> Markdown version of [/jobs/ext/492890-cybersecurity-forensics-and-malware-lead](https://www.wearedevelopers.com/jobs/ext/492890-cybersecurity-forensics-and-malware-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Forensics and Malware Lead - **Company:** Gunnison Consulting Group Inc - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $145,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, Cloud Computing, Cyber Security, Data Recovery, Linux, Digital Forensics, File Systems, Phishing, Security Information and Event Management, Forensic Toolkit, Malware, Information Technology, Encase - **Published:** June 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ac75d48a50a18d11 ## About the Role Do you have experience in Legal evidence?, Do you have a Bachelor's degree?, * Bachelor's degree in Computer Science, Information Technology, or related discipline * Minimum of 5 years of incident response experience in a large SOC, including at least 3 years focused on digital forensics * At least 3 years of experience conducting disk, memory, and registry analysis using industry-standard forensic tools such as EnCase, FTK, X-Ways, and Volatility * Strong understanding of file systems and operating system artifacts (e.g., SRUM, Prefetch, Shellbags) * Familiarity with federal evidence handling requirements and chain-of-custody procedures * Certification required: GCFA, GREM, CFCE, or OSED Clearance Requirement: Ability to obtain and maintain a Public Trust. The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements. ## Description * Lead digital forensic and malware analysis operations in support of cybersecurity activities for the federal customer * Provide subject matter expertise for forensic investigations across Windows, Linux, macOS, cloud, and enterprise environments * Perform both static and dynamic malware analysis to identify indicators of compromise, adversary techniques, and root causes * Analyze forensic artifacts, memory images, endpoint data, and SIEM telemetry to detect malicious activity * Coordinate with incident response and triage teams to support investigation, containment, and recovery efforts * Conduct live forensic investigations using enterprise security tools and approved forensic platforms * Collect, preserve, and manage digital evidence in accordance with forensic standards and procedures * Produce detailed forensic and malware analysis reports documenting findings and investigative results * Support real-time investigations involving high-severity security incidents * Analyze advanced threats including ransomware, phishing campaigns, and sophisticated malware * Perform memory analysis and data recovery using approved forensic methodologies * Correlate data from endpoint, network, identity, and cloud sources to support investigations * Communicate findings to leadership and cybersecurity teams, ensuring timely escalation as needed * Review forensic deliverables for accuracy, completeness, and compliance with SLAs * Develop and maintain forensic SOPs, playbooks, and investigative procedures * Support reporting and awareness efforts by contributing forensic insights and threat trends * Participate in technical briefings and operational meetings * Drive improvements in forensic and investigative processes * Support onboarding, training, and knowledge transfer activities ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How Much FAANG Companies Actually Pay Software Engineers in 2025](https://www.wearedevelopers.com/magazine/230-how-much-faang-companies-actually-pay-software-engineers-in-2025)