Senior Cyber Forensic Analyst
Listed on 2026-09-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Who we are:
ShorePoint is a fast-growing, industry-recognized and award-winning cybersecurity services firm focused on high-profile, high-threat public and private sector customers who demand experience and proven security models to protect their data. We embrace a “work hard, play hard” mentality and celebrate individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers, while fostering an environment that supports creativity, accountability, mission success, critical thinking and a desire to give back to our community.
ThePerks:
As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individual’s technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, major carriers for healthcare providers.
Highlighted benefits include 144 hours of PTO, 11 holidays, 85% of insurance premiums covered, a 401(k), continuing education, certification maintenance and reimbursement and more.
We are seeking an experienced Senior Cyber Forensic Analyst to lead advanced digital forensics analysis and incident response support across complex enterprise environments. This role will support threat hunting, incident triage, forensic analysis, continuous monitoring, vulnerability analysis, defensive exercises and cyber performance metrics while producing defensible findings that inform containment, eradication, recovery, risk decisions and corrective actions. The ideal Sr. Cyber Forensic Analyst candidate will bring deep experience collecting, preserving, analyzing and reporting digital evidence, reconstructing cyber events and translating technical findings into timely, actionable information for government stakeholders, incident response personnel, Information System Security Officers (ISSOs) and Federal technical leads.
This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market. Employment for this position is dependent on the successful award of the contract for a potential opportunity
- Lead and perform advanced digital forensic examinations involving endpoint, server, network, cloud, application, removable-media and log-data sources in support of suspected or confirmed cybersecurity incidents.
- Collect, preserve, validate, analyze and document digital evidence using sound forensic practices while maintaining evidentiary integrity, chain-of-custody records and reproducible analysis methods.
- Reconstruct incident timelines and identify initial access, attacker activity, persistence, lateral movement, data access or exfiltration indicators, affected assets and potential mission or system impacts.
- Lead forensic support for complex incident response activities, including scoping, triage, containment recommendations, eradication and recovery validation, post-incident reporting and lessons learned.
- Conduct proactive threat-hunting activities using endpoint, network, identity and security-event data and develop and refine hypotheses based on threat intelligence, observed behaviors and environmental risk.
- Analyze security alerts, logs, malware artifacts, suspicious files, authentication events and network activity to identify indicators of compromise, tactics, techniques and procedures and detection or monitoring gaps.
- Produce clear technical reports, executive-ready summaries, evidence packages, incident timelines, hunt reports and recommended corrective actions for cybersecurity leadership, government stakeholders, ISSOs, Federal Information Systems Security Engineers (ISSEs) and other authorized personnel.
- Coordinate with ISSOs to ensure relevant incident, forensic, vulnerability and monitoring findings are reflected in risk assessments, security documentation, continuous-monitoring artifacts, authorization evidence and Plans of Action and Milestones (POA&M) records.
- Support vulnerability assessment and defensive-exercise activities by analyzing results, validating operational impact, identifying detection and response gaps and documenting corrective-action recommendations.
- Contribute to continuous-monitoring, incident, hunting,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).