Cyber Investigations Analyst - Mid

asmexternalcareersite

Ashburn (VA)

On-site

USD 120,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

ASM Research seeks a seasoned security professional to support internal investigations, cyber forensics, and SIEM operations across Windows, Linux, Mac, and cloud environments. You will preserve evidence, ensure chain-of-custody, and drive incident response while coordinating with leadership on security posture and SOP updates.

The role spans security engineering, ISSE-adjacent tool support, and formal forensic analysis, including DLP monitoring and egress case management across classification

Qualifications

  • Bachelor’s degree in Computer Science, Engineering, or related technical field or equivalent experience.
  • Minimum 5 years in system administration, database administration, network engineering, software engineering, or software development with cyber security focus; or with a relevant degree.
  • Minimum 3 years in digital media forensic analysis, static/dynamic malware analysis.
  • US Citizenship / No Dual Citizenship.

Responsibilities

  • Advise and assist with maintenance and engineering of the internal investigations forensic network infrastructure across its lifecycle; manage priorities via the internal ticketing/Change Request process.
  • Collaborate, administer, configure, tune, and secure the unit's tool suite/devices/sensors; review network security architecture and provide leadership recommendations.
  • Maintain SIEM infrastructure/OS supporting IDS, firewall, proxy, DLP, antivirus, and vulnerability data.
  • Support near real-time DLP monitoring; recommend incident-response per NIST 800-88.
  • Design/deploy custom digital forensic builds; conduct endpoint and network forensic analysis across Windows/Linux/Mac/cloud.
  • Support formal digital forensic investigations; document findings; handle email hygiene and egress cases in case management system.
  • Serve as SME on evidence preservation/chain-of-custody and advanced forensic extraction techniques.
  • Create and elevate cases to law-enforcement; manage lifecycle of cyber investigations; author/update SOPs.

Skills

System administration
Cyber security
Digital forensics
SIEM
Evidence preservation
Chain of custody
DLP monitoring
Incident response
Malware analysis
Email forensics

Education

Bachelor's degree in CS/Engineering or related field

Job description

Supports systems engineering, administration, cyber security/compliance, and digital forensics support for the organization's internal investigations function, securing the IT networks used to detect and investigate cybercrimes and internal policy violations. The role spans three areas: security engineering support for the internal investigations forensic network infrastructure; ISSO-adjacent support for the unit's tool suite, SIEM, and network security posture; and cyber forensics analyst support for digital investigations. On the forensics side, the role monitors data-loss-prevention (DLP) solutions and processes email-misuse ("egress") cases in the unit's case management system, conducts endpoint and network digital forensic analysis across Windows, Linux, Mac, and cloud systems, and serves as SME on evidence preservation and chain-of-custody procedures spanning classification levels up to Top Secret. The position also manages the full lifecycle of cyber investigations from creation to closure and supports authoring/updating the unit's standard operating procedures.

  • Advise and assist with maintenance and engineering of the internal investigations forensic network infrastructure across its lifecycle; manage priorities/service requests via the internal ticketing/Change Request process.
  • Collaborate, administer, configure, tune, and secure the unit's tool suite/devices/sensors to avoid unnecessary POA&Ms; review network security architecture/design and provide recommendations to leadership.
  • Maintain SIEM infrastructure/OS supporting collection/aggregation of IDS, firewall, proxy, DLP, antivirus, and vulnerability-scanner data.
  • Support near real-time monitoring of DLP solutions; recommend information-spillage incident-response handling/sanitization per NIST 800-88.
  • Support design/deployment of custom digital forensic builds for triaging, imaging, and advanced analysis; conduct endpoint (Windows/Linux/Mac/cloud) and network-based digital forensic analysis.
  • Support formal digital forensic investigations, documenting findings in formal investigation reports; perform email hygiene activities and process email-misuse ("egress") cases in the case management system.
  • Serve as SME on evidence preservation/chain-of-custody across classification levels and on advanced forensic extraction techniques (encryption bypass, mobile-device unlocking, board-level repair).
  • Create and elevate cases to law-enforcement entities per internal policy/SOPs; manage the lifecycle of cyber investigations from creation to closure; author/update unit SOPs.
Minimum Qualifications
  • Bachelor’s Degree in Computer Science, Engineering, or other Engineering or Technical discipline or equivalent relevant experience.
  • Minimum 5 years of experience in system administration, database administration, network engineering, software engineering, or software development with a concentration in Cyber Security; or, with a bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field.
  • Minimum 3 years of professional experience performing digital media forensic analysis, static malware code disassembly/analysis, and/or runtime malware code analysis.
  • US Citizenship / No Dual
Preferred
  • CISSP (Certified Information Systems Security Professional) or CompTIA Security+.
  • GCFE (GIAC Certified Forensic Examiner), GCFA (GIAC Certified Forensic Analyst), or EnCE (EnCase Certified Examiner).
Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.

Physical Requirements

The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

Disclaimer

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Incident Response Engineer, Mid
Cybersecurity Incident Response Engineer, Mid

asmexternalcareersite • United States

Remote
USD 110,000 - 150,000
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr

ASM Research, An Accenture Federal Services Company • Raleigh (NC)

On-site
USD 80,000 - 111,000
Cyber Threat Hunter
Cyber Threat Hunter

ASM Research, An Accenture Federal Services Company • Sacramento (CA)

On-site
USD 94,000 - 150,000
Cyber Threat Hunter
Cyber Threat Hunter

ASM Research, An Accenture Federal Services Company • Charleston (WV)

On-site
USD 94,000 - 150,000
Cyber Threat Hunter
Cyber Threat Hunter

asmexternalcareersite • United States

Remote
USD 120,000 - 180,000
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr

ASM Research, An Accenture Federal Services Company • Harrisburg

On-site
USD 80,000 - 111,000
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr

asmexternalcareersite • United States

Remote
USD 120,000 - 180,000
Incident Response Coordinator
Incident Response Coordinator

ASM Research, An Accenture Federal Services Company • Harrisburg

On-site
USD 77,000 - 102,000
SOC Analyst
SOC Analyst

asmexternalcareersite • Bethesda (MD)

On-site
USD 90,000 - 130,000
Security Operations Center Manager
Security Operations Center Manager

asmexternalcareersite • Ashburn (VA)

On-site
USD 140,000 - 180,000