> Markdown version of [/jobs/ext/2704570-security-spec-lead-digital-forensics-analyst](https://www.wearedevelopers.com/jobs/ext/2704570-security-spec-lead-digital-forensics-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Spec Lead - Digital Forensics Analyst - **Company:** American Electric Power - **Location:** Austin, TX, United States - **Experience:** Expert - **Salary:** $116,255.0 - $151,133.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Android Software Development, Apple IOS, Apple Mac Systems, Cyber Security, Data Control, Information Leak Prevention, Data Security, Linux, Digital Assets, Digital Forensics, Forensics Tools (Digital Forensics Software), Supervisory Control and Data Acquisition (SCADA), Networking Hardware, Intrusion Detection and Prevention, Reverse Engineering, Security Information and Event Management, EndPointSecurity, Data Classification, Information Technology, Cybercrime, Tools for Reporting, Splunk, Programming Languages - **Published:** September 4, 2026 - **Apply:** https://www.austinjobsite.com/job.asp?id=3377314033&tx=KL5757FFI&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Ability to obtain and maintain a U.S. government security clearance * In-depth understanding of Windows, Linux/Unix, MacOS, Android and iOS operating systems and interconnected network devices * Understanding of mobile device forensics and evidence collection techniques * Experience with malware reverse engineering and analysis * Understanding of anomalous user activity monitoring and policy violation investigations * Ability to use internal and external log sources, forensic tools, and established investigative methods to determine incident source and scope * Work independently while maintaining strict confidentiality throughout investigations which sometimes involve high pressure situations or rapidly changing priorities * Communicate clearly, verbally and in writing, with strong analytical and critical-thinking skills * Handle sensitive and confidential material appropriately * Understanding of forensic capture and analysis methodologies and evidence chain of custody procedures, * Bachelor's degree or equivalent experience in cybersecurity, digital forensics, computer science, or related field * Experience with standard forensic methods and leading collection and analysis tools * Deep experience conducting technical investigations or root cause analysis in complex environments * Experience identifying insider risk indicators through analytics tools * Understanding and experience with digital forensics in a cloud environment * Understanding of threat actor tactics, techniques, and procedures * Familiarity with electric utility operations, ICS/SCADA, or critical infrastructure protection frameworks such as NERC CIP * Working knowledge of programming languages and Splunk query development * Ability to apply AI to threat detection and analysis * Understanding and experience with security monitoring tools, SIEM platforms, and endpoint detection solutions * Ability to work and lead in cross-functional environments involving HR, Legal, Compliance, Privacy, and Security teams * Knowledge of cyber investigations and incident response processes * Experience with case management and evidence handling procedures * Experience with data classification, information protection, data loss prevention (DLP), and sensitive data monitoring technologies Preferred Certifications and Courses * SANS Forensics Certifications (Ex. GASF, GCFA, GCFE, GREM, GNFA) * Computer Hacking Forensic Investigator (CHFI) * GIAC Certified Incident Handler (GCIH) * Vendor specific certification for industry leading forensics tools, * Bachelor's degree OR Associates degree with 2 years relevant experience in system administration/help desk/security (cyber or physical) OR High School Diploma/GED with 4 years relevant experience in IT system administration/help desk/security (cyber or physical)., * 7 or more years of Information Technology related experience; OR 5 or more years of security related experience, which may include military/government work experience in addition to any experience identified above. ## Description The Digital Forensic Analyst investigates and examines digital assets. The position is aligned with AEP's Cybersecurity Intelligence & Defense organization and Insider Threat team. It is a highly technical role and supports digital investigations utilizing endpoint images, security analytics, and user activity monitoring across a broad range of cybersecurity and IT tools. The analyst also supports programs and policies that reduce internal risk. The analyst partners with Cyber Incident Responders, HR, Legal, Ethics, Physical Security, and other stakeholders to support data acquisition and analysis. The analyst will document findings, manage cases from initiation to resolution, and communicate technical conclusions in clear business language., * Conduct end-to-end investigations of internal and external matters. * Prepare findings reports for HR, Legal, Ethics, Physical Security, and other stakeholders * Develop and maintain Digital Forensics policies and procedures documentation * Support risk-reduction projects, including post-incident lessons learned * Serve as a technical SME for Insider Threat, DLP, and cyber investigations * Produce clear investigative and analytic reports for technical and executive audiences * Maintain tools and technologies pertaining to Digital Forensics collection and analysis, The Physical Demand Level for this job is: S - Sedentary Work: Exerting up to 10 pounds of force occasionally (Occasionally: activity or condition exists up to 1/3 of the time) and/or a negligible amount of force frequently. (Frequently: activity or condition exists from 1/3 to 2/3 of the time) to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time but may involve walking or standing for brief periods of time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Xcode development redefAIned](https://www.wearedevelopers.com/videos/100195-xcode-development-redefained) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Harnessing Apple Intelligence: Live Coding with Swift for iOS](https://www.wearedevelopers.com/videos/1515-harnessing-apple-intelligence-live-coding-with-swift-for-ios) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers)