Digital Forensics and Incident Analyst

Jobtailor

Washington (WA, District of Columbia)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in Washington state seeks a Senior Digital Forensics & Incident Response professional with an active Top Secret clearance to lead investigations and coordinate across the SOC.

You will apply EnCase, FTK, Autopsy, Wireshark, Ghidra and IDA Pro to analyze evidence, prepare technical reports, and ensure chain-of-custody while communicating findings to legal and oversight authorities.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Digital Forensics, Information Systems, or related field.
  • 7 years of hands-on DFIR experience, ideally in federal or regulated environments.
  • Certifications: CFIA and CFIH.
  • Experience with industry tools: EnCase, FTK, Autopsy, X-Ways, Wireshark, YARA, Ghidra/IDA Pro.
  • Strong command of Windows, Unix, and Linux internals; virtualization; SIEM.
  • Familiarity with NICE Framework, NIST guidance, MITRE ATT&CK, chain-of-custody standards, and Rules of Evidence.
  • Excellent technical writing and the ability to present findings clearly to legal, oversight, and investigative authorities.

Responsibilities

  • Support the Threat Analysis & Investigations (TA&I) function, analyzing digital evidence and investigating computer security incidents
  • Provide Tier 2 and Tier 3 support to the enterprise Security Operations Center (SOC) and coordinate with partner/enterprise security operations centers
  • Identify, collect, examine, and preserve digital evidence using controlled and documented analytical and investigative techniques
  • Conduct digital analysis in response to investigations of computer-based crimes and cyber-intrusion incidents
  • Analyze log files, evidence, and other information to determine the best methods for identifying the perpetrator(s) of a network intrusion
  • Confirm what is known about an intrusion and discover new information via dynamic analysis
  • Provide technical summaries of findings and deliver written analysis reports
  • Collect and analyze intrusion artifacts and recommend courses of action or countermeasures to mitigate risk

Skills

Analytical thinking
Clear communication
Technical writing
Cybersecurity

Education

Bachelor's degree in Cybersecurity, Computer Science, Digital Forensics, Information Systems, or related field

Tools

EnCase
FTK
Autopsy
X-Ways
Wireshark
Ghidra
IDA Pro

Job description

Job Responsibilities
  • Support the Threat Analysis & Investigations (TA&I) function, analyzing digital evidence and investigating computer security incidents
  • Provide Tier 2 and Tier 3 support to the enterprise Security Operations Center (SOC) and coordinate with partner/enterprise security operations centers
  • Identify, collect, examine, and preserve digital evidence using controlled and documented analytical and investigative techniques
  • Conduct digital analysis in response to investigations of computer-based crimes and cyber-intrusion incidents
  • Analyze log files, evidence, and other information to determine the best methods for identifying the perpetrator(s) of a network intrusion
  • Confirm what is known about an intrusion and discover new information via dynamic analysis
  • Provide technical summaries of findings and deliver written analysis reports
  • Collect and analyze intrusion artifacts and recommend courses of action or countermeasures to mitigate risk
Requirements
  • U.S. citizenship and an active Top Secret (TS) security clearance
  • Bachelor's degree in Cybersecurity, Computer Science, Digital Forensics, Information Systems, or a related field (additional experience may substitute for degree)
  • 7 years of hands‑on digital forensics and incident response (DFIR) experience, ideally in federal or otherwise regulated environments
  • Required certifications: CFIA and CFIH
  • Demonstrated expertise with industry‑standard forensic and analysis tools (e.g., EnCase, FTK, Autopsy/The Sleuth Kit, X-Ways, Volatility, Wireshark, YARA, and malware reverse‑engineering tools such as Ghidra or IDA Pro)
  • Strong command of Windows, Unix, and Linux internals; file systems (NTFS, FAT, EXT); virtualization; and SIEM/event‑correlation platforms
  • Working knowledge of the NICE Framework, NIST guidance, MITRE ATT&CK, chain‑of‑custody standards, and Rules of Evidence
  • Excellent technical writing and the ability to present findings clearly to legal, oversight, and investigative authorities
Core Competencies

Demonstrates expertise in digital forensics and incident response, utilizing industry‑standard tools and methodologies to analyze and investigate cyber incidents. Proficient in technical writing and presenting findings to various stakeholders, ensuring compliance with legal and regulatory standards.

Highest‑signal resume keywords
  • Digital Forensics
  • Incident Response
  • Technical Writing
  • Cybersecurity Certifications
  • Security Clearance
ATS Optimization Keywords
Hard Skills
  • Digital Evidence Analysis
  • Intrusion Analysis
  • Log File Analysis
  • Dynamic Analysis
  • Malware Reverse‑Engineering
Soft Skills
  • Clear Communication
  • Analytical Thinking
Certifications & Qualifications
  • CFIA
  • CFIH
Industry Keywords
  • NIST Guidance
  • MITRE ATT&CK
  • NICE Framework
  • Chain‑of‑custody Standards
  • Rules of Evidence
Tools & Technologies
  • EnCase
  • FTK
  • Autopsy
  • X-Ways
  • Wireshark
  • Ghidra
  • IDA Pro
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Digital Forensics and Incident Analyst (TS)
Digital Forensics and Incident Analyst (TS)

Agile Defense • Washington

On-site
USD 120,000 - 160,000
Investigation & Forensic Analyst
Investigation & Forensic Analyst

Jobtailor • San Diego (CA)

On-site
USD 70,000 - 100,000
Digital Forensics / Malware Analyst
Digital Forensics / Malware Analyst

Digital Global Connectors • McLean (VA)

Hybrid
USD 90,000 - 150,000
Mid-Level Digital Forensics and Incident Response Analyst
Mid-Level Digital Forensics and Incident Response Analyst

Jobtailor • Huntsville (AL)

On-site
USD 90,000 - 130,000
Senior Cyber Defense Engineer
Senior Cyber Defense Engineer

Jobtailor • Colorado

On-site
USD 140,000 - 190,000
Digital Forensic Specialist
Digital Forensic Specialist

ALLTECH CONSULTING SVC INC • Troy (MI)

On-site
USD 60,000 - 110,000
Information Technology Manager II
Information Technology Manager II

Jobtailor • Colorado

On-site
USD 140,000 - 190,000
Forensic Analyst
Forensic Analyst

areteir • United States

On-site
USD 90,000 - 140,000
Cyber Security Analyst – TS/SCI with Polygraph
Cyber Security Analyst – TS/SCI with Polygraph

Jobtailor • Colorado

On-site
USD 130,000 - 190,000
Digital Forensics Analyst
Digital Forensics Analyst

SAIC • Chantilly (VA)

On-site
USD 100,000 - 130,000