Digital Forensic / Incident Response - Lead

Antietam Technologies Inc.
Germantown, MD, United States
26 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$180,000.0
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Security Software Documentation Cyber Security Computer Forensics Linux Digital Forensics Identity and Access Management Information Systems Security Architecture Professional Network Security Network Forensics Security Information and Event Management Data Logging
+10 more
Computer Networking Systems Cloud Platform System Mitre Att&ck Malware Cyber Threat Analysis Information Technology OpenText Encase Cyber Warfare Network Server

Job description

We are seeking an experienced Incident Response & Digital Forensics Lead to manage the day-to-day operations of a cybersecurity response team while remaining actively involved in technical investigations.

This is a hands-on leadership role supporting a federal customer. The successful candidate will lead incident response and digital forensic activities, coordinate directly with customer stakeholders, and translate complex findings into clear briefings and recommendations for senior federal leadership.

The role also provides technical support across cloud security, endpoint security, identity and access management, secure networking, and incident response. The ideal candidate has strong incident handling and forensic investigation experience, combined with the organizational and stakeholder-management skills of a mid-level project or program manager. This position requires some on-site work., * Manage the team’s daily operations, priorities, workload, assignments, and deliverables.

  • Lead and participate directly in cyber incident investigations, forensic examinations, analysis, containment, eradication, and recovery activities.
  • Coordinate incident response functions across technical teams, business stakeholders, vendors, and customer leadership.
  • Serve as a primary point of contact for the customer during active incidents and related investigative activities.
  • Prepare and deliver incident briefings, executive summaries, technical findings, status reports, and recommended courses of action to senior federal leadership.
  • Collect, preserve, document, and analyze intrusion artifacts, including malware, malicious code, scripts, executables, logs, system images, and network evidence.
  • Use investigative findings and threat intelligence to support containment, mitigation, remediation, and prevention of cyber defense incidents across the enterprise.
  • Provide expert technical guidance to enterprise cyber defense analysts, engineers, administrators, and technicians working to resolve security incidents.
  • Conduct or oversee forensic acquisition and analysis of endpoints, servers, mobile devices, cloud environments, and other relevant digital evidence.
  • Maintain evidentiary integrity, chain-of-custody records, investigation notes, timelines, and other case documentation.
  • Monitor relevant external information sources, including cybersecurity vendors, government advisories, Computer Emergency Response Teams, information-sharing organizations, and threat-intelligence providers.
  • Assess emerging vulnerabilities, threats, tactics, techniques, and procedures for potential impact on the customer environment.
  • Develop and improve incident response plans, playbooks, escalation procedures, forensic processes, reporting templates, and operational metrics.
  • Coordinate lessons-learned reviews and ensure corrective actions are documented, assigned, and tracked through completion.
  • Support technical cybersecurity activities involving cloud platforms, endpoint protection, identity and access management, network security, logging, and monitoring.
  • Mentor team members and promote consistent investigative, technical, and documentation standards.
  • Support incident response exercises, tabletop exercises, readiness assessments, and after-action reviews.

Requirements

  • Demonstrated professional experience in cybersecurity incident response, incident handling, and digital forensic investigations.
  • Experience leading or coordinating a cybersecurity operations, incident response, or forensic investigation team.
  • Ability and willingness to perform hands-on technical work while managing team operations and customer deliverables.
  • Experience collecting, preserving, analyzing, and documenting digital evidence and intrusion artifacts.
  • Working knowledge of Windows and Linux operating systems, enterprise networks, endpoint technologies, cloud environments, authentication systems, and security logging.
  • Familiarity with common attacker tactics, techniques, and procedures, including the phases of an intrusion and methods used to establish persistence, evade detection, and exfiltrate data.
  • Ability to assess technical evidence, determine incident scope and impact, and recommend appropriate containment and remediation measures.
  • Strong written and verbal communication skills, including the ability to explain complex technical findings to executives and nontechnical stakeholders.
  • Experience preparing formal incident reports, executive briefings, investigation summaries, and corrective-action recommendations.
  • Strong organizational, project-management, and stakeholder-coordination skills.
  • Ability to manage competing priorities and operate calmly and effectively during high-severity incidents.
  • Ability to work on-site at the designated customer location.
  • Ability to satisfy applicable federal customer suitability, background investigation, and clearance requirements., * GIAC Certified Forensic Examiner (GCFE)
  • GIAC Certified Incident Handler (GCIH)
  • CompTIA Cybersecurity Analyst (CySA+)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Network Forensic Analyst (GNFA)
  • Certified Information Systems Security Professional (CISSP)
  • Hands-on experience with forensic and investigative tools such as Magnet AXIOM, Magnet Graykey, OpenText EnCase, and Cellebrite.
  • Experience performing mobile-device acquisition and forensic analysis.
  • Experience supporting federal agencies or other regulated, high-security environments.
  • Familiarity with NIST incident response guidance and the MITRE ATT&CK framework.
  • Experience with endpoint detection and response, security information and event management, cloud-security, network-analysis, malware-analysis, or threat-intelligence platforms.
  • Experience managing projects, schedules, risks, customer communications, and multidisciplinary technical teams.
  • Knowledge of legal, regulatory, privacy, and evidentiary considerations associated with forensic investigations., * Bachelor’s degree in cybersecurity, computer science, information technology, digital forensics, engineering, or a related field; equivalent relevant experience may be considered.
  • 5+ years of cybersecurity experience, including substantial experience in incident response or digital forensics.
  • Prior technical leadership, team-lead, project-management, or program-coordination experience.

Success in This Role

The successful candidate will be a credible technical investigator, a steady incident leader, and an effective customer-facing communicator. This individual must be comfortable moving between detailed forensic analysis, team coordination, and executive-level reporting-often during time-sensitive and high-impact events., * Bachelor’s (Required), * Incident response: 5 years (Required)

Benefits & conditions

Professional development assistance, Parental leave, 401(k), Health insurance, 401(k) matching, Paid time off, Vision insurance, Dental insurance Full-time On call Hybrid work in Germantown, MD 20875, * 401(k)

  • 401(k) matching
  • Dental insurance
  • Flexible schedule
  • Health insurance
  • Paid time off
  • Parental leave
  • Professional development assistance
  • Vision insurance

About the company

Antietam Technologies LLC is a Service Disabled Veteran Owned Small Business dedicated to providing top-tier Cyber Security and Information Assurance services. We are committed to safeguarding digital assets and empowering organizations through innovative security solutions.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker · LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

Videos

See all

Related articles

See all