Digital Forensics Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+16 more
Job description
- Digital Evidence Acquisition & Analysis: Perform forensically sound acquisitions and in-depth analysis of hard drives, volatile memory, mobile devices, and virtual machines across Windows, Linux, and macOS platforms.
- Cloud & Hybrid Investigations: Analyze cloud telemetry, including M365 logs, Azure audit logs, AWS CloudTrail, and IAM activity, to reconstruct cloud-native compromises and unauthorized access.
- Malware Analysis & Triage: Conduct static and dynamic analysis of suspicious files, scripts, and binaries to determine functionality, reverse-engineer behavior, and extract indicators of compromise (IOCs).
- Enterprise Log & Network Forensics: Correlate disparate data sources-including EDR telemetry, SIEM alerts, and full packet captures (PCAP)-to map adversary movement, timeline events, and establish root causes.
- Reporting & Evidence Chain of Custody: Author detailed technical forensic reports, maintain strict chain-of-custody protocols, and present findings to incident response leads, legal counsel, and leadership.
- Tooling & Capability Enhancements: Develop automated forensic collection workflows, custom scripts, and maintain evidence collection toolkits to continuously improve investigative capabilities.
Requirements
- Experience: 5+ years of hands-on experience conducting or supporting digital forensics and incident investigations across multi-OS environments (Windows, Linux, macOS).
-
Technical Mastery: o Digital Media & Mobile: Deep knowledge of forensic imaging techniques, file system internals (NTFS, APFS, EXT4), and mobile device acquisitions. o Cloud & Virtualization: Practical experience auditing M365, Azure, AWS (CloudTrail, IAM, S3 logs), and hypervisor/VM environments. o Enterprise Data Sources: Hands-on experience analyzing EDR telemetry, SIEM logs, network traffic, and raw packet captures. o Malware Analysis: Experience executing basic to intermediate malware triage and artifact analysis. Preferred Certifications:
- SANS GIAC: GCFA, GCFE, GREM, GCIH, GISF, GXPN, GCTI, or GOSI.
- EnCase: EnCE, CFSR, or ENCEP.
Job Location: Hybrid to Alexandria, VA.
Clearance: Public Trust or higher.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this roleβ¦