Host Based Cyber Systems Analyst III

ARGO Cyber Systems, LLC

Arlington (VA)

On-site

USD 130,000 - 190,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical
Dental
401K
Equal Opportunity Employer

Job summary

ARGO Cyber Systems (SDVOSB) is seeking experienced Host Forensics Analysts to support a critical federal mission in Arlington, VA. The ideal candidate will bring deep expertise in digital forensics, cyber incident response, host-based investigations, and forensic analysis, along with the ability to operate effectively in government environments.

The Host Forensics Analyst will support federal leads and forensic teams during onsite engagements, providing technical expertise throughout the

Qualifications

  • U.S. Citizenship required and active TS/SCI clearance.
  • Bachelor's degree in a technical discipline or equivalent experience.
  • 8+ years of direct host/digital forensics experience.
  • Experience leading forensic investigations and producing reports.
  • Knowledge of chain-of-custody and forensic integrity.
  • Ability to communicate complex findings to technical and executive audiences.

Responsibilities

  • Coordinate data collection, acquisition, and analysis on onsite engagements.
  • Lead forensic teams and mentor junior personnel.
  • Write detailed technical reports documenting methodologies and findings.
  • Identify indicators of compromise and attack vectors in digital evidence.
  • Maintain chain-of-custody documentation and ensure evidence integrity.
  • Serve as liaison to federal leads and stakeholders and provide status updates.
  • Travel to incident sites across the United States as required.

Skills

Host forensics
Digital forensics
Incident response
Technical writing
Team leadership
Communication
Travel readiness

Education

Bachelor's degree in Computer Science / Cybersecurity / related field
High School Diploma with 10+ years relevant experience

Tools

EnCase
SIFT
X-Ways
Volatility
Wireshark
Sleuth Kit / Autopsy
Splunk
CrowdStrike / EDR

Job description

Company: ARGO Cyber Systems (SDVOSB)

Location: Arlington, VA
Clearance: Active TS/SCI required
Employment Type: Full-Time

We are seeking experienced Host Forensics Analysts to support a critical federal customer mission. The ideal candidate will bring deep expertise in digital forensics, cyber incident response, host-based investigations, and forensic analysis, along with the ability to operate effectively in government environments.

The Host Forensics Analyst will support federal leads and forensic teams during onsite engagements, providing technical expertise throughout the collection, preservation, examination, analysis, and reporting of digital evidence. This position requires strong investigative judgment, attention to forensic integrity, excellent technical writing skills, and the ability to communicate complex findings to both technical and executive stakeholders.

Key Responsibilities
  • Assist federal leads with overseeing and leading forensic teams during onsite engagements, including coordinating data collection and acquisition operations.
  • Provide technical guidance on data collection methods, digital forensic procedures, and investigative techniques to appropriate personnel.
  • Plan, coordinate, and direct the inventory, examination, and comprehensive technical analysis of computer systems, hosts, and digital artifacts.
  • Create and maintain forensically sound duplicates and images of computer systems and digital evidence.
  • Support forensic analysis and mentor junior personnel on data collection, evidence analysis, investigative methodologies, and technical reporting.
  • Assist with leading and coordinating forensic teams during preliminary investigations and onsite incident response engagements.
  • Conduct technical analysis of digital evidence to identify indicators of compromise, malicious activity, attack vectors, persistence mechanisms, and other artifacts associated with cyber incidents.
  • Evaluate, extract, and analyze suspected malicious code and related artifacts.
  • Analyze and characterize cyber attacks, including identifying attack classes, stages of compromise, tactics, techniques, and procedures.
  • Ensure appropriate digital evidence collection, preservation, documentation, and chain-of-custody procedures are followed.
  • Write comprehensive technical reports documenting forensic findings, investigative methodologies, analysis, and conclusions.
  • Distill complex analytic findings into clear executive summaries and detailed technical reports for leadership and stakeholders.
  • Conduct peer reviews and quality assurance reviews of forensic products and reports, particularly those prepared by junior personnel.
  • Serve as a technical forensics liaison to customers and stakeholders, explaining investigative findings, forensic methodologies, protocols, and supporting evidence.
  • Track and document onsite incident response activities and provide regular status updates to federal leadership throughout an engagement.
  • Conduct proactive analysis of systems and networks, including evaluating and establishing trust levels for critical resources.
  • Collaborate effectively with forensic, cybersecurity, incident response, and customer teams operating across multiple physical locations.
  • Travel to incident response locations throughout the United States, U.S. Territories, and Possessions as required.
Required Qualifications
  • U.S. Citizenship required.
  • Active TS/SCI security clearance required.
  • Ability to obtain DHS Suitability.
  • Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical discipline; or
  • High School Diploma/GED with 10+ years of host or digital forensics experience.
  • Minimum 8 years of directly relevant experience conducting cyber forensic investigations using industry-standard forensic tools and leading-edge technologies.
  • Demonstrated experience conducting host-based and/or digital forensic investigations.
  • Experience creating forensically sound duplicates and forensic images of computer systems.
  • Demonstrated ability to produce comprehensive cyber investigative reports documenting digital forensic findings.
  • Experience analyzing and characterizing cyber attacks and related digital evidence.
  • Knowledge of proper digital asset collection, preservation, handling, and chain-of-custody procedures.
  • Demonstrated ability to identify different classes of cyber attacks and stages of compromise.
  • Knowledge of system and application security threats, vulnerabilities, and attack methodologies.
  • Knowledge and experience conducting proactive analysis of systems and networks, including establishing trust levels for critical resources.
  • Strong technical writing, analytical, communication, and presentation skills.
  • Ability to work collaboratively with geographically dispersed teams and stakeholders.
  • Ability and willingness to travel extensively to support onsite incident response engagements.
Desired Skills
  • EnCase
  • SIFT
  • X-Ways
  • Volatility
  • Wireshark
  • Sleuth Kit / Autopsy
  • Magnet AXIOM Cyber
  • Snort
  • Splunk or other SIEM platforms, including ArcSight, LogRhythm, Elastic, or similar
  • EDR platforms, including CrowdStrike, Microsoft Defender for Endpoint (MDE), Trellix, or similar technologies
  • Other industry-standard digital forensics, incident response, SIEM, EDR, or security analysis tools
Desired Certifications
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Certified Forensic Examiner (GCFE)
  • EnCase Certified Examiner (EnCE)
  • Certified Computer Examiner (CCE)
  • Certified Forensic Computer Examiner (CFCE)
  • Certified Information Systems Security Professional (CISSP)
Company Benefits

ARGO Cyber Systems provides industry competitive employee benefits to include medical, dental, vision, life insurance, and 401K.

Argo Cyber Systems is a Federal Contractor and an Equal Opportunity Employer.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Host Based Cyber Systems Analyst III
Host Based Cyber Systems Analyst III

ARGO Cyber Systems • Arlington (VA)

On-site
USD 120,000 - 140,000
Medical insurance
Dental insurance
Vision insurance
+2
Host Based Systems Analyst IV
Host Based Systems Analyst IV

ARSIEM • Arlington (VA)

On-site
USD 85,000 - 110,000
Senior Host-Based Cyber Forensics Analyst
Senior Host-Based Cyber Forensics Analyst

ARGO Cyber Systems, LLC • Arlington (VA)

On-site
USD 130,000 - 190,000
Medical
Dental
401K
+1
Host Forensics Analyst
Host Forensics Analyst

Solutions³ LLC • Arlington (VA)

Hybrid
USD 90,000 - 120,000
Senior Host Forensics Analyst – TS/SCI
Senior Host Forensics Analyst – TS/SCI

ARGO Cyber Systems • Arlington (VA)

On-site
USD 120,000 - 140,000
Medical insurance
Dental insurance
Vision insurance
+2
Host Based Analyst III
Host Based Analyst III

DigiFlight, Inc. • Columbia (MD)

On-site
USD 90,000 - 120,000
Host Based Systems Analyst - L03
Host Based Systems Analyst - L03

Base One Technologies • Arlington (VA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Host Based Systems Analyst III
Host Based Systems Analyst III

Solutions3 LLC • Arlington (VA), Northern (KY)

On-site
USD 140,000 - 200,000
Host Based Systems Analyst - III
Host Based Systems Analyst - III

Base One Technologies • Arlington (VA), Northern (KY)

Hybrid
USD 120,000 - 180,000
Host Based Systems Analyst III
Host Based Systems Analyst III

ARSIEM • Arlington (VA)

On-site
USD 80,000 - 120,000
Referral bonus program
Equal Opportunity and Affirmative Action Employer