Digital Forensics Analyst SME
Listed on 2026-10-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Serve as a key member of a 24x7x365 Security Operations Center and Incident Response team, responsible for conducting evidence collection, forensic analysis, data recovery, and reporting in response to incident investigations. The role performs hands‑on digital forensics activities such as forensic imaging, analysis of physical and virtual drives, and incident documentation while leveraging FRED’s and forensic tools to capture and preserve evidence for security events.
The analyst contributes to the development forensics playbooks and standard operating procedures, conducts ad‑hoc forensic analysis, and supports the SOC with investigating security events. This position collaborates closely with federal stakeholders, communicates findings to technical and non‑technical audiences, and produces high‑quality reports and briefings, all while helping to advance the maturity and effectiveness of the organization’s security operations. Join us.
The world can't wait.
- 5+ years of experience in a Security Operations Center (SOC) providing forensic analysis, imaging, log and evidence analysis or preservation, chain-of-custody, incident documentation, and coordination with Federal stakeholders
- Experience analyzing and responding to forensic security requests across enterprise host including Linux, Windows, or macOS and network‑based platforms
- Experience developing or contributing to evidence collection, examination, and chain-of‑custody documentation or standard operating procedures
- Experience using Splunk SIEM platform to support investigations and evidence enrichment
- Experience using a forensic recovery of evidence device (FRED) to collect, store, and maintain forensic images
- Ability to analyze and correlate data from multiple technical sources to identify malicious activity, artifacts, indicators, or investigative leads
- Ability to communicate clearly with both technical and non-technical audiences, including the production of high‑quality incident reports, briefings, and technical documentation
- Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements
- Bachelor's degree
- Experience using industry forensic suites and toolsets such as EnCase, FTK, X-Ways, Cellebrite, Autopsy, KAPE, or Velociraptor
- Experience performing volatile memory acquisition and analysis
- Experience with cloud forensics methodologies such as AWS, Azure, or GCP including log acquisition and artifact preservation
- Experience with federal security controls such as NIST 800‑53, RMF, or FedRAMP and impact on investigative activities
- Ability to build strong client relationships, collaborate across varied teams, and communicate complex technical concepts in a clear, inclusive manner
- Experience with malware analysis and reverse engineering DFIR
- Certifications such as GIAC, GCFA, GCFE, GCIH, CFCE, IACIS, and EnCase EnCE Certifications
Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client;
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well‑being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work‑life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full‑time and part‑time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs.
Individuals that do not meet the threshold…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).