×
Register Here to Apply for Jobs or Post Jobs. X

Digital Forensics and Incident Analyst; TS

Job in Washington, District of Columbia, 20022, USA
Listing for: Agile Defense
Full Time position
Listed on 2026-09-17
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 120000 - 160000 USD Yearly USD 120000.00 160000.00 YEAR
Job Description & How to Apply Below

Digital Forensics and Incident Analyst

Location: Onsite, Washington, DC Clearance: Top Secret

Description

The Digital Forensics & Incident Analyst supports the Threat Analysis & Investigations (TA&I) function, analyzing digital evidence and investigating computer security incidents to derive information that supports system and network vulnerability mitigation. The analyst provides Tier 2 and Tier 3 support to the enterprise Security Operations Center (SOC) and coordinates with partner/enterprise security operations centers as required for incident response and advanced analysis.

Aligned to the NICE Framework, the role identifies, collects, examines, and preserves digital evidence using controlled and documented analytical and investigative techniques in support of authorized requesting authorities — including oversight bodies, legal and general counsel offices, professional‑responsibility offices, FOIA requests, and law enforcement partners. The analyst conducts digital analysis in response to investigations of computer‑based crimes and cyber‑intrusion incidents, leveraging enterprise forensic and live‑monitoring tools while rigorously maintaining chain of custody.

Incoming requests are logged into a case‑management application, and the analyst performs the analytical function supporting the appropriate authorities.

Essential Functions
  • Analyze log files, evidence, and other information to determine the best methods for identifying the perpetrator(s) of a network intrusion. (T0027)
  • Confirm what is known about an intrusion and discover new information via dynamic analysis. (T0036)
  • Provide technical summaries of findings in accordance with established reporting procedures, and deliver written analysis reports to requesting customers. (T0075)
  • Examine recovered data for information relevant to the matter at hand. (T0103)
  • Perform file signature analysis (T0167) and file system forensic analysis across implementations such as NTFS, FAT, and EXT. (T0286)
  • Collect and analyze intrusion artifacts (e.g., source code, malware, system configuration) and use discovered data to enable mitigation of potential cyber defense incidents. (T0432)
  • Conduct malware analysis in the event of a compromise, identify obfuscation techniques, and interpret debugging results to ascertain adversary tactics, techniques, and procedures.
  • Determine the extent of threats and recommend courses of action or countermeasures to mitigate risk; analyze crises to ensure public, personal, and resource protection.
  • Identify data concealment methods (e.g., encryption algorithms, steganography) and conduct memory dumps to extract information.
  • Conduct security event analysis and correlation using enterprise tooling, and apply network security architecture concepts (topology, protocols, components, defense‑in‑depth) to forensic analysis.
  • Determine physical computer components and architectures, conduct physical disassembly of systems, and identify/modify/manipulate system components within Windows, Unix, or Linux (e.g., passwords, user accounts, files).
  • Apply system administration, network, and operating‑system hardening techniques, and use virtual machines (e.g., Hyper‑V, VMware vSphere, Citrix Xen, Amazon EC2) in the course of analysis.
  • Conduct hashing for chain‑of‑custody and validation (e.g., SHA, MD5) and preserve evidence integrity according to standard operating procedures or national standards.
  • Support the full evidence lifecycle — collecting, packaging, transporting, and storing electronic evidence while maintaining chain of custody — and interpret insider‑threat investigations, reporting, tools, and applicable laws/regulations.
  • Provide legal governance related to admissibility (e.g., Rules of Evidence) and advise on applicable laws and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary