Senior Forensic Analyst

Revolutional

Kansas City (MO)

Hybrid

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible schedules
Telework options
Paid holidays & PTO

Job summary

Revolutional is seeking a Senior Forensic Analyst to lead end-to-end forensic evaluations of federal systems suspected of compromise. You will maintain strict chain of custody, perform host and network analyses, and interface directly with the intelligence community to inform investigations.

The role requires a TS clearance, 7+ years of digital forensics experience, and willingness to travel to government sites. Telework options may be available, with local on-site as needed.

Qualifications

  • 7+ years of hands-on digital forensics experience, including investigations in federal or law enforcement environments.
  • Active Top Secret clearance required.
  • Ability and willingness to travel to government sites as required.

Responsibilities

  • Conduct forensic evaluations of federal enterprise systems, endpoints, and media suspected of compromise; apply rigorous methodology and maintain chain of custody throughout in accordance with applicable federal and state law.
  • Perform host-based forensic analysis: disk imaging, file system examination, artifact recovery, memory analysis, and timeline reconstruction.
  • Conduct network forensic analysis: packet capture review, NetFlow analysis, log correlation, and lateral movement identification.
  • Produce thorough, legally defensible forensic reports documenting findings, methodology, evidence handling, and recommended actions.
  • Interface with the intelligence community to share findings and ensure investigations are informed by current threat context.

Skills

Digital forensics
Active TS clearance
Travel readiness

Education

Bachelor’s degree in Computer Science or related field

Tools

EnCase
FTK
Autopsy
Volatility
Wireshark

Job description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.

We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

Senior Forensic Analyst

Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred)

Terms: Full-time

Clearance: Active Top Secret required

Salary Range: $130-170k DOE

Travel: Yes – travel to government sites as required

Project Description

This position supports a large-scale federal security operations program responsible for protecting enterprise networks, detecting and responding to intrusions, and conducting forensic investigations of suspected compromises. Forensic evaluations on this program are non-repetitive, fixed-duration engagements — each one is unique, consequential, and conducted under legal chain of custody requirements.

The core challenge: conducting rigorous forensic evaluations of federal systems suspected of compromise — independently, under legal and evidentiary standards, with findings that inform both immediate response and broader intelligence community awareness.

Position Description

As a Senior Forensic Analyst at Revolutional, you conduct forensic evaluations of federal enterprise systems suspected of compromise. You are a senior practitioner operating with a high degree of independence — each engagement is distinct, and you bring the expertise to scope, execute, and deliver findings without a playbook written specifically for the situation in front of you.

You maintain strict chain of custody in accordance with applicable federal and state legal requirements, conduct both host and network analysis to determine the full extent of compromise, and interface directly with the intelligence community to share and receive context that sharpens your findings. You may travel to government sites as required to support on-site forensic collection and analysis.

What You Will Own
  • End-to-end forensic evaluation of federal systems suspected of compromise
  • Chain of custody integrity across all evidence collected and handled
  • Host and network analysis to determine compromise scope and attacker activity
  • Intelligence community interface and information sharing on active investigations
  • Forensic project support across program-directed engagements
  • On-site forensic collection and analysis at government facilities as required
Responsibilities
  • Conduct forensic evaluations of federal enterprise systems, endpoints, and media suspected of compromise; apply rigorous methodology and maintain chain of custody throughout in accordance with applicable federal and state law
  • Perform host-based forensic analysis: disk imaging, file system examination, artifact recovery, memory analysis, and timeline reconstruction to determine attacker activity and compromise extent
  • Conduct network forensic analysis: packet capture review, NetFlow analysis, log correlation, and lateral movement identification to establish the full scope of intrusion activity
  • Produce thorough, legally defensible forensic reports documenting findings, methodology, evidence handling, and recommended response actions
  • Interface with the intelligence community to share forensic findings, receive relevant threat context, and ensure investigations are informed by the current intelligence picture
  • Support forensic projects as directed by program leadership, including surge support for high-priority or time-sensitive investigations
  • Travel to government sites as required to conduct on-site evidence collection, system imaging, and forensic analysis
  • Maintain current awareness of adversary TTPs, malware families, and forensic evasion techniques relevant to the federal threat landscape
  • Contribute to development and refinement of forensic procedures, evidence handling standards, and investigation methodologies
  • Coordinate with incident response, threat intelligence, and SOC teams to ensure forensic findings drive timely and effective response actions
What You Bring (Requirements)
  • Bachelor’s degree in Computer Science, Digital Forensics, Information Security, or related field (or equivalent experience)
  • 7 or more years of hands‑on digital forensics experience, including complex investigations of suspected system compromises in federal or law enforcement environments
  • Demonstrated experience maintaining chain of custody in accordance with federal and state legal requirements
  • Active Top Secret clearance required
  • Ability and willingness to travel to government sites as required
Technical & Domain Capabilities
  • Expert-level host forensics: disk and memory acquisition, file system analysis, artifact recovery, malware triage, and attack timeline reconstruction across Windows and Linux environments
  • Hands‑on network forensics: packet capture analysis, NetFlow, proxy and DNS log review, and identification of lateral movement, exfiltration, and command‑and‑control activity
  • Proficiency with industry‑standard forensic tools: EnCase, FTK, Autopsy, Volatility, Wireshark, or equivalent
  • Experience conducting non‑repetitive, fixed‑duration forensic evaluations independently with minimal direction
  • Established working relationships or experience interfacing with the intelligence community in the context of cybersecurity investigations
  • Understanding of attacker TTPs, kill‑chain methodology, and MITRE ATT&CK framework as applied to forensic investigations
  • Experience producing forensic reports that meet legal and evidentiary standards for federal proceedings
Core Strengths
  • Technically expert and analytically independent — you scope and execute complex forensic investigations without needing the situation pre‑defined for you
  • Legally disciplined: chain of custody, evidence integrity, and documentation rigor are non‑negotiable to you
  • Credible intelligence community partner — you share findings with precision and incorporate external context effectively
  • Composed under operational pressure; fixed‑duration engagements with real consequences don’t rattle your methodology or your output quality
Preferred Certifications
  • GCFE or GCFA (GIAC Forensics), EnCE (EnCase Certified Examiner), CFCE (Certified Forensic Computer Examiner), GCIH, or CISSP
Nice to Have (Differentiators)
  • GREM (GIAC Reverse Engineering Malware) or equivalent malware analysis credential
  • Experience conducting forensic investigations at the TS/SCI level or within classified network environments
  • Active TS/SCI clearance
  • Prior direct experience working with or embedded in an intelligence community organization
  • Background in mobile device forensics, cloud forensics, or industrial control system (ICS) forensics
  • Experience supporting law enforcement actions or legal proceedings with forensic evidence and expert testimony
Benefits
  • Traditional and HSA‑eligible medical insurance plans
  • 100% employer‑paid dental and vision insurance options
  • 100% employer‑sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible‑schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental Leave
  • Professional development and career growth opportunities
  • Team and company‑wide events, recognition, and appreciation

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Cyber Defense Forensics Analyst
Lead Cyber Defense Forensics Analyst

Revolutional • Suitland (MD)

On-site
USD 110,000 - 150,000
Medical insurance
Dental and vision insurance
STD, LTD, and life insurance
+6
Senior Threat Hunter Analyst
Senior Threat Hunter Analyst

Revolutional • Kansas City (MO)

Hybrid
USD 125,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+3
Cyber Intelligence Analyst
Cyber Intelligence Analyst

Harmonia Holdings Group, LLC • Fort Collins (CO)

Hybrid
USD 90,000 - 130,000
Lead Cyber Threat Intelligence Analyst
Lead Cyber Threat Intelligence Analyst

Revolutional • Suitland (MD)

On-site
USD 130,000 - 180,000
Medical insurance
Dental and vision insurance
401(k) matching
+2
Senior Threat Hunter
Senior Threat Hunter

Revolutional • Washington

On-site
USD 135,000 - 175,000
Medical insurance
Dental and vision insurance
401(k) matching
+2
Program Manager
Program Manager

Revolutional • Kansas City (MO)

Hybrid
USD 165,000 - 220,000
Medical insurance
Dental and vision insurance
401(k) 5% match
+3
SOC Operations Manager
SOC Operations Manager

Revolutional • Kansas City (MO)

Hybrid
USD 150,000 - 190,000
Medical insurance
Dental & Vision
STD/LTD/Life insurance
+6
Lead Penetration Tester
Lead Penetration Tester

Revolutional • Kansas City (MO)

On-site
USD 110,000 - 150,000
Medical insurance
Dental/vision insurance
STD/LTD/Life insurance
+5
Technical Support Analyst (Tier II)
Technical Support Analyst (Tier II)

Revolutional • Washington

On-site
USD 75,000 - 95,000
Medical insurance
Dental and vision insurance
STD/LTD and life insurance
+3
Senior Cybersecurity Technical Advisor
Senior Cybersecurity Technical Advisor

Revolutional • Martinsburg (IN)

Hybrid
USD 180,000 - 200,000
Medical insurance
Dental and vision insurance
STD/LTD/Life insurance
+6