Cyber Forensic Specialist
Listed on 2026-06-06
-
IT/Tech
Cybersecurity, Information Security, Data Security
Overview
At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology and ingenuity for clients across defense, national security, public safety, civilian, and military health organizations.
Join Accenture Federal Services, a technology company within global Accenture. Recognized as a Glassdoor Top 100 Best Place to Work, we offer a collaborative and caring community where you feel like you belong and are empowered to grow, learn and thrive through hands‑on experience, certifications, industry training and more.
We are seeking a skilled and detail-oriented Cyber Forensic Specialist to join our Digital Forensics and Incident Response (DFIR) team. This role is critical in supporting the organization's Cyber Incident Response Team (CIRT) by providing expert-level digital forensic and investigative support. The position also involves working closely with cross‑functional teams, including Human Resources, Legal, and Insider Threat, to conduct sensitive internal investigations related to policy adherence.
TheWork
- DFIR Support:
- Collaborate with the Cyber Incident Response Team (CIRT) to investigate and respond to cybersecurity incidents, including malware infections, unauthorized access, data breaches, and advanced persistent threats (APTs).
- Perform digital forensic analysis on devices such as laptops, desktops, servers, mobile devices, and network logs to identify the root cause and scope of incidents.
- Provide recommendations on containment, remediation, and recovery activities.
- Investigative Support:
- Conduct internal investigations in collaboration with HR, Legal, and Insider Threat teams related to potential risks to organizational assets and operations.
- Analyze electronic communications, file systems, and digital artifacts to uncover evidence.
- Prepare detailed, well‑documented reports and findings to support decision‑making and potential actions.
- Litigation Holds and eDiscovery:
- Partner with Legal to ensure the timely and accurate implementation of litigation holds, identifying, preserving, and collecting electronically stored information (ESI).
- Perform eDiscovery‑related data captures, including on‑premises and cloud‑based systems, in alignment with legal and regulatory requirements.
- Maintain thorough documentation of all eDiscovery activities for legal proceedings and audits.
- Evidence Intake and Management:
- Serve as the central point for evidence intake, ensuring proper chain of custody and documentation for all collected digital evidence.
- Maintain and enforce evidence management protocols, including secure storage, tagging, and tracking for litigation holds and legal proceedings.
- Ensure compliance with data retention and destruction policies.
- Process Optimization and Tooling:
- Leverage forensic tools (e.g., EnCase, FTK, X‑Ways, Magnet Axiom) to analyze and process evidence efficiently.
- Continuously improve and document forensic methodologies, workflows, and playbooks.
- Stay up to date with emerging forensic techniques, tools, and industry best practices.
- Collaboration and Training:
- Provide guidance and training to the CIRT and other internal teams on forensic processes and evidence handling.
- Collaborate with outside counsel or external third‑party forensic services when required.
- US Citizenship required.
- 3-5 years of experience in information security, or other equivalent combination of education or equivalent work experience.
- 3+ years of experience performing digital forensics on physical and cloud systems.
- 2+ years of experience performing event and log analysis including one or more of the following:
Anti‑Virus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security Information and Event Management (SIEM) solutions. - 1+ years of experience investigating, containing, eradicating, and preventing current and future compromises (e.g., implementing or requesting an…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).