Cyber Defense Forensics Analysts - Mid

ECS

Washington (District of Columbia)

On-site

USD 102,600 - 117,500

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading cybersecurity firm in Washington, DC, is seeking a mid-level Cyber Defense Forensics Analyst to enhance their security team for a long-term contract. The role involves threat detection, forensics analysis, and supporting governmental cybersecurity initiatives. Candidates should have a Bachelor’s degree and 5+ years in cyber forensics, with strong communication skills and an understanding of security tools. Active Secret clearance is required.

Qualifications

  • 5+ years of experience in cyber threat hunting and forensics support.
  • Ability to apply threat hunting using the MITRE ATT&CK framework.
  • Active Secret clearance or higher.

Responsibilities

  • Identify threat tactics using frameworks like MITRE ATT&CK.
  • Perform hypothesis-based cyber threat hunts.
  • Investigate and analyze intrusion artifacts.

Skills

Communication skills
Threat detection automation
Forensics analysis
TCP/IP networking knowledge
Operating system security
Malware forensics

Education

Bachelor’s degree or higher

Tools

EnCase
Sleuthkit
FTK

Job description

Join to apply for the Cyber Defense Forensics Analysts - Mid role at ECS.

1 day ago Be among the first 25 applicants

Join to apply for the Cyber Defense Forensics Analysts - Mid role at ECS.

Job Description

ECS is seeking a Cyber Defense Forensics Analysts - Mid to work in our Washington, DC office.

Position Summary

ECS Federal is a leading information security and information technology company in Washington, DC. We are looking to hire a mid-level Cyber Defense Forensics Analyst to support a full range of cyber security services on a long-term contract in Washington DC. The position is full time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background clearance.

Security Clearance Requirement
  • Active Secret clearance
Job Requirements
  • Strong written and verbal communication skills.
  • Create detections and automation to detect, contain, eradicate, and recover from security threats.
  • Develop new and novel defense techniques to identify and stop advanced adversary tactics and techniques.
  • Perform forensics on network, host, memory, and other artifacts originating from multiple operating systems, applications, or networks and extract IOCs (Indicators of Compromise) and TTPs (Tactics, Techniques, and Procedures).
  • Conduct proactive hunts through enterprise networks, endpoints, or datasets to detect malicious, suspicious, or risky activities.
  • Solid knowledge of TCP/IP networking, and network services such as DNS, SMTP, DHCP, etc.
  • Understanding of attacker tradecraft related to email, app-based, cloud threats, and defensive tactics.
  • Good knowledge of operating system internals, OS security mitigations, and security challenges in Windows, Linux, Mac, Android & iOS platforms.
  • Experience with forensic tools (e.g., EnCase, Sleuthkit, FTK).
  • Ability to analyze malicious code (malware forensics).
  • Skill in analyzing code as malicious or benign.
  • Knowledge of system and application security threats and vulnerabilities.
  • Apply threat hunting and the MITRE ATT&CK framework to identify and develop detection capabilities.
Certifications/Licenses
  • Bachelor’s degree or higher.
  • 5+ years’ experience in cyber threat hunting and forensics support for incident response.
  • Active Secret clearance or higher.
Salary Range:

$102,600 - $117,500

Responsibilities
  • Identify threat tactics and methodologies using frameworks like MITRE ATT&CK.
  • Perform hypothesis-based or intelligence-based cyber threat hunts.
  • Use cloud-native techniques for threat detection and response.
  • Research intelligence reports for actionable data.
  • Analyze large datasets to uncover attack techniques.
  • Investigate and analyze intrusion artifacts.
  • Create forensic images and maintain chain of custody.
  • Report findings and ensure evidence integrity.
  • Extract data using forensic techniques.
Desired Skills
  • Exposure to Python, PowerShell, or bash.
  • Proficiency with SIEM query languages (Splunk, Sentinel).
  • Experience producing threat intelligence reports.
  • Ability to analyze memory dumps and media forensics.

ECS is an equal opportunity employer and does not discriminate on any protected characteristic.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Incident Analyst
Senior Cyber Incident Analyst

ECS • Arlington (VA)

On-site
USD 170,000 - 180,000
Security Analyst - Forensics/Malware Analysis
Security Analyst - Forensics/Malware Analysis

Peraton • Chandler (AZ)

On-site
USD 110,000 - 160,000
Cyber Defense Forensics Lead
Cyber Defense Forensics Lead

Tyto Athene, LLC • Ashburn (VA)

On-site
USD 120,000 - 150,000
Sr. Cyber Defense Analyst
Sr. Cyber Defense Analyst

Patriot Talent Solutions • United States

On-site
USD 120,000 - 190,000
Host Based Systems Analyst IV
Host Based Systems Analyst IV

Solutions³ LLC • Virginia (MN)

On-site
USD 110,000 - 170,000
Cyber Hunt Analyst
Cyber Hunt Analyst

Synergy ECP • Columbia (MD)

On-site
USD 90,000 - 130,000
Host Forensics Analyst
Host Forensics Analyst

NewGen Technologies • Arlington (VA)

Hybrid
USD 120,000 - 180,000
Mid-Level Digital Forensics and Incident Response Analyst
Mid-Level Digital Forensics and Incident Response Analyst

Jobtailor • Huntsville (AL)

On-site
USD 90,000 - 130,000
Senior Associate, Information Security - Forensics
Senior Associate, Information Security - Forensics

Publicis Groupe Holdings B.V • United States

Remote
USD 100,000 - 120,000
Cyber Defense Forensics Analyst (Mid) - Washington, DC
Cyber Defense Forensics Analyst (Mid) - Washington, DC

ECS • Washington

On-site
USD 102,000 - 118,000