Security Spec Lead – Digital Forensics Analyst

Jobtailor

Kentucky

On-site

USD 110,000 - 165,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Jobtailor in Kentucky seeks a senior Digital Forensics & Insider Threat investigator to lead end-to-end investigations and develop forensic policies.

The role requires reporting findings to HR, Legal, Ethics, Physical Security, and other stakeholders, and serving as a technical SME for threat analytics and DLP. You will manage cases from start to finish and translate complex results into business implications.

Qualifications

  • Bachelor's degree OR Associate's degree with 2 years relevant experience OR High School Diploma/GED with 4 years relevant experience.
  • 7+ years of Information Technology experience OR 5+ years in security
  • Experience with standard forensic methods and collection/analysis tools
  • Experience in technical investigations or root cause analysis
  • Experience identifying insider risk indicators through analytics tools
  • Understand digital forensics in cloud environments
  • Familiarity with threat actor tactics, techniques, and procedures
  • Knowledge of cyber investigations and incident response processes

Responsibilities

  • Conduct end-to-end investigations of internal and external matters
  • Prepare findings reports for HR, Legal, Ethics, Physical Security, and other stakeholders
  • Develop and maintain Digital Forensics policies and procedures documentation
  • Support risk-reduction projects, including post-incident lessons learned
  • Serve as a technical SME for Insider Threat, DLP, and cyber investigations
  • Produce clear investigative and analytic reports for technical and executive audiences
  • Maintain tools and technologies for Digital Forensics collection and analysis
  • Partner with Cyber Incident Responders, HR, Legal, Ethics, Physical Security, and other stakeholders
  • Manage cases from initiation to resolution
  • Communicate technical conclusions in clear business language

Skills

Digital Forensics
Insider Threat Investigation
Malware reverse engineering
Threat analytics
Security monitoring
Log sources analysis
Evidence handling
Forensic tooling
Splunk query development

Education

Bachelor's degree
Associate's degree + 2 years relevant experience
High School Diploma/GED + 4 years relevant experience

Tools

Forensic Tools
SIEM Platforms
Endpoint Detection Solutions
Splunk

Job description

  • Conduct end-to-end investigations of internal and external matters
  • Prepare findings reports for HR, Legal, Ethics, Physical Security, and other stakeholders
  • Develop and maintain Digital Forensics policies and procedures documentation
  • Support risk-reduction projects, including post-incident lessons learned
  • Serve as a technical SME for Insider Threat, DLP, and cyber investigations
  • Produce clear investigative and analytic reports for technical and executive audiences
  • Maintain tools and technologies for Digital Forensics collection and analysis
  • Partner with Cyber Incident Responders, HR, Legal, Ethics, Physical Security, and other stakeholders
  • Manage cases from initiation to resolution
  • Communicate technical conclusions in clear business language
Requirements
  • Ability to obtain and maintain a U.S. government security clearance
  • In-depth understanding of Windows, Linux/Unix, MacOS, Android, iOS, and interconnected network devices
  • Understanding of mobile device forensics and evidence collection techniques
  • Experience with malware reverse engineering and analysis
  • Understanding of anomalous user activity monitoring and policy violation investigations
  • Ability to use internal and external log sources, forensic tools, and established investigative methods
  • Ability to handle sensitive and confidential material appropriately
  • Understanding of forensic capture and analysis methodologies and evidence chain of custody procedures
  • Bachelor's degree OR Associate's degree with 2 years relevant experience OR High School Diploma/GED with 4 years relevant experience
  • 7 or more years of Information Technology related experience OR 5 or more years of security related experience
  • Experience with standard forensic methods and collection and analysis tools
  • Experience conducting technical investigations or root cause analysis
  • Experience identifying insider risk indicators through analytics tools
  • Understanding and experience with digital forensics in a cloud environment
  • Understanding of threat actor tactics, techniques, and procedures
  • Familiarity with electric utility operations, IC/SCADA, or NERC CIP
  • Working knowledge of programming languages and Splunk query development
  • Ability to apply AI to threat detection and analysis
  • Understanding and experience with security monitoring tools, SIEM platforms, and endpoint detection solutions
  • Knowledge of cyber investigations and incident response processes
  • Experience with case management and evidence handling procedures
  • Experience with data classification, information protection, DLP, and sensitive data monitoring technologies
  • Preferred certifications include SANS Forensics Certifications, CHFI, GCIH, and vendor-specific certifications
Core Competencies

Demonstrates expertise in Digital Forensics, including evidence collection, analysis methodologies, and insider threat investigations. Proficient in communicating technical findings to diverse stakeholders and managing complex cases from initiation to resolution.

Highest-signal resume keywords
  • Digital Forensics
  • Malware Reverse Engineering
  • Insider Threat Investigation
  • Forensic Tools Proficiency
  • Security Clearance
Hard Skills
  • Windows
  • Linux/Unix
  • MacOS
  • Android
  • IOS
  • Mobile Device Forensics
  • Anomalous User Activity Monitoring
  • Data Classification
  • Incident Response
  • Root Cause Analysis
Soft Skills
  • Clear Communication
  • Confidential Material Handling
  • Stakeholder Collaboration
Certifications & Qualifications
  • SANS Forensics Certifications
  • CHFI
  • GCIH
Industry Keywords
  • ICS/SCADA
  • NERC CIP
  • Cyber Investigations
  • Threat Actor Tactics
  • Evidence Chain of Custody
Tools & Technologies
  • Forensic Tools
  • SIEM Platforms
  • Endpoint Detection Solutions
  • Splunk Query Development
  • Cyber Investigation Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Mid-Level Digital Forensic Examiner
Mid-Level Digital Forensic Examiner

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Digital Forensics Analyst
Digital Forensics Analyst

SAIC • Chantilly (VA)

On-site
USD 100,000 - 130,000
Digital Forensics Analyst
Digital Forensics Analyst

Weiatech, LLC • Tysons (VA)

On-site
USD 70,000 - 90,000
Host Based Analyst III
Host Based Analyst III

DigiFlight, Inc. • Columbia (MD)

On-site
USD 90,000 - 120,000
Digital Forensics Senior Analyst at Gulfstream Savannah, GA
Digital Forensics Senior Analyst at Gulfstream Savannah, GA

Gulfstream • Savannah (GA)

On-site
USD 90,000 - 120,000
Digital Forensics Systems Specialist
Digital Forensics Systems Specialist

NXTKEY CORPORATION • Washington

On-site
USD 80,000 - 120,000
Forensics Technician
Forensics Technician

Consilio LLC • Northern (KY)

Hybrid
USD 65,000 - 95,000
Digital Forensics Examiner
Digital Forensics Examiner

The Amatriot Group • Linthicum (MD)

On-site
USD 134,000 - 165,000
Host Based Systems Analyst - L03
Host Based Systems Analyst - L03

Base One Technologies • Arlington (VA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Digital Forensic Specialist
Digital Forensic Specialist

ALLTECH CONSULTING SVC INC • Troy (MI)

On-site
USD 60,000 - 110,000