> Markdown version of [/jobs/ext/491693-mid-level-forensics-analyst](https://www.wearedevelopers.com/jobs/ext/491693-mid-level-forensics-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Mid-Level Forensics Analyst - **Company:** Cybervance Inc. - **Location:** Portland, OR, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Bash Shell, Software as a Service, Cloud Computing, Data Loss, Linux, Digital Forensics, File Systems, Python (Programming Language), Windows PowerShell, Scripting, Malware - **Published:** June 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d40b6e98e0278b3e ## About the Role Do you have experience in Windows?, The ideal candidate has practical forensic experience, strong attention to evidentiary detail, and the ability to independently analyze systems while escalating complex findings appropriately., * 3-5 years of experience in digital forensics, incident response, or cybersecurity analysis. * Hands-on experience performing forensic acquisitions and analysis. * Solid understanding of: * + Windows and Linux operating systems + File systems, logs, and system artifacts + Common attacker behaviors and malware indicators * Strong documentation and written communication skills. * Ability to follow evidence handling and legal defensibility requirements., * Experience with memory forensics, log correlation, or malware triage. * Familiarity with cloud, SaaS, or email forensics (e.g., M365, cloud platforms). * Scripting or automation experience (Python, PowerShell, Bash). * Certifications such as GCFA, GCIH, CHFI, EnCE, or equivalent. * Experience in regulated, enterprise, or government environments. ## Description We are seeking a full-time Mid-Level Digital Forensics Analyst who supports and conducts digital forensic investigations related to cybersecurity incidents, insider threats, data loss, and policy or regulatory inquiries. This role performs hands-on forensic analysis under established methodologies while working closely with senior forensics staff, incident response teams, and legal or compliance stakeholders., * Conduct forensic analysis on endpoints, servers, and removable media. * Acquire, preserve, and analyze digital evidence in accordance with forensic best practices. * Perform disk, memory, and artifact analysis to identify user activity, malware, or unauthorized access. * Support investigations involving security incidents, insider activity, and data exfiltration. * Assist incident response teams with forensic scoping, timeline creation, and root cause analysis. * Analyze forensic artifacts to determine attack vectors, persistence mechanisms, and impact. * Identify indicators of compromise (IOCs) and support remediation efforts. * Maintain proper evidence handling and chain-of-custody documentation. * Produce clear forensic notes, findings, and supporting artifacts. * Contribute to forensic and incident reports used by technical, legal, or leadership teams. * Utilize forensic tools for data acquisition, analysis, and reporting. * Perform artifact validation and cross-verification to ensure analytical accuracy. * Support improvements to forensic workflows and repeatable procedures. * Work closely with senior forensic analysts and incident responders. * Participate in tabletop exercises, incident reviews, and training activities. * Continue skill development in forensic techniques, tools, and emerging technologies. Required Skills & Qualifications ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [How to Avoid LLM Pitfalls - Mete Atamel and Guillaume Laforge](https://www.wearedevelopers.com/videos/1328-how-to-avoid-llm-pitfalls-mete-atamel-and-guillaume-laforge) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)