Lead Digital Investigations Engineer

MITRE Corporation
Orlando, FL, United States
about 1 month ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$158,800.0 - $198,500.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services Apple Mac Systems Microsoft Azure Cloud Computing Cyber Security Linux Digital Forensics Log Analysis Network Forensics Security Information and Event Management Google Cloud
+7 more
Cloud Platform System Malware Cyber Threat Analysis Cybercrime Cyber Warfare Network Server Vulnerability Analysis

Job description

MITRE’s Digital Investigations Department (L515) delivers innovative technical solutions and capabilities primarily focused on support to law enforcement and investigative cyber operations conducted by sponsors, most notably within DOJ, DHS, and DoW. The department’s core technology areas are:

  • Digital Investigations and Cases
  • Digital/Media/Mobile Device Access and Forensics
  • Digital Artifact Discovery
  • Digital Evidence Processing
  • Cryptocurrency Analysis and Seizure
  • Cyber Attribution
  • Darkweb Research
  • Financial Cybercrime Analysis
  • Social Media Exploitation

Roles & Responsibilities:

  • Conduct digital investigations related to cybersecurity incidents, insider threat concerns, policy violations, and suspicious activity.
  • Collect, preserve, analyze, and document digital evidence from endpoints, servers, mobile devices, cloud environments, logs, and network sources.
  • Support cybersecurity operations by triaging alerts, correlating threat activity, and assisting with incident response and containment efforts.
  • Perform forensic analysis using industry-standard tools and methodologies to determine attack vectors, timeline of events, impacted systems, and scope of compromise.
  • Maintain chain of custody and proper evidence handling procedures in support of internal investigations and potential legal or regulatory matters.
  • Analyze system, application, security, and network logs to identify indicators of compromise and anomalous behavior.
  • Collaborate with Security Operations Center, Threat Intelligence, IT, HR, Legal, and Compliance teams during investigations.
  • Prepare clear, concise, and defensible investigative reports, briefings, and technical documentation for both technical and non-technical audiences.
  • Assist in developing and improving digital investigation procedures, playbooks, and evidence collection standards.
  • Recommend remediation and mitigation actions based on investigative findings.
  • Stay current on emerging cyber threats, attacker tactics, forensic techniques, and relevant technologies.

Requirements

  • Typically requires a minimum of 8 years of related experience with a Bachelor’s degree; or 6 years and a Master’s degree; or a PhD with 3 years’ experience; or equivalent combination of related education and work experience
  • Experience supporting investigations involving endpoints, operating systems, user activity, malware, or network-based threats.
  • Familiarity with common forensic and investigative tools, SIEM platforms, endpoint detection and response tools, and log analysis solutions.
  • Knowledge of incident response processes, digital evidence handling, and forensic best practices.
  • Understanding of Windows, Linux, and/or macOS operating systems and associated artifacts relevant to investigations.
  • Strong analytical, problem-solving, and documentation skills.
  • Ability to communicate investigative findings clearly to technical and non-technical stakeholders.
  • This position requires a minimum of 50% hybrid on-site, * Experience in a Security Operations Center, Computer Security Incident Response Team, or digital forensics function.
  • Familiarity with cloud investigation techniques in environments such as Azure, AWS, or Google Cloud.
  • Experience with eDiscovery, insider threat investigations, or fraud-related digital analysis.
  • Exposure to malware analysis, threat hunting, or network forensics.
  • Relevant certifications such as Security+, CySA+, GCFA, GCIH, GCFE, EnCE, CHFI, or similar.
  • Knowledge of regulatory, compliance, and privacy considerations related to investigations.

This requisition requires the candidate to have a minimum of the following clearance(s)

Benefits & conditions

Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That’s because MITRE people are committed to tackling our nation’s toughest challenges-and we’re committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts to influence what we do. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We’re making a difference every day-working for a safer, healthier, and more secure nation and world. Our workplace reflects our values. We offer competitive benefits, exceptional professional development opportunities for career growth, and a culture of innovation that embraces adaptability, collaboration, technical excellence, and people in partnership. If this sounds like the choice you want to make, then choose MITRE - and make a difference with us.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard Ā· World Congress 2025

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 Ā· LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa Ā· LIVE

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker Ā· LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani Ā· Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all