Digital Forensics and Incident Analyst (TS)

Agile Defense
Washington
Workplace: HybridFull timeFunction: CybersecurityExperience: 7+ yearsEducation: bachelorsSkills: ["Technical writing","Risk management","Analytical thinking","Evidence handling","Clear communication"]

Support the Threat Analysis & Investigations (TA&I) function by analyzing digital evidence and investigating computer security incidents to enable system and network vulnerability mitigation. Provide Tier 2/3 support to the enterprise SOC, coordinate with partner security operations centers, and perform Tiered forensic work aligned to the NICE Framework. Execute dynamic analysis, malware and file system investigations, maintain chain of custody, and deliver technical reports to authorized requesting authorities.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Agile Defense
Agile Defense
2 months ago

Digital Forensics and Incident Analyst (TS)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 2 hours agoStatus: Live

Job Summary

Support the Threat Analysis & Investigations (TA&I) function by analyzing digital evidence and investigating computer security incidents to enable system and network vulnerability mitigation. Provide Tier 2/3 support to the enterprise SOC, coordinate with partner security operations centers, and perform Tiered forensic work aligned to the NICE Framework. Execute dynamic analysis, malware and file system investigations, maintain chain of custody, and deliver technical reports to authorized requesting authorities.
Location: Washington
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Analyze log files, evidence, and other information to determine best methods for identifying perpetrators of network intrusions.
  • •Perform dynamic analysis to confirm known intrusion details and discover new information.
  • •Examine recovered data and conduct file signature and file system forensic analysis (NTFS, FAT, EXT).
  • •Collect and analyze intrusion artifacts (e.g., source code, malware, system configuration) and perform malware analysis to identify adversary TTPs.
  • •Maintain chain of custody while supporting the evidence lifecycle and provide technical summaries/reports aligned to established procedures.

Key Requirements

  • •U.S. citizenship and an active Top Secret (TS) security clearance.
  • •7 years of hands-on digital forensics and incident response (DFIR) experience, ideally in federal or regulated environments.
  • •Bachelor's degree in Cybersecurity, Computer Science, Digital Forensics, Information Systems, or a related field (additional experience may substitute).
  • •Required certifications: CFIA and CFIH.
  • •Expertise with forensic and analysis tools (e.g., EnCase, FTK, Autopsy/The Sleuth Kit, X-Ways, Volatility, Wireshark, YARA, and malware reverse-engineering tools like Ghidra or IDA Pro).
Experience:7+ yearsFederalCybersecurityIncident responseDigital forensics
Education:Bachelor's in Cybersecurity, Computer Science, Digital Forensics, Information Systems, or a related field
Skills:Technical writingRisk managementAnalytical thinkingEvidence handlingClear communication
Certifications:CFIACFIH
Tech Stack:NICE FrameworkNISTMITRE ATT&CKEnCaseFTKAutopsy/The Sleuth KitX-WaysVolatilityWiresharkYARAGhidraIDA ProNTFSFATEXTHyper-VVMware vSphereCitrix XenAmazon EC2SIEM

Eligibility

Security Clearance:Top Secret (TS)

Company Brief

Agile Defense
Provides cybersecurity services including managed detection and response, incident response, vulnerability assessments, and security operations to help organizations detect, respond to, and remediate cyber threats while meeting regulatory and compliance requirements.
Industry: Cybersecurity
Website