Cloud Forensic Analyst IV with Security Clearance

Nightwing

Arlington (VA)

On-site

USD 122,000 - 253,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, Vision, Dental Insurance
401k Plan
PTO & Holidays

Job summary

Nightwing is seeking a highly experienced cyber forensics professional to support on-site engagements. You will collect artifacts, triage devices, and correlate findings to network events to build intrusion narratives.

Required qualifications include U.S. citizenship, TS/SCI clearance, and 10+ years in cyber investigations. Strong cloud experience and proficiency with forensics tools are essential.

Qualifications

  • U.S. Citizenship is required.
  • Active TS/SCI clearance.
  • 10+ years of direct relevant cyber forensics experience.
  • Deep understanding of SaaS, PaaS and IaaS in cloud environments.
  • Ability to produce forensically sound duplicates of evidence and write cyber investigative reports.

Responsibilities

  • Acquire/collect computer artifacts (malware, user activity, link files) for onsite engagements.
  • Triage devices and assess evidentiary value.
  • Correlate forensic findings to network events to develop intrusion narratives.
  • Document system state information prior to imaging.
  • Perform forensic triage to determine scope, urgency and impact.
  • Track and document forensic analysis from start to finish.
  • Coordinate with Government staff and customer personnel on findings.
  • Analyze forensic images and draft write-ups for reports.

Skills

Cyber Forensics
Incident Response
Evidence Handling
Windows/Linux
Cloud Experience

Education

GCFA/GCFE/GCIH
CISSP
AWS Practitioner
Azure Fundamentals

Tools

Forensic Tools
Cloud Platforms

Job description

Nightwing provides technically advanced full-spectrum cyber, data operations, systems integration and intelligence mission support services to meet our customers' most demanding challenges. Our capabilities include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data intelligence, lifecycle mission enablement, and software modernization. Nightwing brings disruptive technologies, agility, and competitive offerings to customers in the intelligence community, defense, civil, and commercial markets.

Nightwing provides technically advanced full-spectrum cyber, data operations, systems integration and intelligence mission support services to meet our customers' most demanding challenges. Our capabilities include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data intelligence, lifecycle mission enablement, and software modernization. Nightwing brings disruptive technologies, agility, and competitive offerings to customers in the intelligence community, defense, civil, and commercial markets.

Nightwing provides technically advanced full-spectrum cyber, data operations, systems integration and intelligence mission support services to meet our customers' most demanding challenges. Our capabilities include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data intelligence, lifecycle mission enablement, and software modernization. Nightwing brings disruptive technologies, agility, and competitive offerings to customers in the intelligence community, defense, civil, and commercial markets.

The Desired Skills/CERTs/Education are not required and will be used to develop training plans for candidates/team members that demonstrate a cyber aptitude, desire to learn and strong work ethic.

Responsibilities
  • Acquire/collect computer artifacts (e.g., malware, user activity, link files) in support of onsite engagements
  • Triage electronic devices and assess evidentiary value
  • Correlate forensic findings to network events in support of developing an intrusion narrative
  • Collect and document system state information (e.g. running processes, network connections) prior to imaging, as required
  • Perform forensic triage of an incident to include determining scope, urgency and potential impact
  • Track and document forensic analysis from initial participation through resolution
  • Collect, process, preserve, analyze and present computer related evidence
  • Coordinate with Government staff and customer personnel to validate/investigate alerts or additional preliminary findings
  • Conduct analysis of forensic images, and available evidence in support of forensic write-ups for inclusion in reports and written products
  • Assist with documenting and publishing Computer Network Defense (CND) guidance and reports pertaining to incident findings
Required Skills/Clearances
  • U.S. Citizenship
  • Active TS/SCI clearance
  • Ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability
  • 10 years of direct relevant experience in cyber forensic investigations using leading edge technologies and industry standard forensic tools
  • In depth understanding of SaaS, PaaS and IaaS in the Cloud Environment
  • Ability to create forensically sound duplicates of evidence (forensic images)
  • Ability to author cyber investigative reports documenting digital forensics findings
  • Proficiency with analysis and characterization of cyber attacks
  • Proficiency with proper evidence handing procedures and chain of custody protocols
  • Skilled in identifying different classes of attacks and attack stages
  • Understanding of system and application security threats and vulnerabilities
  • Understanding of proactive analysis of systems and networks, to include creating trust levels of critical resources- Able to work collaboratively across physical locations
  • Action-oriented and have a proactive approach to problem solving
  • Proficiency with common operating systems (e,g, Linux/Unix, Windows)
Desired Skills
  • Ability to provide knowledge of strategies/architectures involved in implementing M365/Azure authentication, how these hook to a federated identity solution and a fundamental understanding of how threat actors would target identity to compromise an environment
  • Advanced experience and proficiency across various aspects of IT operations (e.g. networking, virtualization, identity, security, business continuity, disaster recovery, data management, governance)
  • Experience and understanding in acquisition, processing and analysis of digital evidence from onsite enterprises and cloud native platforms
  • Fundamental understanding of APIs and proficiency with PowerShell/PowerShell modules leveraged to conduct API queries as they relate to Azure/M365
  • Proficiency with scripting languages (e.g. Bash, Python, Powershell, JS) for automation of hunt tools used in commercial cloud environments- Ability to develop tools, architecture and configurations in Azure environment to support identifying threat activity.
  • Understanding of Azure administration, M365 administration and/or development/DevOps, with advanced level skills in at least one of these domains
  • Understand of how Azure/M365 platform protection is implemented and security operations available
Desired Certifications/Education

- One or more of the following certifications:

GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, AWS Practitioner, AWS Certified Developer, AWS Certified SysOps Administrator, AWS Certified Architect, Kubernetes Security SpecialistMS-500: Microsoft 365 Security AdministrationAZ-900: Azure FundamentalsAZ-500: Azure Security TechnologiesAZ-303: Azure Architect TechnologiesAZ-304: Azure Architect DesignMS-100: Microsoft 365 Identity and ServicesMS-101: Microsoft 365 Mobility and SecurityAZ-104: Azure Administrator SANS SEC 510, Public Cloud Security: AWS, Azure, and GCPSANS FOR509: Enterprise Cloud Forensics and Incident Response (BETA)SEC 541: Cloud Monitoring and Threat DetectionSEC584: Cloud Native Security: Defending Containers and KubernetesSEC588: Cloud Penetration testing AWS Certified Cloud Practitioner AWS Certified SysOps Administrator Associate or AWS Certified Developer Associate or AWS Certified Solutions Architect Associate AWS Certified Solutions Architect Professional or AWS Certified DevOps Engineer Professional

Salary & Benefits

The salary associated with this position ($122,000-$253,000) is commensurate with the selected candidate's qualifications, years of relevant experience, and demonstrated level of expertise. Compensation will be determined based on these factors to ensure alignment with skills, responsibilities, and market standards.

Nightwing offers medical, vision and dental insurance coverage in addition to a 401k plan, PTO, Holidays, and additional insurances.

Nightwing is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Forensic Analyst IV
Cloud Forensic Analyst IV

Nightwing • Arlington (VA)

On-site
USD 90,000 - 120,000
Competitive compensation
Professional development opportunities
Cloud Forensic Analyst IV
Cloud Forensic Analyst IV

Nightwing Intelligence Solutions, LLC • Sterling (VA)

On-site
USD 122,000 - 253,000
Medical insurance and vision
Dental insurance
401k plan
+2
Cyber Host Forensic Analyst II with Security Clearance
Cyber Host Forensic Analyst II with Security Clearance

Nightwing • Arlington (VA)

On-site
USD 77,000 - 163,000
Medical Insurance
401k Plan
PTO / Holidays
Cloud Forensic Analyst IV
Cloud Forensic Analyst IV

Nightwing Group • Arlington (VA), Northern (KY)

On-site
USD 140,000 - 190,000
Cyber Host Forensic Analyst II
Cyber Host Forensic Analyst II

Nightwing • Arlington (VA)

On-site
USD 80,000 - 120,000
Collaborative work environment
Opportunities for professional growth
Cloud Forensic Analyst III
Cloud Forensic Analyst III

Nightwing • Arlington (VA)

On-site
USD 90,000 - 120,000
Collaborative work environment
Opportunity for career growth
Employee Referral Award eligibility
Cyber Threat Hunter II: Incident Response & Forensics
Cyber Threat Hunter II: Incident Response & Forensics

Nightwing • Sterling (VA)

On-site
USD 99,000 - 206,000
Medical insurance
Vision insurance
Dental insurance
+3
Cyber Network Defense Analyst III
Cyber Network Defense Analyst III

Nightwing • Sterling (VA)

On-site
USD 100,000 - 130,000
Equal Opportunity Employer
Collaboration and teamwork environment
Cyber Host Forensic Analyst II
Cyber Host Forensic Analyst II

Nightwing Intelligence Solutions, LLC • Sterling (VA)

On-site
USD 77,000 - 163,000
Medical, Vision & Dental Insurance
401(k)
PTO & Holidays
Cyber Network Defense Analyst II
Cyber Network Defense Analyst II

Nightwing • Sterling (VA)

On-site
USD 99,000 - 206,000
Medical insurance
Vision insurance
Dental insurance
+3