Security Spec Lead - Digital Forensics Analyst
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Summary
The Digital Forensic Analyst investigates and examines digital assets. The position is aligned with AEP’s Cybersecurity Intelligence & Defense organization and Insider Threat team. It is a highly technical role and supports digital investigations utilizing endpoint images, security analytics, and user activity monitoring across a broad range of cybersecurity and IT tools. The analyst also supports programs and policies that reduce internal risk.
The analyst partners with Cyber Incident Responders, HR, Legal, Ethics, Physical Security, and other stakeholders to support data acquisition and analysis. The analyst will document findings, manage cases from initiation to resolution, and communicate technical conclusions in clear business language.
Job Description What You’ll Do Essential Job Functions & TasksConduct end-to-end investigations of internal and external matters.
Prepare findings reports for HR, Legal, Ethics, Physical Security, and other stakeholders
Develop and maintain Digital Forensics policies and procedures documentation
Support risk-reduction projects, including post-incident lessons learned
Serve as a technical SME for Insider Threat, DLP, and cyber investigations
Produce clear investigative and analytic reports for technical and executive audiences
Maintain tools and technologies pertaining to Digital Forensics collection and analysis
Ability to obtain and maintain a U.S. government security clearance
In-depth understanding of Windows, Linux/Unix, MacOS, Android and iOS operating systems and interconnected network devices
Understanding of mobile device forensics and evidence collection techniques
Experience with malware reverse engineering and analysis
Understanding of anomalous user activity monitoring and policy violation investigations
Ability to use internal and external log sources, forensic tools, and established investigative methods to determine incident source and scope
Work independently while maintaining strict confidentiality throughout investigations which sometimes involve high pressure situations or rapidly changing priorities
Communicate clearly, verbally and in writing, with strong analytical and critical-thinking skills
Handle sensitive and confidential material appropriately
Understanding of forensic capture and analysis methodologies and evidence chain of custody procedures
Bachelor’s degree or equivalent experience in cybersecurity, digital forensics, computer science, or related field
Experience with standard forensic methods and leading collection and analysis tools
Deep experience conducting technical investigations or root cause analysis in complex environments
Experience identifying insider risk indicators through analytics tools
Understanding and experience with digital forensics in a cloud environment
Understanding of threat actor tactics, techniques, and procedures
Familiarity with electric utility operations, ICs/SCADA, or critical infrastructure protection frameworks such as NERC CIP
Working knowledge of programming languages and Splunk query development
Ability to apply AI to threat detection and analysis
Understanding and experience with security monitoring tools, SIEM platforms, and endpoint detection solutions
Ability to work and lead in cross-functional environments involving HR, Legal, Compliance, Privacy, and Security teams
Knowledge of cyber investigations and incident response processes
Experience with case management and evidence handling procedures
Experience with data classification, information protection, data loss prevention (DLP), and sensitive data monitoring technologies
SANS Forensics Certifications (Ex. GASF, GCFA, GCFE, GREM, GNFA)
Computer…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).