Digital Forensics Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Digital Forensics Engineer (Cybersecurity): Providing advanced digital forensics, incident response, and cyber investigation services for the SBA Enterprise Cybersecurity Services program with an accent on evidence preservation, malware analysis, and e-discovery. Focus on conducting complex forensic examinations across cloud, mobile, and enterprise environments to identify indicators of compromise and reconstruct attack timelines.
Location: Must be based in the United States (SBA Federal Program)
Company
provides specialized cybersecurity and IT services to federal government agencies.
What you will do
- Perform advanced digital forensic analysis and investigations for cybersecurity incidents, insider threats, and unauthorized access.
- Collect and preserve digital evidence in accordance with federal forensic standards and strict chain-of-custody procedures.
- Analyze endpoint telemetry, security logs, and network packet captures (PCAP) to identify indicators of compromise (IOCs).
- Conduct malware analysis and reverse engineering to identify malicious behaviors and command-and-control communications.
- Support e-discovery operations, including the collection, indexing, and processing of electronically stored information (ESI).
- Develop technical forensic reports and provide executive briefings and remediation recommendations.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Digital Forensics, or a related discipline.
- Minimum of 8 years of experience in digital forensics, incident response, or SOC environments.
- Hands-on expertise with forensic tools such as EnCase, FTK, X-Ways, Velociraptor, or Volatility.
- Proficiency in analyzing forensic artifacts across Windows, Linux, cloud, and mobile platforms.
- Strong understanding of NIST cybersecurity standards, specifically SP 800-61 and SP 800-86.
- Ability to present complex investigative findings to both technical and executive stakeholders.
Nice to have
- Relevant certifications: GCFA, GNFA, GCIH, EnCE, CCE, CEH, CySA+, Security+, or CISSP.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →