident response and management activities, forensic analysis, and other emerging enterprise-wide IT challenges., * 8+ years of specialized experience in incident response, management of the APT, forensic analysis, and handling of evidentiary data, with the most recent experience in the past 4 years. * Experience performing IR, Forensics, and post-mortem reports in cloud environments (AWS preferred). * Experience with Mobile Device Forensics * Ability to identify malware characteristics and conduct reverse engineering in x86 and x64 assembly * Ability to demonstrate and conduct Windows memory forensics techniques to analyze malware threats. * Strong knowledge of malware code and behavioral analysis. * Working knowledge in SIFT, REMnux, or other similar frameworks. * Experience in Presentation and Reporting of Evidence and Analysis * Experience in File System Timeline Analysis * Experience in Live Incident Response and Volatile Evidence Collection * Experience in Advanced Windows Registry Analysis * Experience in Forensic Imaging and Filesystem Media Analysis * Experience performing Advanced Network Event and Protocol analysis and timeline reconstruction * Experience and ability to develop, use, and follow Standard Operating Procedures (SOPs) * In-depth experience with processing and triage of Security Alerts from multiple sources, but not limited to Endpoint security tools, SIEM, email security solutions, CISA, Threat Intel Sources * Demonstrated ability to evaluate events (through a triage process) and identify appropriate prioritization for response * Expert understanding of security incident response processes * Support and participate in Threat Hunt and Threat Intel operations, * GIAC Certified Forensics Examiner (GCFE) * Certified Forensic Analyst (GCFA) * Certified Computer Examiner (CCE) * AccessData Certified Examiner (ACE) EnCase Certified Examiner (EnCE) * Magent Certified Forensic Examiner (MCFE) * Magent Certified GRAYKEY Examiner (MCGE) * AWS Solution Architect (AWS) * SANS GIAC Certified Incident Handler (GCIH) * SANS GIAC Certified Intrusion Analyst (GCIA) * SANS GIAC Network Forensics Analyst (GNFA) * SANS GIAC Certified Enterprise Defender (GCED) * SANS GIAC Reverse Engineering Malware (GREM) * Carnegie Mellon Certified Computer Incident Handler (CSIH) * IACIS Certified Forensic Computer Examiner (CFCE) * ISFCE Certified Computer Examiner (CCE) ## Description * Participate in a rotating on-call; rotation is based on the number of team members * Serve as a hybrid Incident Response Serve (IR) and Digital Forensics (DFIR) function, requiring both real-time incident handling and deep forensic investigative expertise across enterprise and cloud environments. * Provide Incident Management and Forensic Support as required for incidents/investigations, including off-hours * Provide Incident Management support, including guidance and expertise to the Incident Response Team and SOC components * Development of policies, instructions, standards, and procedures around security functions * Develops, maintains, and optimizes the malware and forensic analysis laboratory environment * Maintains digital evidence Chain of Custody for forensic activity in accordance with policy, industry standards, and law * Perform forensic analysis on a variety of networks, hosts, digital media, and operating systems/environments as but not limited to: Windows, Mac, iOS, Android, Windows Mobile, Linux/Unix, Mainframe, and cloud computing platforms (SaaS, PaaS, IaaS) * Prepare detailed written technical reports covering the methodology applied to forensic investigation, findings, and recommendations for further action * Provide SME technical analysis for Incident Response and Forensics for Incident / Breach / and Compromise Activities. Including but not limited to malware detection, lateral movement, data collection, and exfiltration detection * Provide a complete response to all DFIR tasks * Produce and review aggregated performance metrics * Work directly with Security and SOC leadership to convert intelligence and results from forensic analysis into useful detection in enterprise security tools * Collaborate with the incident response team to rapidly build detection rules as needed * Perform customer security assessments * Supporting incident response or remediation as needed * Participate and develop, and run tabletop exercises * Perform lessons learned activities * Supporting ad-hoc data and investigation requests * Support the enrichment and enhancement of security monitoring tools, including but not limited to evaluation and recommendations on rule tuning and development of new rules/detections ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)