Cyber Forensic Examiner – Intermediate

Sentinel Group

Chantilly, Northern (VA, KY)

Hybrid

USD 100,000 - 150,000

Full time

1 hour ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Sentinel Group is seeking an Intermediate Cyber Forensic Examiner in Chantilly, VA. The role involves conducting comprehensive digital forensic examinations, preserving chain-of-custody, and reporting findings to stakeholders.

Candidates should have 3+ years of relevant experience or a related degree, proficiency with major forensic tools, and must hold a Top Secret clearance. Responsibilities include imaging, timeline analysis, mobile forensics, and collaboration with incident-response teams

Qualifications

  • 3+ years of relevant experience in digital forensics or a related field.
  • Experience with one or more forensic tools such as Cellebrite, FTK, EnCase, Magnet AXIOM, or Paladin.
  • Knowledge of acquisition, evidence preservation, file-system and artifact analysis.
  • Experience across endpoints, servers, mobile devices, networks, cloud, or virtualized systems.
  • Strong analytical, investigative, technical writing and documentation skills.
  • Top Secret security clearance is required; counterintelligence polygraph desired.

Responsibilities

  • Independently conduct forensic examinations of workstations, servers, mobile devices, storage media, virtual machines, cloud environments, and other digital systems.
  • Identify and acquire relevant digital evidence while preserving forensic integrity and maintaining chain-of-custody documentation.
  • Perform forensic imaging and acquisition from physical, logical, virtual, mobile, and cloud-based sources.
  • Conduct forensic timeline analysis and correlate evidence across multiple systems and data sources.
  • Perform mobile-device forensic examinations, including analysis of application data and location information.
  • Analyze network and security data to identify evidence of unauthorized access, persistence, or data exfiltration.
  • Recover and analyze deleted or obfuscated data where feasible.
  • Utilize forensic suites and specialized tools to acquire, parse, search, and analyze digital evidence.
  • Develop and document forensic examination procedures and methodologies.
  • Identify artifacts and develop investigative hypotheses based on available evidence.
  • Produce comprehensive forensic examination reports detailing methodology and conclusions.
  • Brief technical and government stakeholders regarding forensic findings and conclusions.
  • Support incident-response investigations and collaborate with cybersecurity and IT teams.
  • Review junior examiner work and provide technical guidance.

Skills

Digital forensics
Cyber operations
Incident response
Technical writing
Documentation

Education

Bachelor's degree in a related discipline

Tools

Cellebrite
FTK
EnCase
Magnet AXIOM
Paladin

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Cyber Forensic Examiner – Intermediate

Full Time Chantilly, VA, US

Minimum Qualifications:


The Intermediate Cyber Forensic Examiner independently conducts digital forensic examinations and provides technical analysis of digital evidence across enterprise computing environments. The examiner applies established forensic methodologies to identify, preserve, acquire, examine, and analyze evidence and develops technically defensible findings and reports.

Responsibilities:

  • Independently conduct forensic examinations of workstations, servers, mobile devices, storage media, virtual machines, cloud environments, and other digital systems.
  • Identify and acquire relevant digital evidence while preserving forensic integrity and maintaining complete chain-of-custody documentation.
  • Perform forensic imaging and acquisition from physical, logical, virtual, mobile, and cloud-based sources.
  • Conduct forensic timeline analysis and correlate evidence across multiple systems and data sources.
  • Perform mobile-device forensic examinations, including analysis of application data, communications, location information, media, and device activity.
  • Analyze network and security data to identify evidence of unauthorized access, persistence, lateral movement, data staging, exfiltration, or other malicious activity.
  • Perform recovery and analysis of deleted, fragmented, concealed, encrypted, or otherwise obfuscated data where technically feasible.
  • Utilize forensic suites and specialized tools to acquire, parse, search, correlate, and analyze digital evidence.
  • Develop and document forensic examination procedures and analytical methodologies.
  • Identify relevant artifacts and develop investigative hypotheses based on available evidence.
  • Produce comprehensive forensic examination reports documenting methodology, evidence examined, findings, analytical reasoning, and conclusions.
  • Brief technical and government stakeholders regarding forensic findings and investigative conclusions.
  • Support incident-response investigations and collaborate with cybersecurity, network, system, and threat-analysis personnel.
  • Review junior examiner work products and provide technical guidance and mentoring.
  • Maintain knowledge of emerging operating systems, applications, devices, forensic artifacts, and anti-forensic techniques.

Required Qualifications:

  • 3+ years of relevant experience OR a relevant bachelor's degree with demonstrated/proven practical experience in digital forensics, cyber operations, cyber defense, incident response, computer science, cybersecurity, or a related discipline.
  • Demonstrated experience with one or more relevant forensic tools, such as Cellebrite, FTK, EnCase, Magnet AXIOM, Paladin, or comparable forensic platforms.
  • Demonstrated knowledge of forensic acquisition, evidence preservation, file-system analysis, artifact analysis, timeline analysis, and digital evidence handling.
  • Experience conducting forensic examinations across one or more enterprise technology domains, including endpoints, servers, mobile devices, networks, cloud environments, or virtualized systems.
  • Strong analytical, investigative, technical writing, and documentation skills.
  • Must hold Top Secret security clearance. Counterintelligence polygraph desired.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Forensic Examiner – Intermediate
Cyber Forensic Examiner – Intermediate

SENTINEL GROUP LLC • Chantilly (VA)

On-site
USD 90,000 - 120,000
Cyber Forensic Examiner – Entry Level
Cyber Forensic Examiner – Entry Level

SENTINEL GROUP LLC • Chantilly (VA)

On-site
USD 45,000 - 60,000
Cyber Forensic Examiner – Entry Level
Cyber Forensic Examiner – Entry Level

Sentinel Group • Chantilly (VA), Northern (KY)

Hybrid
USD 55,000 - 75,000
Cyber Forensic Examiner – Entry Level
Cyber Forensic Examiner – Entry Level

ADP, Inc. • Chantilly (VA)

On-site
USD 60,000 - 90,000
Digital Forensics Examiner
Digital Forensics Examiner

Peraton • Linthicum (MD)

On-site
USD 90,000 - 130,000
Cyber Forensic Examiner – Intermediate, Investigative
Cyber Forensic Examiner – Intermediate, Investigative

SENTINEL GROUP LLC • Chantilly (VA)

On-site
USD 90,000 - 120,000
Jr Digital Forensic Examiner
Jr Digital Forensic Examiner

Aone Consulting, LLC • Lorton (VA)

On-site
USD 70,000 - 95,000
Jr Digital Forensic Examiner
Jr Digital Forensic Examiner

Aone Talent • Lorton (VA)

On-site
USD 60,000 - 80,000
Digital Forensic Examiner
Digital Forensic Examiner

The HT Group • Austin (TX)

On-site
USD 90,000 - 120,000
Digital Forensic Examiner
Digital Forensic Examiner

Infotrend, Inc. • Lorton (VA), Northern (KY)

Hybrid
USD 70,000 - 80,000
Health insurance
401(k) match
Paid time off
+1