Digital Forensic Analyst - Koniag Government Services

OpenTalent

Washington

On-site

USD 90,000 - 130,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

OpenTalent in Washington state seeks a seasoned digital forensics expert to perform examinations of hard drives, mobile devices, servers, network devices, VMs, and cloud environments, ensuring evidence integrity and admissibility.

You will lead forensic acquisitions with write-blocking and hashing, analyze artifacts, conduct memory forensics, log correlation, malware and network analysis, and support e-discovery and IR.

Responsibilities

  • Conduct comprehensive digital forensic examinations of hard drives, mobile devices, servers, networks, VMs, and cloud environments for evidentiary artifacts.
  • Perform forensic acquisition with write-blocking, hashing, and chain-of-custody procedures to ensure integrity.
  • Analyze images for artifacts such as deleted files, metadata, logs, browser history, emails, and user activity records.
  • Conduct memory forensics to identify volatile artifacts and running processes.
  • Perform log analysis and correlation across endpoints, networks, apps, and cloud platforms to reconstruct timelines and IOCs.
  • Perform static and dynamic malware analysis to identify capabilities and indicators of compromise.
  • Analyze network captures (PCAPs) and flows to detect malicious activity and exfiltration.
  • Conduct mobile forensics (logical/physical) on iOS and Android devices.
  • Perform cloud forensics across enterprise cloud environments, including audit logs and IAM records.
  • Support e-discovery and litigation holds for electronic data in compliance with legal requirements.
  • Serve as the forensics SME within the incident response team across all phases from detection to post-incident review.
  • Respond to cybersecurity incidents requiring forensic investigations, preserving volatile and non-volatile evidence.

Job description

  • Conduct comprehensive digital forensic examinations of a wide range of digital media and platforms, including hard drives, solid-state drives, removable media, mobile devices, network devices, servers, virtual machines, and cloud environments (e.g., AWS, Microsoft Azure/Microsoft 365).
  • Perform forensic acquisition of digital evidence using industry-standard forensic imaging tools and techniques, ensuring the integrity and admissibility of all acquired evidence through proper application of write-blocking, hashing, and chain of custody procedures.
  • Analyze acquired forensic images for relevant artifacts, including deleted files, file system metadata, registry entries, event logs, browser history, email artifacts, user activity records, network connection logs, and other evidentiary data relevant to the investigation.
  • Conduct memory forensics, including volatile memory acquisition and analysis, to identify running processes, network connections, injected code, encryption keys, and other artifacts not present in disk-based evidence.
  • Perform log analysis and correlation across endpoint, network, application, and cloud platform log sources to reconstruct timelines of activity, identify indicators of compromise (IOCs), and support investigation findings.
  • Conduct static and dynamic malware analysis to identify malicious code capabilities, behaviors, command-and-control infrastructure, persistence mechanisms, and indicators of compromise associated with investigated incidents.
  • Analyze network traffic captures (PCAPs) and network flow data to identify malicious activity, data exfiltration, unauthorized access, lateral movement, and other network-based indicators relevant to active investigations.
  • Perform mobile device forensics, including logical and physical acquisition and analysis of iOS and Android devices, recovering relevant communications, application data, location history, and user activity artifacts.
  • Conduct cloud forensics activities across enterprise cloud environments, including the collection and analysis of cloud audit logs, storage artifacts, identity and access management records, and other cloud-native evidence sources.
  • Support e-discovery and litigation hold activities, including the identification, preservation, collection, and processing of electronically stored information (ESI) in accordance with applicable legal requirements and client policies.
  • Serve as the forensics subject matter expert within the incident response team, providing timely and expert forensic support across all phases of the incident response lifecycle, from initial detection and containment through eradication, recovery, and post-incident review.
  • Respond to cybersecurity incidents requiring forensic investigation, deploying forensic capabilities rapidly to collect and preserve volatile and non-volatile evidence before it is lost or altered.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Digital Forensics Analyst – Incident Response Expert
Digital Forensics Analyst – Incident Response Expert

Koniag Government Services • Washington

Hybrid
USD 95,000 - 135,000
Medical insurance
Dental insurance
Vision insurance
+7
Senior Digital Forensics Analyst: IR & Cloud Evidence
Senior Digital Forensics Analyst: IR & Cloud Evidence

Koniag Services, Inc. • Washington, Northern (KY)

Hybrid
USD 120,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+3
Digital Forensic Analyst
Digital Forensic Analyst

Koniag Services, Inc. • Washington, Northern (KY)

Hybrid
USD 120,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+3
Digital Forensic Analyst
Digital Forensic Analyst

Koniag Government Services • Washington

Hybrid
USD 95,000 - 135,000
Medical insurance
Dental insurance
Vision insurance
+7
Digital Forensic Specialist
Digital Forensic Specialist

ALLTECH CONSULTING SVC INC • Troy (MI)

On-site
USD 60,000 - 110,000
Digital Forensics Analyst
Digital Forensics Analyst

Forensic Focus Limited • Alexandria (VA), Northern (KY)

Hybrid
USD 120,000 - 180,000
Digital Forensic Analyst - Incident Response & Cloud
Digital Forensic Analyst - Incident Response & Cloud

OpenTalent • Washington

On-site
USD 90,000 - 130,000
Digital Forensics Analyst
Digital Forensics Analyst

SAIC • Chantilly (VA)

On-site
USD 100,000 - 130,000
Digital Forensics Systems Specialist
Digital Forensics Systems Specialist

NXTKEY CORPORATION • Washington

On-site
USD 80,000 - 120,000
Senior Digital Forensics Analyst: Endpoint, Mobile & Cloud
Senior Digital Forensics Analyst: Endpoint, Mobile & Cloud

Forensic Focus Limited • Alexandria (VA), Northern (KY)

Hybrid
USD 120,000 - 180,000