обновлено 1 день назад
Host Forensics Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Host Forensics Analyst (Cybersecurity): Conducting host-based digital forensics and incident response investigations for DHS’s Hunt and Incident Response Team with an accent on forensic data collection, malware analysis, and cyberattack characterization. Focus on coordinating onsite forensic teams, creating technically sound investigative reports, and analyzing computer systems and digital artifacts during incident response engagements.
Location: Arlington, VA; travel to incident response locations in the United States, Territories & Possessions is required
Company
is a small-business IT and cybersecurity contractor supporting federal, state, and local agencies, including DHS’s Hunt and Incident Response Team.
What you will do
- Coordinate data collection and acquisition operations for onsite forensic engagements.
- Provide technical guidance on forensic collection and investigative techniques.
- Plan and direct the inventory, examination, and technical analysis of computer systems and digital artifacts.
- Lead or support preliminary investigations, mentor forensic personnel, and conduct quality assurance reviews.
- Prepare executive summaries and detailed technical reports documenting digital forensics findings.
- Analyze suspected malicious code and communicate forensic methodologies, findings, and engagement updates to stakeholders and leadership.
Requirements
- U.S. citizenship required.
- Active TS/SCI clearance required; ability to obtain DHS Suitability.
- At least 8 years of directly relevant experience in cyber forensic investigations using industry-standard forensic tools.
- Experience creating forensically sound computer-system duplicates, preserving digital assets, and maintaining chain of custody.
- Experience writing cyber investigative reports and analyzing and characterizing cyberattacks.
- Bachelor’s degree in Computer Science, Cybersecurity, Computer Engineering, or a related field; alternatively, a high school diploma with 10+ years of host or digital forensics experience.
Nice to have
- Experience with at least two forensic, network, SIEM, or EDR tools such as EnCase, SIFT, X-Ways, Volatility, Wireshark, Autopsy, Magnet Axiom Cyber, Snort, Splunk, ArcSight, Elastic, CrowdStrike, MDE, or Trellix.
- Proficiency in all-source research.
- Certifications such as GCFA, GCFE, EnCE, CCE, CFCE, or CISSP.
Culture & Benefits
- 95% employer-paid medical, dental, and vision coverage.
- Employer-paid life, short-term disability, and long-term disability coverage.
- 401(k) with company match and profit sharing.
- Flexible Spending Account for dependent and healthcare expenses.
- 11 standard holidays and three weeks of annual leave.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →