Digital Forensics Analyst

ADRISAN, LLC
Alexandria, VA, United States
about 1 month ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Amazon Web Services Amazon S3 Apple Mac Systems Audit Trail Microsoft Azure Cloud Computing Cloud Engineering Computer Networks Linux Digital Forensics File Systems
+16 more
Hard Disk Drives Identity and Access Management Imaging Technology Pcap Network Forensics Packet Analyzer NT File System (NTFS) Program Analysis Reverse Engineering Security Information and Event Management Virtual Machines Virtualization Technology Scripting Office365 Malware Encase

Job description

  • Digital Evidence Acquisition & Analysis: Perform forensically sound acquisitions and in-depth analysis of hard drives, volatile memory, mobile devices, and virtual machines across Windows, Linux, and macOS platforms.
  • Cloud & Hybrid Investigations: Analyze cloud telemetry, including M365 logs, Azure audit logs, AWS CloudTrail, and IAM activity, to reconstruct cloud-native compromises and unauthorized access.
  • Malware Analysis & Triage: Conduct static and dynamic analysis of suspicious files, scripts, and binaries to determine functionality, reverse-engineer behavior, and extract indicators of compromise (IOCs).
  • Enterprise Log & Network Forensics: Correlate disparate data sources-including EDR telemetry, SIEM alerts, and full packet captures (PCAP)-to map adversary movement, timeline events, and establish root causes.
  • Reporting & Evidence Chain of Custody: Author detailed technical forensic reports, maintain strict chain-of-custody protocols, and present findings to incident response leads, legal counsel, and leadership.
  • Tooling & Capability Enhancements: Develop automated forensic collection workflows, custom scripts, and maintain evidence collection toolkits to continuously improve investigative capabilities.

Requirements

  • Experience: 5+ years of hands-on experience conducting or supporting digital forensics and incident investigations across multi-OS environments (Windows, Linux, macOS).
  • Technical Mastery: o Digital Media & Mobile: Deep knowledge of forensic imaging techniques, file system internals (NTFS, APFS, EXT4), and mobile device acquisitions. o Cloud & Virtualization: Practical experience auditing M365, Azure, AWS (CloudTrail, IAM, S3 logs), and hypervisor/VM environments. o Enterprise Data Sources: Hands-on experience analyzing EDR telemetry, SIEM logs, network traffic, and raw packet captures. o Malware Analysis: Experience executing basic to intermediate malware triage and artifact analysis. Preferred Certifications:

  • SANS GIAC: GCFA, GCFE, GREM, GCIH, GISF, GXPN, GCTI, or GOSI.
  • EnCase: EnCE, CFSR, or ENCEP.

Job Location: Hybrid to Alexandria, VA.

Clearance: Public Trust or higher.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Loading talks and stories from around this role…