Host Based Cyber Systems Analyst III

ARGO Cyber Systems

Arlington (VA)

Hybrid

USD 120,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Argo Cyber Systems is seeking a Host-Based Systems Analyst III to support DHS HIRT’s incident response and digital forensics operations. You will lead host-level investigations, triage, and reporting, triaging evidence, and coordinating across federal stakeholders while maintaining strict chain‑of‑custody standards.

You will work on advanced cyber threats targeting critical government systems, performing malware triage, evidence collection, and investigative reporting, with onsite/remote work

Qualifications

  • 5+ years of hands-on forensic investigations
  • Experience acquiring and preserving digital evidence
  • Ability to analyze attacks and system compromises

Responsibilities

  • Lead forensic investigations for incident response and post‑mortem reviews
  • Direct collection and analysis of host-based evidence across OS environments
  • Correlate host findings with network telemetry to reconstruct intrusion narratives
  • Maintain chain-of-custody and produce technical and executive reports

Skills

Forensic investigations
Memory analysis
Evidence handling
Windows/Linux
Chain of custody

Education

Bachelor's degree in Computer Science/Cybersecurity/Computer Engineering
High School Diploma with 7-9 years of host/digital forensics

Tools

EnCase
FTK
Volatility
Sleuth Kit

Job description

Host-Based Systems Analyst III (HBA03) - Full Performance

Location: Onsite / Remote (as required for mission)

Clearance: Active TS/SCI with DHS EOD eligibility

Company: Argo Cyber Systems, LLC - Service-Disabled Veteran-Owned Small Business (SDVOSB)

About Argo Cyber Systems

Argo Cyber Systems supports the Department of Homeland Security (DHS) Hunt and Incident Response Team (HIRT) in protecting the Nation's cyber and communications infrastructure. Our mission-driven analysts provide rapid onsite and remote response, advanced forensics, and proactive threat-hunting capabilities across federal civilian networks and high-value assets.

As part of the HIRT mission, Argo personnel deliver advanced technical assistance, incident containment, and forensic expertise to mitigate intrusions, restore operations, and strengthen national cyber resilience.

Position Overview

Argo Cyber Systems is seeking an experienced Host-Based Systems Analyst III (HBA03) to support DHS HIRT's national incident response and digital forensics operations. The successful candidate will lead and execute host-level forensic analysis, malware triage, and investigative reporting in response to advanced cyber threats targeting critical government systems.

This role combines hands-on technical expertise with mission-critical communication and coordination responsibilities - directly supporting DHS leadership and federal stakeholders during high-impact incidents.

Key Responsibilities

  • Lead and coordinate forensic investigations in support of incident response engagements and post-compromise assessments.
  • Plan, direct, and execute the collection, examination, and analysis of host-based evidence across multiple operating systems and environments.
  • Acquire, preserve, and analyze digital artifacts (malware, volatile memory, registry data, user activity, logs, and executables) to support attribution and root-cause analysis.
  • Perform forensic triage to determine incident scope, urgency, and potential impact on enterprise operations.
  • Correlate host-level findings with network telemetry to reconstruct intrusion narratives and identify persistence or lateral movement.
  • Evaluate and dissect malicious code and executable behavior to identify tactics, techniques, and procedures (TTPs).
  • Maintain strict chain of custody and documentation standards to ensure evidence integrity.
  • Distill technical analysis into clear, actionable reports and executive summaries suitable for senior leadership and interagency partners.
  • Serve as a technical liaison to government stakeholders, explaining forensic methodologies, tools, and findings in both technical and operational terms.
  • Support the development of Computer Network Defense (CND) guidance, playbooks, and after-action reports based on investigative outcomes.

Required Qualifications

  • U.S. Citizenship (required)
  • Active TS/SCI clearance (required)
  • Ability to obtain DHS Entry on Duty (EOD) Suitability
  • 5+ years of hands-on experience conducting host-based or digital forensic investigations
  • Expertise in forensically sound data acquisition, duplication, and preservation
  • Proficiency in analyzing, categorizing, and reporting cyber attacks and system compromises
  • Strong knowledge of evidence handling procedures, documentation, and chain-of-custody standards
  • Familiarity with attack lifecycle phases and common adversary techniques
  • Comprehensive understanding of system and application security threats, vulnerabilities, and mitigation strategies
  • Experience performing host triage, live response, and volatile memory analysis
  • Proficiency with Windows, Linux/Unix, and related file systems
  • Demonstrated ability to collaborate across distributed teams in time-sensitive operational environments

Desired Qualifications

  • Proficiency with two or more of the following forensic and analysis tools:
    • EnCase, FTK, X-Ways, SIFT, Volatility, Sleuth Kit/Autopsy
    • Wireshark, Splunk, Snort, or EDR tools (CrowdStrike, Carbon Black, SentinelOne)
  • Experience conducting malware reverse-engineering and all-source research
  • Understanding of threat actor TTPs and advanced intrusion methodologies
  • Strong communication skills for technical briefings and interagency coordination
Education

  • Bachelor's Degree in Computer Science, Cybersecurity, Computer Engineering, or a related field or
  • High School Diploma with 7-9 years of host or digital forensics experience

Preferred Certifications

  • GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, or equivalent

Why Join Argo Cyber Systems

Argo Cyber Systems empowers federal partners to outpace and outmaneuver adversaries through precision forensics, agile response, and mission-first cybersecurity operations. As part of the DHS HIRT mission, you will be on the front lines of national cyber defense-supporting the investigation, containment, and recovery of the nation's most critical systems.

Salary: $120000 - $140000 per year

Job Posted by ApplicantPro

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Host-Based Cyber Forensics Analyst
Senior Host-Based Cyber Forensics Analyst

ARGO Cyber Systems • Arlington (VA)

Hybrid
USD 120,000 - 140,000
Host Based Cyber Systems Analyst IV
Host Based Cyber Systems Analyst IV

ARGO Cyber Systems • Arlington (VA)

Hybrid
USD 130,000 - 160,000
Incident Response Expert III
Incident Response Expert III

ARGO Cyber Systems • Arlington (VA)

On-site
USD 100,000 - 125,000
Host Forensics Analyst
Host Forensics Analyst

bcmcllc • Arlington (VA)

On-site
USD 85,000 - 110,000
95% employer paid medical, dental, & vision coverages
100% employer paid life, STD & LTD disability coverages
401k with company match and profit sharing
+1
Host Based Systems Analyst IV
Host Based Systems Analyst IV

Solutions³ LLC • Virginia (MN)

On-site
USD 110,000 - 170,000
Computer Network Defense Incident Manager III
Computer Network Defense Incident Manager III

argocyber • Arlington (VA)

On-site
USD 140,000 - 190,000
Host Based Systems Analyst III
Host Based Systems Analyst III

ARSIEM • Arlington (VA)

On-site
USD 80,000 - 120,000
Referral bonus program
Equal Opportunity and Affirmative Action Employer
Host Based Systems Analyst IV
Host Based Systems Analyst IV

ARSIEM • Arlington (VA)

On-site
USD 85,000 - 110,000
Host Based Systems Analyst IV
Host Based Systems Analyst IV

Solutions³ LLC • Arlington (VA)

On-site
USD 120,000 - 165,000
Host Forensics Analyst
Host Forensics Analyst

Solutions³ LLC • Arlington (VA)

Hybrid
USD 90,000 - 120,000