Cyber Forensic Specialist
Core
Conduct digital forensic analysis and internal investigations for US federal government clients, supporting incident response, litigation holds, and evidence management.
Role type
Cyber Forensic Specialist (DFIR & eDiscovery)
Builds
Forensic reports, evidence preservation, incident response playbooks, and legal evidence production.
Domain
US Federal Government / Cybersecurity & Digital Forensics
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Digital forensics on physical and cloud systems, event and log analysis, malware analysis, eDiscovery (ESI collection), chain of custody management, network protocol analysis, static and dynamic malware analysis, scripting for automation
Preferred skills
DFIR certifications (SANS, CFCE), eDiscovery toolsets (Microsoft Purview, Nuix), Python/PowerShell scripting
Technologies
EnCase, FTK, X-Ways, Magnet Axiom, Cellebrite, Autopsy, Nuix, Microsoft Purview eDiscovery, SIEM, Active Directory, TCP/IP
Responsibilities
Investigate and respond to cybersecurity incidents (malware, breaches, APTs), perform digital forensic analysis on devices and logs, conduct internal investigations with HR/Legal, execute litigation holds and eDiscovery data captures, manage evidence intake and chain of custody, optimize forensic workflows and tools
Seniority
Mid-level, hands-on IC