JobTarget Logo

Digital Forensics Analyst- HYBRID in at Crest Security Assurance

NewSalary: $140000 - $150000Job Function: Safety
Crest Security Assurance
United States
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

Digital Forensics Analyst (US Citizenship Required)

Conducts advanced digital forensic investigations, malware analysis, and forensic evidence collection across enterprise networks, endpoints, and cloud environments. Supports cybersecurity incident response, insider threat investigations, and threat hunting by identifying malicious activity, reconstructing attack timelines, and determining the scope and impact of security incidents.

Key Responsibilities

  • Conduct digital forensic investigations involving compromised endpoints, servers, networks, cloud services, and enterprise applications to identify evidence of malicious or unauthorized activity.
  • Acquire, preserve, and analyze digital evidence, including disk images, memory captures, system artifacts, event logs, network traffic, and cloud audit records.
  • Utilize forensic tools such as EnCase, FTK, Autopsy, Volatility, Magnet AXIOM, and other approved platforms to conduct evidence collection, examination, and analysis.
  • Perform malware analysis, including static and dynamic analysis, behavioral examination, sandbox execution, and reverse engineering to identify malicious functionality and indicators of compromise (IOCs).
  • Investigate ransomware, credential theft, unauthorized access, insider threats, data exfiltration, lateral movement, and advanced persistent threat (APT) activity.
  • Analyze Windows, Linux, Active Directory, Microsoft 365, Azure, and AWS artifacts to reconstruct adversary activity, establish incident timelines, and determine root causes.
  • Conduct forensic analysis of endpoint telemetry, SIEM alerts, EDR/XDR data, network packet captures, and system logs using Splunk, Microsoft Defender, Wireshark, and related security tools.
  • Perform targeted threat hunting and IOC analysis using MITRE ATT&CK tactics, techniques, and procedures (TTPs) to identify previously undetected compromises.
  • Support incident response teams with forensic evidence, attack-path reconstruction, compromise assessments, and technical recommendations for containment and remediation.
  • Investigate suspected insider threats, unauthorized data access, account misuse, and potential data leakage while maintaining confidentiality and investigative integrity.
  • Maintain forensic evidence integrity, chain-of-custody documentation, secure evidence storage, and repeatable forensic procedures in accordance with NIST SP 800-86 and applicable federal requirements.
  • Develop and maintain forensic SOPs, investigation playbooks, evidence collection procedures, and analysis methodologies.
  • Prepare detailed forensic examination reports documenting investigative methods, evidence, attack timelines, findings, potential impact, and recommended corrective actions.
  • Coordinate with incident response, SOC, threat intelligence, legal, privacy, and Government stakeholders to support investigations, reporting, and post-incident reviews.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Digital Forensics, Computer Science, Information Technology, or a related field.
  • 5+ years of hands-on digital forensics, incident investigation, or digital forensic incident response (DFIR) experience.
  • Demonstrated experience with forensic imaging, memory analysis, malware investigation, evidence preservation, and chain-of-custody procedures.
  • Proficiency investigating Windows, Linux, Microsoft 365, Azure, and AWS environments.
  • Hands-on experience with forensic tools, SIEM platforms, EDR/XDR technologies, and network traffic analysis.
  • Strong knowledge of MITRE ATT&CK, adversary TTPs, forensic artifacts, and investigative reporting.

Preferred Qualifications

  • Experience supporting federal cybersecurity and digital forensic investigations in complex enterprise environments.
  • Experience with malware reverse engineering, memory forensics, insider threat investigations, and cloud forensics.
  • Familiarity with NIST SP 800-86, NIST SP 800-61, FISMA, and federal evidence handling requirements.
  • Experience preparing forensic reports and presenting technical findings to Government leadership.
  • GCFA, GCFE, GNFA, GREM, EnCE, or equivalent digital forensics certification.

Clearance Requirements

Must be a U.S. Citizen; Public Trust required. TS/SCI may be required for designated threat intelligence support activities.

Work Environment

Hybrid role based in Alexandria, VA. Initial 30 days onsite, followed by 2–3 days onsite per week.

Job Location

United States

Frequently asked questions about this position

Apply For This Position

Apply Now