Назад
Company hidden
6 часов назад

Lead Cyber Defense Forensics Analyst

Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Cyber Defense Forensics Analyst (Digital Forensics/Cybersecurity): Leading complex digital forensic investigations and supporting incident response and threat hunting in classified government-controlled secure facilities with an accent on host and network forensics, evidentiary handling, and threat analysis. Focus on reconstructing attacks across Windows and Linux environments, producing legally defensible findings, validating forensic tools, and mapping adversary activity to MITRE ATT&CK.

Location: Suitland, Maryland, United States; onsite work is required within a government-controlled secure facility.

Company

hirify.global builds and delivers federal technology using a product-oriented approach focused on speed, ownership, and execution.

What you will do

  • Lead highly complex digital forensic investigations from evidence acquisition through findings documentation in classified facilities.
  • Perform host-based forensics across Windows and Linux, including disk and memory acquisition, artifact recovery, malware triage, and timeline reconstruction.
  • Conduct network forensic analysis using packet captures, NetFlow, and logs to identify lateral movement, exfiltration, and command-and-control activity.
  • Provide forensic analysis for incident response and threat hunting, including IOC extraction and support for containment, eradication, and recovery decisions.
  • Validate forensic tools and new investigation capabilities through Software Testing and Evaluation methods.
  • Produce legally defensible reports and map findings to adversary TTPs using MITRE ATT&CK and other structured frameworks.

Requirements

  • Bachelor’s degree in Computer Science, Digital Forensics, Information Security, or a related field, or equivalent experience.
  • 5–7 years of hands-on experience in digital forensics, incident response, and threat hunting with lead-level technical proficiency.
  • Active Final Top Secret/SCI clearance is required.
  • Onsite work in a government-controlled secure facility is required.
  • Expertise in computer forensics, network defense, system administration, threat analysis, chain of custody, and evidentiary standards.
  • Experience with EnCase, FTK, Autopsy, Volatility, Wireshark, or equivalent tools, plus the NICE Cybersecurity Workforce Framework IN-FOR-002.

Nice to have

  • GCFA, GCFE, EnCE, CFCE, or GCIH certification; current role-based training under NICE IN-FOR-002 is required.
  • GREM, GNFA, or equivalent advanced malware and network forensics credentials.
  • Forensic investigation experience at TS/SCI level in SCIFs or other government-controlled secure facilities.
  • Advanced mobile, cloud, or memory forensics experience.
  • Experience supporting legal proceedings or law enforcement actions and knowledge of anti-forensics tradecraft.

Culture & Benefits

  • Family-focused, collaborative, and innovation-oriented work environment.
  • Medical insurance, including traditional and HSA-eligible plans.
  • Employer-paid dental and vision options, plus employer-sponsored short-term disability, long-term disability, and life insurance.
  • 5% 401(k) company match, paid holidays, PTO accrual, and paid parental leave.
  • Professional development, career growth opportunities, and team and company-wide events.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →