5 часов назад
Senior Forensic Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Forensic Analyst (Cybersecurity): Conducting independent forensic evaluations of federal enterprise systems suspected of compromise with an accent on host and network analysis, legal chain of custody, and intelligence-community collaboration. Focus on reconstructing attacker activity, producing legally defensible reports, and performing on-site evidence collection during high-priority investigations.
Location: Fort Collins, Colorado; Kansas City, Missouri; or Washington, DC, United States. Travel to government sites and on-site forensic collection may be required.
Company
builds and delivers federal technology using a product-oriented approach focused on speed, ownership, and execution.
What you will do
- Conduct end-to-end forensic evaluations of federal enterprise systems, endpoints, and media suspected of compromise.
- Perform host-based analysis, including disk imaging, file-system examination, artifact recovery, memory analysis, and timeline reconstruction across Windows and Linux.
- Perform network forensic analysis using packet captures, NetFlow, proxy and DNS logs to identify lateral movement, exfiltration, and command-and-control activity.
- Maintain evidence integrity and chain of custody while producing legally defensible reports with findings, methodology, and response recommendations.
- Interface with the intelligence community and coordinate with incident response, threat intelligence, and SOC teams.
- Travel to government sites for on-site evidence collection, system imaging, and forensic analysis.
Requirements
- Bachelor’s degree in Computer Science, Digital Forensics, Information Security, or a related field, or equivalent experience.
- At least 7 years of hands-on digital forensics experience, including complex investigations in federal or law-enforcement environments.
- Active Top Secret clearance required.
- Expertise in host and network forensics, malware triage, attack timeline reconstruction, and forensic analysis of Windows and Linux environments.
- Experience with EnCase, FTK, Autopsy, Volatility, Wireshark, or equivalent tools.
- Ability to work independently on non-repetitive investigations and willingness to travel to government sites as required.
Nice to have
- GCFE, GCFA, EnCE, CFCE, GCIH, or CISSP certification.
- GREM or an equivalent malware-analysis credential.
- TS/SCI clearance or experience in classified network environments.
- Experience with mobile, cloud, or industrial control system forensics.
- Experience supporting law-enforcement actions or legal proceedings with forensic evidence and expert testimony.
Culture & Benefits
- Family-focused culture and a dynamic, productive work environment.
- Medical insurance, including HSA-eligible plans, plus employer-paid dental and vision options.
- Employer-sponsored short-term disability, long-term disability, and life insurance.
- 5% 401(k) company match, paid holidays, PTO, and paid parental leave.
- Flexible schedules, teleworking options, professional development, and career growth opportunities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →