Digital Forensics Examiner
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Digital Forensics Examiner
Job Location s: US-MD-Bethesda
Job DetailsRequisition
Position Category Cyber Security
Clearance Top Secret/SCI w/Poly
ResponsibilitiesPeraton is seeking an experienced and highly skilled Senior Digital Forensics Examiner to join our specialized team in Bethesda, MD in support of our Department of War (DoW) customer. The ideal candidate will conduct comprehensive forensic examinations on a diverse range of digital media, including hard drives, mobile devices, and removable media. You will serve as a subject matter expert, responsible for the entire lifecycle of digital evidence from acquisition to reporting.
This role requires a meticulous and analytical mindset, coupled with the ability to convey complex technical findings to both technical and non-technical audiences.
- Conduct forensically sound examinations of digital and mobile devices (including computers, smartphones, and tablets) to support investigative requirements.
- Utilize industry-standard forensic tools and advanced techniques to perform data extraction, recovery, and in-depth analysis of file systems, operating systems (Windows, macOS, Linux, iOS, Android), and application data.
- Perform comprehensive analysis, including timeline generation, file signature and hash analysis, email and communication analysis, and examination of large, complex datasets.
- Identify and analyze malware and evidence of intrusion or unauthorized activity.
- Prepare detailed, clear, and concise technical reports documenting examination procedures, findings, and expert opinions for a variety of audiences.
- Perform peer reviews of forensic reports to ensure technical accuracy, completeness, and adherence to established standards.
- Maintain strict chain of custody for all digital evidence and associated documentation.
- Provide expert consultation to stakeholders on Tactics, Techniques, and Procedures (TTPs) for digital evidence handling and forensic examinations.
- Stay abreast of the latest developments in digital forensics technology, trends, and methodologies to ensure the use of current best practices.
- Proven proficiency with industry-standard forensic tool suites (e.g., EnCase, FTK, Magnet AXIOM, X-Ways Forensics, Autopsy).
- Demonstrated mobile forensics experience extracting and parsing iOS and Android devices using tools such as Cellebrite UFED/Physical Analyzer or Gray Key.
- Working knowledge of file systems and structures (NTFS, FAT
32, exFAT, EXT3/4, APFS, HFS+). - Demonstrated ability to identify full-disk, volume, and file-level encryption and evaluate appropriate key extraction or decryption workflows.
- In-depth knowledge of cryptographic hashing algorithms (MD5, SHA-1, SHA-256) and their practical forensic application for data integrity verification and identifying known threat artifacts.
- Experience conducting static and behavioral triage of malicious files (e.g., string analysis, header analysis, sandbox execution) to support forensic attribution.
- Strong technical writing and briefing capabilities, with experience authoring formal forensic reports.
- Must possess an active Top Secret/SCI security clearance with a Polygraph.
- Current DoD 8570/8140 IAT Level II certification (e.g., CompTIA Security+, CySA+, GICSP).
- Minimum of 8 years with BS/BA;
Minimum of 6 years with MS/MA;
Minimum of 3 years with PhD. A degree in one of the following fields is highly desired:
Cybersecurity, Computer Science, Information Systems, Information Technology, Mathematics, Data Science, or Software Engineering. However, an additional four years of experience may be considered in lieu of a bachelor's degree.
- Advanced industry certifications, such as:
- GIAC Certified Forensic Examiner (GCFE) or Analyst (GCFA)
- GIAC Advanced Smartphone Forensics (GASF)
- Cellebrite Certified Mobile Examiner (CCME)
- EnCase Certified Examiner (EnCE)
- Access Data Certified Examiner (ACE)
- Certified Forensic Computer Examiner (CFCE)
- Proficiency in programming or scripting languages (e.g., Python, Power Shell) to automate forensic workflows, parse novel artifacts, and process bulk data.
- Prior experience working within the Intelligence Community (IC).
- Demonstrated experience authoring finished intelligence reports and assessments.
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).