Senior Cyber Forensic Analyst

ShorePoint, Inc
Albuquerque, NM, United States
10 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Computer Forensics Data Security Digital Forensics Information Security Management Security Information and Event Management Cyber Threat Analysis Cybercrime Plan of Action and Milestones Vulnerability Analysis

Job description

We are seeking an experienced Senior Cyber Forensic Analyst to lead advanced digital forensics analysis and incident response support across complex enterprise environments. This role will support threat hunting, incident triage, forensic analysis, continuous monitoring, vulnerability analysis, defensive exercises and cyber performance metrics while producing defensible findings that inform containment, eradication, recovery, risk decisions and corrective actions. The ideal Sr. Cyber Forensic Analyst candidate will bring deep experience collecting, preserving, analyzing and reporting digital evidence, reconstructing cyber events and translating technical findings into timely, actionable information for government stakeholders, incident response personnel, Information System Security Officers (ISSOs) and Federal technical leads. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market. Employment for this position is dependent on the successful award of the contract. for a potential opportunity

What you’ll be doing:

  • Lead and perform advanced digital forensic examinations involving endpoint, server, network, cloud, application, removable-media and log-data sources in support of suspected or confirmed cybersecurity incidents.
  • Collect, preserve, validate, analyze and document digital evidence using sound forensic practices while maintaining evidentiary integrity, chain-of-custody records and reproducible analysis methods.
  • Reconstruct incident timelines and identify initial access, attacker activity, persistence, lateral movement, data access or exfiltration indicators, affected assets and potential mission or system impacts.
  • Lead forensic support for complex incident response activities, including scoping, triage, containment recommendations, eradication and recovery validation, post-incident reporting and lessons learned.
  • Conduct proactive threat-hunting activities using endpoint, network, identity and security-event data and develop and refine hypotheses based on threat intelligence, observed behaviors and environmental risk.
  • Analyze security alerts, logs, malware artifacts, suspicious files, authentication events and network activity to identify indicators of compromise, tactics, techniques and procedures and detection or monitoring gaps.
  • Produce clear technical reports, executive-ready summaries, evidence packages, incident timelines, hunt reports and recommended corrective actions for cybersecurity leadership, government stakeholders, ISSOs, Federal Information Systems Security Engineers (ISSEs) and other authorized personnel.
  • Coordinate with ISSOs to ensure relevant incident, forensic, vulnerability and monitoring findings are reflected in risk assessments, security documentation, continuous-monitoring artifacts, authorization evidence and Plans of Action and Milestones (POA&M) records.
  • Support vulnerability assessment and defensive-exercise activities by analyzing results, validating operational impact, identifying detection and response gaps and documenting corrective-action recommendations.
  • Contribute to continuous-monitoring, incident, hunting, detection-effectiveness and capability-gap metrics, identify recurring trends and recommend process or detection improvements.
  • Develop and maintain forensic playbooks, standard operating procedures, evidence-handling processes and analytical work instructions consistent with customer, program and legal requirements.
  • Mentor cyber analysts and contribute to an integrated, repeatable and measurable cyber-defense operating model.

What you need to know:

  • Digital forensic investigations and incident response within complex federal, national-security or other highly regulated environments.
  • Host-, network- and log-based forensic analysis, attack-timeline reconstruction, evidence preservation, chain of custody, forensic imaging and collection, artifact analysis, log correlation, malware triage and incident documentation practices.
  • Security information and event management (SIEM), endpoint detection and response (EDR), network-security monitoring, forensic-analysis tools and threat-intelligence sources.
  • Incident-response lifecycle practices, threat hunting, vulnerability analysis, continuous monitoring and control-effectiveness validation.
  • Cybersecurity risk management, federal security controls, continuous monitoring and the relationship between operational findings and authorization or POA&M activities.
  • Development of concise, defensible reports, evidence packages and corrective-action recommendations under time-sensitive conditions, including communicating findings to technical and nontechnical stakeholders and coordinating with government stakeholders, ISSOs, security operations personnel and Federal technical authorities.

Requirements

  • Bachelor’s degree from an accredited university; a postgraduate degree from an accredited university may substitute for 6 years of experience.
  • 10+ years of relevant work experience.
  • Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
  • Applicants must currently be a U.S. citizen and eligible to obtain and maintain a security clearance, in compliance with federal contract requirements.

Beneficial to have:

  • Active DOE Q or equivalent DoD Top Secret clearance.

Benefits & conditions

As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individual’s technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, major carriers for healthcare providers. Highlighted benefits include 144 hours of PTO, 11 holidays, 85% of insurance premiums covered, a 401(k), continuing education, certification maintenance and reimbursement and more.

About the company

ShorePoint is a fast-growing, industry-recognized and award-winning cybersecurity services firm focused on high-profile, high-threat public and private sector customers who demand experience and proven security models to protect their data. We embrace a “work hard, play hard” mentality and celebrate individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers, while fostering an environment that supports creativity, accountability, mission success, critical thinking and a desire to give back to our community.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all