Digital Forensics Analyst

Gunnison

Alexandria (VA)

Hybrid

USD 125,000 - 145,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

401(k) employer match
Medical, Dental & Vision
Professional development funds
Paid holidays
Flexible time off

Job summary

Gunnison is seeking a skilled digital forensics and incident response professional to join our security operations. The role focuses on investigations, threat hunting, malware analysis, and proactive defense to strengthen enterprise security across enterprise infrastructure.

The candidate will work with security operations, incident response, and engineering teams to enhance detection capabilities, produce detailed reports, and maintain SOPs.

Qualifications

  • 5+ years digital forensics experience (Windows, Linux, macOS)
  • Experience with disk duplication, mobile forensics, malware analysis, and forensic toolsets
  • Experience with AWS, Azure, M365, CloudTrail, IAM logs, EDR, SIEM, packet capture
  • Ability to investigate Virtual Machines, CloudTrail, IAM logs
  • Clearance or ability to obtain a Public Trust is implied by employer requirements

Responsibilities

  • Perform network and media digital forensic investigations to support cybersecurity incident response, threat analysis, and enterprise security operations.
  • Conduct advanced threat hunting activities to identify malicious activity, IOCS, and persistent threats.
  • Utilize forensic tools and procedures to investigate cybersecurity events and incidents.
  • Analyze malware, suspicious files, network traffic, and compromised systems to determine attack vectors and remediation actions.
  • Execute proactive defense through IOC sweeps, host interrogation, and ongoing threat hunting.
  • Prepare forensic and incident response reports documenting findings, root cause, remediation actions, and lessons learned.
  • Develop and update SOPs for forensic analysis, malware analysis, and threat hunting.
  • Coordinate insider threat investigations and preserve digital evidence according to requirements.
  • Produce status reports for cybersecurity leadership and stakeholders.
  • Collaborate with security operations, incident response, and engineering teams to strengthen detection and response capabilities.

Skills

Digital forensics
Threat hunting
Incident response
Malware analysis
Security monitoring

Tools

EDR tools
SIEM
Cloud logs (AWS/Azure)
Forensic tooling (EnCase/FTK)

Job description

  • This position is contingent upon a future opening with Gunnison.

Salary: $125,000-$145,000

  • Perform network and media digital forensic investigations to support cybersecurity incident response, threat analysis, and enterprise security operations.
  • Conduct advanced threat hunting activities across enterprise infrastructure to identify malicious activity, indicators of compromise (IOCs), and persistent threats.
  • Utilize industry-standard forensic, malware analysis, and incident response tools, techniques, and procedures to investigate cybersecurity events and security incidents.
  • Analyze malware, suspicious files, network traffic, and compromised systems to determine attack vectors, scope of compromise, and remediation recommendations.
  • Execute proactive defense activities through IOC sweeps, host interrogation, and continuous threat hunting across systems operated by and on behalf of the organization.
  • Support enterprise incident response activities by providing forensic analysis, technical findings, and status updates in accordance with established incident response procedures and reporting timelines.
  • Develop, maintain, and update forensic analysis, malware analysis, and advanced threat hunting standard operating procedures (SOPs) and operational documentation.
  • Prepare detailed forensic and incident response reports documenting investigative findings, technical analysis, root cause, remediation actions, and lessons learned.
  • Develop and enhance forensic processes, detection capabilities, scripts, automation tools, and security content to improve investigative efficiency and threat detection.
  • Coordinate and support insider threat investigations by collecting, analyzing, and preserving digital evidence in accordance with organizational and legal requirements.
  • Produce recurring technical status reports and communicate investigative progress, trends, and risks to cybersecurity leadership and stakeholders.
  • Collaborate with security operations, incident response, and cybersecurity engineering teams to strengthen enterprise detection, response, and defensive capabilities.
Description
  • Perform network and media digital forensic investigations to support cybersecurity incident response, threat analysis, and enterprise security operations.
  • Conduct advanced threat hunting activities across enterprise infrastructure to identify malicious activity, indicators of compromise (IOCs), and persistent threats.
  • Utilize industry-standard forensic, malware analysis, and incident response tools, techniques, and procedures to investigate cybersecurity events and security incidents.
  • Analyze malware, suspicious files, network traffic, and compromised systems to determine attack vectors, scope of compromise, and remediation recommendations.
  • Execute proactive defense activities through IOC sweeps, host interrogation, and continuous threat hunting across systems operated by and on behalf of the organization.
  • Support enterprise incident response activities by providing forensic analysis, technical findings, and status updates in accordance with established incident response procedures and reporting timelines.
  • Develop, maintain, and update forensic analysis, malware analysis, and advanced threat hunting standard operating procedures (SOPs) and operational documentation.
  • Prepare detailed forensic and incident response reports documenting investigative findings, technical analysis, root cause, remediation actions, and lessons learned.
  • Develop and enhance forensic processes, detection capabilities, scripts, automation tools, and security content to improve investigative efficiency and threat detection.
  • Coordinate and support insider threat investigations by collecting, analyzing, and preserving digital evidence in accordance with organizational and legal requirements.
  • Produce recurring technical status reports and communicate investigative progress, trends, and risks to cybersecurity leadership and stakeholders.
  • Collaborate with security operations, incident response, and cybersecurity engineering teams to strengthen enterprise detection, response, and defensive capabilities.
Work location

Hybrid, 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site.

  • Perform network and media digital forensic investigations to support cybersecurity incident response, threat analysis, and enterprise security operations.
  • Conduct advanced threat hunting activities across enterprise infrastructure to identify malicious activity, indicators of compromise (IOCs), and persistent threats.
  • Utilize industry-standard forensic, malware analysis, and incident response tools, techniques, and procedures to investigate cybersecurity events and security incidents.
  • Analyze malware, suspicious files, network traffic, and compromised systems to determine attack vectors, scope of compromise, and remediation recommendations.
  • Execute proactive defense activities through IOC sweeps, host interrogation, and continuous threat hunting across systems operated by and on behalf of the organization.
  • Support enterprise incident response activities by providing forensic analysis, technical findings, and status updates in accordance with established incident response procedures and reporting timelines.
  • Develop, maintain, and update forensic analysis, malware analysis, and advanced threat hunting standard operating procedures (SOPs) and operational documentation.
  • Prepare detailed forensic and incident response reports documenting investigative findings, technical analysis, root cause, remediation actions, and lessons learned.
  • Develop and enhance forensic processes, detection capabilities, scripts, automation tools, and security content to improve investigative efficiency and threat detection.
  • Coordinate and support insider threat investigations by collecting, analyzing, and preserving digital evidence in accordance with organizational and legal requirements.
  • Produce recurring technical status reports and communicate investigative progress, trends, and risks to cybersecurity leadership and stakeholders.
  • Collaborate with security operations, incident response, and cybersecurity engineering teams to strengthen enterprise detection, response, and defensive capabilities.
Requirements
  • US Citizenship required
  • 5+ years digital forensics experience (Windows, Linux, macOS)
  • Experience with disk duplication, mobile forensics, malware analysis, and forensic toolsets
  • Experience with AWS, Azure, M365, CloudTrail, IAM logs, EDR, SIEM, packet capture
  • Ability to investigate Virtual Machines, CloudTrail, IAM logs.
  • Accepted certifications include: GCIH, GCFA, GCFE, GREM, GISF, GXPN, GCTI, GOSI, EnCase (EnCE, CFSR, ENCEP)
Clearance Requirement

Ability to obtain and maintain a Public Trust.

Benefits

Gunnison Consulting Group's total compensation package also includes bonus and profit-sharing opportunities, depending on company and employee performance. Available employee benefits include:

  • 3 weeks of Personal Leave you first year
  • 11 paid Holidays each year
  • 5 days of Flexible Time Off each year for approved training or certifications (self-study is ineligible)
  • 401(k) company match at 50% up to 10% of your salary
  • Medical, Dental and Vision Insurance
  • Life and Disability Insurance
  • Public Transportation Subsidies
  • Certifications and Training Allowance - Up to $5,000/year!
Why Join Gunnison?
  • Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation.
  • Quality is our top priority.
  • Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer.
  • There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow.
  • We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding.
  • We hire for careers at Gunnison, not to fill a position.

Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time.

In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects. By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could, the company has thrived for over 25 years.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

Gunnison Consulting Group • Northern (KY)

Hybrid
USD 115,000 - 121,000
Personal Leave 3 weeks
11 Paid Holidays
Flexible Time Off
+5
Cybersecurity Engineer
Cybersecurity Engineer

Gunnison Consulting Group • Washington

Hybrid
USD 115,000 - 121,000
3 weeks of Personal Leave
11 paid Holidays
5 days of Flexible Time Off
+5
Cybersecurity Engineer
Cybersecurity Engineer

Gunnison • Washington

Hybrid
USD 115,000 - 121,000
Personal Leave
Holidays (11)
Flexible Time Off
+5
Junior Artificial Intelligence (AI) Solutions Engineer
Junior Artificial Intelligence (AI) Solutions Engineer

Worky • Washington

On-site
USD 80,000 - 90,000
Personal Leave
Paid Holidays
Flexible Time Off
+5
Artificial Intelligence (AI) Solutions Engineer (part-time)
Artificial Intelligence (AI) Solutions Engineer (part-time)

Worky • Washington

On-site
USD 99,000 - 112,000
Personal Leave
Holidays
Flexible Time Off
+5
Cybersecurity Policy Analyst
Cybersecurity Policy Analyst

Gunnison • Chevy Chase (MD)

Hybrid
USD 95,000 - 107,000
Personal Leave (3 weeks) toll
Paid Holidays (11 days)
Flexible Time Off (5 days)
+5
Digital Forensic Analyst I
Digital Forensic Analyst I

CGS Federal (Contact Government Services) • Los Angeles (CA)

On-site
USD 85,000 - 125,000
Health, Dental, and Vision
Life Insurance
401k
+2
Desktop Technician
Desktop Technician

Gunnison Consulting Group • Ruidoso (NM)

On-site
USD 40,000 - 43,000
3 weeks of Personal Leave your first年
11 paid Holidays each year
5 days of Flexible Time Off each year
+5
Desktop Technician
Desktop Technician

Gunnison Consulting Group • Portland (OR), Northern (KY)

Hybrid
USD 40,000 - 43,000
Personal Leave
Holidays
Flexible Time Off
+5
Digital Forensic Analyst I
Digital Forensic Analyst I

CGS Federal (Contact Government Services) • United States

On-site
USD 70,000 - 90,000
Health, Dental, and Vision
Life Insurance
401k
+2