Digital Forensics and Incident Response (DFIR) Analyst
Minerva Cyber Technologies is seeking a Digital Forensics and Incident Response (DFIR) Analyst to investigate cyber incidents and produce reliable evidence about what happened, what was affected, and what should happen next. You will support incident responders and system owners throughout investigation and recovery.
What You Will Do
- Collect and examine authorized endpoint, memory, network, identity, and cloud forensic evidence.
- Preserve evidence integrity and maintain investigation notes and chain-of-custody handling records.
- Build forensic timelines and assess persistence, affected accounts, access paths, and potential impact.
- Provide evidence-based input to containment, eradication, and recovery decisions.
- Prepare technical findings, incident summaries, and recommendations for future detection.
Required Qualifications
- Experience conducting digital forensic examinations or hands-on incident investigations.
- Knowledge of operating system artifacts, log analysis, evidence integrity, and investigative limitations.
- Ability to explain analytical methods and distinguish confirmed findings from unresolved questions.
- Experience producing clear reports and working within defined investigative authority.
- Ability to travel to client sites as needed.
Preferred Qualifications
- Experience with memory forensics, cloud investigations, forensic tooling, or endpoint detection and response (EDR) platforms.
- GCFA, GCFE, GCIH, or comparable digital forensics and incident response expertise.
Why Join Minerva
- Work on meaningful missions tied to critical infrastructure resilience and cybersecurity.
- Join a team with deep hands-on cyber and national security experience.
- Help build and shape Minerva's growing OT and critical infrastructure practice.
- Contribute to practical, outcomes-driven work rather than checkbox consulting.