> Markdown version of [/jobs/ext/3455680-digital-forensics-analyst](https://www.wearedevelopers.com/jobs/ext/3455680-digital-forensics-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Digital Forensics Analyst - **Company:** ADRISAN, LLC - **Location:** Alexandria, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Amazon S3, Apple Mac Systems, Audit Trail, Microsoft Azure, Cloud Computing, Cloud Engineering, Computer Networks, Linux, Digital Forensics, File Systems, Hard Disk Drives, Identity and Access Management, Imaging Technology, Pcap, Network Forensics, Packet Analyzer, NT File System (NTFS), Program Analysis, Reverse Engineering, Security Information and Event Management, Virtual Machines, Virtualization Technology, Scripting, Office365, Malware, Encase - **Published:** September 1, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9134364/digital-forensics-analyst ## About the Role * Experience: 5+ years of hands-on experience conducting or supporting digital forensics and incident investigations across multi-OS environments (Windows, Linux, macOS). * Technical Mastery: o Digital Media & Mobile: Deep knowledge of forensic imaging techniques, file system internals (NTFS, APFS, EXT4), and mobile device acquisitions. o Cloud & Virtualization: Practical experience auditing M365, Azure, AWS (CloudTrail, IAM, S3 logs), and hypervisor/VM environments. o Enterprise Data Sources: Hands-on experience analyzing EDR telemetry, SIEM logs, network traffic, and raw packet captures. o Malware Analysis: Experience executing basic to intermediate malware triage and artifact analysis. Preferred Certifications: * SANS GIAC: GCFA, GCFE, GREM, GCIH, GISF, GXPN, GCTI, or GOSI. * EnCase: EnCE, CFSR, or ENCEP. Job Location: Hybrid to Alexandria, VA. Clearance: Public Trust or higher. ## Description * Digital Evidence Acquisition & Analysis: Perform forensically sound acquisitions and in-depth analysis of hard drives, volatile memory, mobile devices, and virtual machines across Windows, Linux, and macOS platforms. * Cloud & Hybrid Investigations: Analyze cloud telemetry, including M365 logs, Azure audit logs, AWS CloudTrail, and IAM activity, to reconstruct cloud-native compromises and unauthorized access. * Malware Analysis & Triage: Conduct static and dynamic analysis of suspicious files, scripts, and binaries to determine functionality, reverse-engineer behavior, and extract indicators of compromise (IOCs). * Enterprise Log & Network Forensics: Correlate disparate data sources-including EDR telemetry, SIEM alerts, and full packet captures (PCAP)-to map adversary movement, timeline events, and establish root causes. * Reporting & Evidence Chain of Custody: Author detailed technical forensic reports, maintain strict chain-of-custody protocols, and present findings to incident response leads, legal counsel, and leadership. * Tooling & Capability Enhancements: Develop automated forensic collection workflows, custom scripts, and maintain evidence collection toolkits to continuously improve investigative capabilities.