Digital Forensic / Incident Response - Lead
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+10 more
Job description
We are seeking an experienced Incident Response & Digital Forensics Lead to manage the day-to-day operations of a cybersecurity response team while remaining actively involved in technical investigations.
This is a hands-on leadership role supporting a federal customer. The successful candidate will lead incident response and digital forensic activities, coordinate directly with customer stakeholders, and translate complex findings into clear briefings and recommendations for senior federal leadership.
The role also provides technical support across cloud security, endpoint security, identity and access management, secure networking, and incident response. The ideal candidate has strong incident handling and forensic investigation experience, combined with the organizational and stakeholder-management skills of a mid-level project or program manager. This position requires some on-site work., * Manage the team’s daily operations, priorities, workload, assignments, and deliverables.
- Lead and participate directly in cyber incident investigations, forensic examinations, analysis, containment, eradication, and recovery activities.
- Coordinate incident response functions across technical teams, business stakeholders, vendors, and customer leadership.
- Serve as a primary point of contact for the customer during active incidents and related investigative activities.
- Prepare and deliver incident briefings, executive summaries, technical findings, status reports, and recommended courses of action to senior federal leadership.
- Collect, preserve, document, and analyze intrusion artifacts, including malware, malicious code, scripts, executables, logs, system images, and network evidence.
- Use investigative findings and threat intelligence to support containment, mitigation, remediation, and prevention of cyber defense incidents across the enterprise.
- Provide expert technical guidance to enterprise cyber defense analysts, engineers, administrators, and technicians working to resolve security incidents.
- Conduct or oversee forensic acquisition and analysis of endpoints, servers, mobile devices, cloud environments, and other relevant digital evidence.
- Maintain evidentiary integrity, chain-of-custody records, investigation notes, timelines, and other case documentation.
- Monitor relevant external information sources, including cybersecurity vendors, government advisories, Computer Emergency Response Teams, information-sharing organizations, and threat-intelligence providers.
- Assess emerging vulnerabilities, threats, tactics, techniques, and procedures for potential impact on the customer environment.
- Develop and improve incident response plans, playbooks, escalation procedures, forensic processes, reporting templates, and operational metrics.
- Coordinate lessons-learned reviews and ensure corrective actions are documented, assigned, and tracked through completion.
- Support technical cybersecurity activities involving cloud platforms, endpoint protection, identity and access management, network security, logging, and monitoring.
- Mentor team members and promote consistent investigative, technical, and documentation standards.
- Support incident response exercises, tabletop exercises, readiness assessments, and after-action reviews.
Requirements
- Demonstrated professional experience in cybersecurity incident response, incident handling, and digital forensic investigations.
- Experience leading or coordinating a cybersecurity operations, incident response, or forensic investigation team.
- Ability and willingness to perform hands-on technical work while managing team operations and customer deliverables.
- Experience collecting, preserving, analyzing, and documenting digital evidence and intrusion artifacts.
- Working knowledge of Windows and Linux operating systems, enterprise networks, endpoint technologies, cloud environments, authentication systems, and security logging.
- Familiarity with common attacker tactics, techniques, and procedures, including the phases of an intrusion and methods used to establish persistence, evade detection, and exfiltrate data.
- Ability to assess technical evidence, determine incident scope and impact, and recommend appropriate containment and remediation measures.
- Strong written and verbal communication skills, including the ability to explain complex technical findings to executives and nontechnical stakeholders.
- Experience preparing formal incident reports, executive briefings, investigation summaries, and corrective-action recommendations.
- Strong organizational, project-management, and stakeholder-coordination skills.
- Ability to manage competing priorities and operate calmly and effectively during high-severity incidents.
- Ability to work on-site at the designated customer location.
- Ability to satisfy applicable federal customer suitability, background investigation, and clearance requirements., * GIAC Certified Forensic Examiner (GCFE)
- GIAC Certified Incident Handler (GCIH)
- CompTIA Cybersecurity Analyst (CySA+)
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Network Forensic Analyst (GNFA)
- Certified Information Systems Security Professional (CISSP)
- Hands-on experience with forensic and investigative tools such as Magnet AXIOM, Magnet Graykey, OpenText EnCase, and Cellebrite.
- Experience performing mobile-device acquisition and forensic analysis.
- Experience supporting federal agencies or other regulated, high-security environments.
- Familiarity with NIST incident response guidance and the MITRE ATT&CK framework.
- Experience with endpoint detection and response, security information and event management, cloud-security, network-analysis, malware-analysis, or threat-intelligence platforms.
- Experience managing projects, schedules, risks, customer communications, and multidisciplinary technical teams.
- Knowledge of legal, regulatory, privacy, and evidentiary considerations associated with forensic investigations., * Bachelor’s degree in cybersecurity, computer science, information technology, digital forensics, engineering, or a related field; equivalent relevant experience may be considered.
- 5+ years of cybersecurity experience, including substantial experience in incident response or digital forensics.
- Prior technical leadership, team-lead, project-management, or program-coordination experience.
Success in This Role
The successful candidate will be a credible technical investigator, a steady incident leader, and an effective customer-facing communicator. This individual must be comfortable moving between detailed forensic analysis, team coordination, and executive-level reporting-often during time-sensitive and high-impact events., * Bachelor’s (Required), * Incident response: 5 years (Required)
Benefits & conditions
Professional development assistance, Parental leave, 401(k), Health insurance, 401(k) matching, Paid time off, Vision insurance, Dental insurance Full-time On call Hybrid work in Germantown, MD 20875, * 401(k)
- 401(k) matching
- Dental insurance
- Flexible schedule
- Health insurance
- Paid time off
- Parental leave
- Professional development assistance
- Vision insurance
About the company
Antietam Technologies LLC is a Service Disabled Veteran Owned Small Business dedicated to providing top-tier Cyber Security and Information Assurance services. We are committed to safeguarding digital assets and empowering organizations through innovative security solutions.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
System change: restart as developer?
Finding IT & Technology English-speaking Jobs in GermanyÂ
The Most Popular IT Jobs on the Market
IT Salaries in Germany