Digital Forensic Analyst
$100kKoniag Government Services
This position may be filled prior to the posted deadline. Interested candidates are encouraged to apply as soon as possible.
Koniag Operations Services, LLC (KOS), a Koniag Government Services company, is seeking an experienced Digital Forensics Analyst to support cybersecurity operations and incident response activities for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at the time of offer. Primary work will be performed at the client site in Washington, DC, and approved remote/telework locations.
Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits, and tuition reimbursement.
This role serves as a critical technical function responsible for the collection, preservation, examination, and analysis of digital evidence in support of cybersecurity incident investigations, insider threat inquiries, litigation holds, and other forensic examination requirements across a complex, geographically distributed federal IT enterprise environment.
The ideal candidate is a technically proficient and detail-oriented forensics professional with deep expertise in digital forensics methodologies, forensic tool suites, incident response procedures, and chain of custody requirements within a federal government context. This individual must possess the analytical rigor, technical depth, and professional judgment required to conduct thorough, defensible forensic examinations across a diverse range of digital media, operating systems, cloud environments, and enterprise platforms.
The Digital Forensics Analyst will serve as the program's primary technical expert for all digital forensics activities, supporting cybersecurity incident investigations, insider threat inquiries, e-discovery and litigation hold support, malware analysis, and forensic examination of digital media across a complex federal enterprise IT environment. This individual is responsible for ensuring all forensic activities are conducted in accordance with established forensic methodologies, chain of custody requirements, applicable Federal regulations, and client policies, producing thorough, well-documented, and legally defensible forensic examination reports and evidentiary findings.
Principal responsibilities will include but are not limited to:
Digital Forensics Examination & Analysis
Conduct comprehensive digital forensic examinations of a wide range of digital media and platforms, including hard drives, solid-state drives, removable media, mobile devices, network devices, servers, virtual machines, and cloud environments (e.g., AWS, Microsoft Azure/Microsoft 365).
Perform forensic acquisition of digital evidence using industry-standard forensic imaging tools and techniques, ensuring the integrity and admissibility of all acquired evidence through proper application of write-blocking, hashing, and chain of custody procedures.
Analyze acquired forensic images for relevant artifacts, including deleted files, file system metadata, registry entries, event logs, browser history, email artifacts, user activity records, network connection logs, and other evidentiary data relevant to the investigation.
Conduct memory forensics, including volatile memory acquisition and analysis, to identify running processes, network connections, injected code, encryption keys, and other artifacts not present in disk-based evidence.
Perform log analysis and correlation across endpoint, network, application, and cloud platform log sources to reconstruct timelines of activity, identify indicators of compromise (IOCs), and support investigation findings.
Conduct static and dynamic malware analysis to identify malicious code capabilities, behaviors, command-and-control infrastructure, persistence mechanisms, and indicators of compromise associated with investigated incidents.
Analyze network traffic captures (PCAPs) and network flow data to identify malicious activity, data exfiltration, unauthorized access, lateral movement, and other network-based indicators relevant to active investigations.
Perform mobile device forensics, including logical and physical acquisition and analysis of iOS and Android devices, recovering relevant communications, application data, location history, and user activity artifacts.
Conduct cloud forensics activities across enterprise cloud environments, including the collection and analysis of cloud audit logs, storage artifacts, identity and access management records, and other cloud-native evidence sources.
Support e-discovery and litigation hold activities, including the identification, preservation, collection, and processing of electronically stored information (ESI) in accordance with applicable legal requirements and client policies.
Incident Response Support
Serve as the forensics subject matter expert within the incident response team, providing timely and expert forensic support across all phases of the incident response lifecycle, from initial detection and containment through eradication, recovery, and post-incident review.
Respond to cybersecurity incidents requiring forensic investigation, deploying forensic capabilities rapidly to collect and preserve volatile and non-volatile evidence before it is lost or altered.
Conduct forensic triage of affected systems and environments to rapidly characterize the scope, nature, and impact of security incidents, providing actionable intelligence to incident response and operations teams in support of containment and eradication decisions.
Develop and maintain incident-specific forensic timelines, reconstructing the sequence of attacker or insider actions from available evidence to support root cause analysis, impact assessment, and lessons learned activities.
Coordinate with the NOC, Security Operations Center (SOC), and other functional teams to ensure forensic activities are integrated effectively into the broader incident response process.
Support post-incident review activities, providing forensic findings, timeline reconstructions, and evidentiary analysis to inform root cause determinations and corrective action recommendations.
Evidence Handling & Chain of Custody
Establish, maintain, and enforce rigorous chain of custody procedures for all digital evidence collected, processed, and stored under the program, ensuring all evidence handling activities are documented in accordance with applicable legal and regulatory requirements.
Maintain accurate and complete evidence logs, documenting the acquisition, transfer, storage, examination, and disposition of all digital evidence items throughout their lifecycle.
Ensure all digital evidence is stored securely in accordance with applicable client policies, Federal regulations, and evidence handling best practices, protecting evidence integrity and preventing unauthorized access, alteration, or destruction.
Support the preparation and organization of digital evidence for submission to law enforcement, legal counsel, or other authorized parties as directed by the Government.
Forensic Reporting & Documentation
Prepare comprehensive, well-structured, and legally defensible forensic examination reports documenting examination scope, methodologies, tools used, findings, evidence items, and conclusions for each completed forensic investigation.
Develop and maintain forensic case files, ensuring all examination notes, tool output, evidence logs, chain of custody records, and supporting documentation are organized, complete, and accessible throughout the investigation lifecycle.
Present forensic findings clearly and effectively to diverse audiences, including program leadership, Government stakeholders, legal counsel, and, where required, law enforcement or investigative authorities, translating complex technical findings into clear, actionable narratives.
Develop and maintain forensic process documentation, standard operating procedures, and examination templates to ensure consistency, repeatability, and quality across all forensic examination activities.
Contribute forensic findings and indicators of compromise to the program's threat intelligence repository, supporting broader detection, prevention, and response capabilities.
Tool Management & Capability Development
Maintain and administer the program's forensic tool suite, ensuring all forensic tools and platforms are properly licensed, configured, updated, and validated for operational use.
Stay current with emerging digital forensics techniques, tools, threat actor tactics, techniques, and procedures (TTPs), and evolving evidentiary standards, incorporating new capabilities and methodologies into the program's forensic practice as appropriate.
Develop and maintain custom scripts, queries, and analysis frameworks to enhance forensic examination efficiency, automate repetitive analysis tasks, and extend forensic coverage across diverse evidence types and platforms.
Support the development and delivery of forensic awareness training and knowledge transfer activities for program personnel and Government stakeholders as directed.
Evaluate and recommend new forensic tools, platforms, and capabilities to enhance the program's forensic examination capabilities in response to evolving threats and client requirements.
Compliance & Regulatory Adherence
Ensure all digital forensics activities are conducted in full compliance with applicable Federal statutes, regulations, and client policies, including FISMA, NIST SP 800-53, NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response), applicable privacy laws, and Federal Rules of Evidence requirements.
Support compliance with applicable cybersecurity frameworks and requirements, including NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, and client-specific cybersecurity policies.
Ensure all forensic activities involving personally identifiable information (PII), protected health information (PHI), CUI, or other sensitive data categories are conducted in accordance with applicable privacy protection requirements and data handling restrictions.
Support audit readiness activities by maintaining organized, complete, and accessible forensic case documentation and compliance evidence files.
Education and Experience:
Required:
Bachelor's degree in Computer Science, Cybersecurity, Digital Forensics, Information Technology, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience may be considered.
Minimum of 5 years of hands-on experience in digital forensics, cybersecurity incident response, or a closely related discipline within a federal government IT contracting or law enforcement environment.
Demonstrated hands-on experience conducting forensic examinations of Windows and Linux-based systems, including disk forensics, memory forensics, log analysis, and forensic timeline reconstruction.
Experience conducting forensic investigations in cloud environments, including Microsoft 365, Azure, or AWS.
Experience maintaining chain of custody and producing legally defensible forensic examination reports suitable for submission to legal or law enforcement authorities.
Active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations. Specific clearance requirements will be confirmed at time of offer.
Preferred:
Prior experience supporting digital forensics and incident response on a federal IT program of comparable scale and complexity.
Experience conducting mobile device forensics, network forensics, and/or malware analysis in support of federal cybersecurity investigations.
Experience supporting e-discovery and litigation hold activities in a federal government context.
Required Skills and Competencies:
Exceptional analytical and critical thinking skills with demonstrated ability to conduct thorough, methodical, and well-documented forensic examinations across a diverse range of digital evidence types, platforms, and investigation scenarios.
Deep technical proficiency with industry-standard digital forensics tools, including one or more of the following: Magnet AXIOM, EnCase, FTK (Forensic Toolkit), Cellebrite UFED, Volatility, Autopsy, X-Ways Forensics, or equivalent platforms.
Strong proficiency in forensic acquisition techniques, including disk imaging, memory acquisition, network traffic capture, and cloud evidence collection, with demonstrated ability to ensure evidence integrity through proper hashing and write-blocking procedures.
Demonstrated experience in Windows forensic artifact analysis, including NTFS file system forensics, Windows registry analysis, Windows event log analysis, prefetch and LNK file analysis, and browser artifact examination.
Experience with Linux and/or macOS forensic artifact analysis, including file system forensics, log analysis, and user activity reconstruction.
Proficiency in memory forensics, including volatile memory acquisition and analysis using tools such as Volatility or equivalent platforms.
Experience with log analysis and correlation across diverse log sources, including Windows event logs, Sysmon, network device logs, web server logs, and cloud platform audit logs.
Familiarity with malware analysis techniques, including static analysis (e.g., PE analysis, string extraction, YARA rule development) and dynamic analysis (e.g., sandbox execution and behavioral analysis).
Experience with network forensics, including PCAP analysis using tools such as Wireshark or equivalent platforms, and network flow analysis for investigation support.
Knowledge of cloud forensics techniques and evidence sources across Microsoft 365 (e.g., Unified Audit Log, Exchange Online, SharePoint, Teams), Azure, and/or AWS environments.
Strong chain of custody documentation skills with demonstrated ability to maintain accurate and complete evidence logs and produce professionally formatted, legally defensible forensic examination reports.
Excellent written and verbal communication skills with the demonstrated ability to present complex technical forensic findings clearly and accurately to diverse audiences including program leadership, Government stakeholders, and legal counsel.
Familiarity with applicable Federal forensic and cybersecurity standards, including NIST SP 800-86, NIST SP 800-53, FISMA, and Federal Rules of Evidence requirements.
Proficiency with scripting languages (e.g., Python, PowerShell, or Bash) for forensic automation, data parsing, and analysis workflow development.
Desired Skills and Competencies:
Certified Forensic Computer Examiner (CFCE), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Forensic Examiner (GCFE), EnCase Certified Examiner (EnCE), AccessData Certified Examiner (ACE), or equivalent industry-recognized digital forensics certification.
GIAC Certified Incident Handler (GCIH), GIAC Certified Enterprise Defender (GCED), Certified Information Systems Security Professional (CISSP), or equivalent cybersecurity certification.
GIAC Reverse Engineering Malware (GREM) certification or demonstrated equivalent malware analysis expertise.
Cellebrite Certified Mobile Examiner (CCME) or equivalent mobile device forensics certification.
Experience with Security Information and Event Management (SIEM) platforms (e.g., Splunk, Microsoft Sentinel, or equivalent) for log aggregation, query development, and investigation support.
Experience with threat intelligence platforms and the practical application of threat intelligence to forensic investigation and indicator of compromise development.
Familiarity with MITRE ATT&CK framework and its application to forensic investigation, attacker TTP identification, and incident reconstruction.
Experience supporting insider threat investigations, including the forensic analysis of user activity, data exfiltration indicators, and behavioral anomalies.
Experience with e-discovery platforms and electronically stored information (ESI) processing workflows in support of Federal litigation hold and legal matter requirements.
Knowledge of Zero Trust Architecture principles (NIST SP 800-207, OMB M-22-09) and their practical application to forensic investigation and incident response within a federal enterprise IT environment.
Experience with YARA rule development and application for malware identification and forensic artifact classification.
Familiarity with Section 508 compliance requirements for digital tools and reporting products delivered under federal contracts.
Experience developing and delivering forensic training, knowledge transfer sessions, or awareness materials for program personnel and Government stakeholders.
Our Equal Employment Opportunity Policy:
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at View email address on click.appcast.io or by calling View phone number on click.appcast.io to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit .
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
Job Details
Job Family IT, Cyber Security, Network Systems
Pay Type Salary
Hiring Min Rate 100,000 USD
Hiring Max Rate 130,000 USD
$125k - $145k
...Cybersecurity Digital Forensic Investigator This position is contingent upon a future opening with Gunnison. Salary: $125,000-$145,000 Work location: Hybrid, 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site....SuggestedFull timeContract workFlexible hours2 days per week3 days per week$104k - $166k
...Senior Digital Forensic Analyst Job Locations US-VA-Arlington Requisition ID 2026-169184 Position Category Cyber Security Clearance Top Secret Responsibilities Peraton is currently seeking a Senior Digital Forensic...SuggestedFull timeContract workFor contractorsInterim roleLocal areaShift work- cFocus Software seeks a Digital Forensics Analyst to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance....SuggestedWork at office
$101k - $152k
...manages vendor relationships. As your initial project assignment, you will support the unique needs of our client as a Digital Forensics Analyst. Project Summary The Digital Forensics Analyst is responsible for conducting advanced forensic examinations across a wide...SuggestedContract work- ...Digital Forensic Analyst Employment Type: Full-Time, Mid-Level CGS is seeking a Digital Forensic Analyst whose primary focus will be on the preservation & collection of mobile device and cloud-stored data. This candidate should be fluent in a broad range of forensic...SuggestedFull timeWork at officeRemote workFlexible hours
- ...meaningful results. This is a contingent position based upon customer approval. SkyePoint Decisions is seeking a Mid-Level Digital Forensic Analyst to support the Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and technology security experience...Remote work
$86k - $138k
Peraton is seeking a Mid-Level Digital Forensic Analyst in Arlington, VA. This role involves recovering and analyzing digital evidence to support investigations, utilizing industry-standard tools like Cellebrite and Magnet Axiom. A Bachelor's degree with 5 years of experience...$101k - $152k
Applied Information Sciences, Inc in Alexandria, Virginia is seeking a Senior Security Engineer to conduct comprehensive digital forensic examinations across various systems. This role includes responsibility for incident management, malware analysis, and deep investigations...Contract work$86k - $138k
Mid-Level Digital Forensic Analyst Peraton is currently seeking a Mid-Level Digital Forensic Analyst to support Federal Strategic Cyber programs in the Cyber & Intelligence sector. Responsibilities This role focuses on the recovery, analysis, and reporting of digital...Shift work- ...full benefits package. Required Experience Must have at least 5 years of experience conducting, or supporting the conduct of, digital forensic analysis (Windows, Linux and Mac), digital media acquisition (disk duplication), mobile device acquisition/analysis, malware analysis...
- Forensic Focus Limited seeks a seasoned digital forensics analyst to conduct examinations across Windows, Linux, and macOS, perform disk duplication and mobile acquisitions, and analyze malware. You will perform cloud investigations in M365, Azure, and AWS and lead threat...For contractors
- The Role The analyst conducts digital forensic examinations across Windows, Linux, and macOS environments, performs disk duplication and mobile device acquisition, and carries out malware analysis. Day-to-day work also includes cloud-based investigations using M365, Azure...For contractors
- Overview Vexterra Group is searching for a Digital Forensic Analyst to provide support across forensic examinations, technical exploitation, and related activities for diverse customer assets and stakeholders. Responsibilities Conduct forensic examination of High Priority...Temporary workWork experience placement
- Vexterra Group is looking for a Digital Forensic Analyst to conduct comprehensive forensic examinations, support technical exploitation and generate professional reports for diverse stakeholders. The ideal candidate will have extensive experience and must possess active...
$86k - $138k
Peraton is seeking a Mid-Level Digital Forensic Analyst in Arlington, VA to support Federal Cyber programs. This role requires expertise in recovering, analyzing, and reporting digital evidence for criminal and administrative investigations. The ideal candidate will have...$66k - $106k
Peraton is seeking a Junior Digital Forensic Analyst in Arlington, VA. This on-site role involves solving complex investigative challenges, conducting forensic examinations, and producing clear reports while collaborating with a mission-focused team. Key qualifications...$65k - $80k
...leading eDiscovery technology and consulting firm headquartered in Washington, DC is looking for a qualified and experienced Digital Forensic Analyst. We are seeking a motivated individual with a strong interest in the legal and technology fields, excellent organizational...Remote work$104k - $166k
...Investigations, and Technology Innovation and Engineering State. About The Role Peraton is currently seeking to hire a Sr Digital Forensic Analyst for its Federal Strategic Cyber program. Location: Arlington, VA - full-time, on-site role. This Federal StrategicCyber...Full timeContract workTemporary workInterim roleCurrently hiringWork at officeLocal areaShift work$66k - $106k
Junior Digital Forensic Analyst Location: Arlington, VA (On-site) Responsibilities Peraton is currently seeking to hire a Junior Digital Forensic Analyst to join our Federal Strategic Cyber program in the Cyber & Intelligence sector. The programs' Computer Investigations...Interim roleCurrently hiringLocal areaShift work$104k - $166k
Peraton is seeking a Senior Digital Forensic Analyst in Arlington, VA to support Federal Strategic Cyber programs in the Cyber & Intelligence sector. In this role, you will conduct forensic examinations of digital data from various platforms and provide expert witness...- Saliense is seeking a senior security analyst with extensive digital forensics and incident response experience. You will conduct forensic analysis across Windows, Linux, and Mac and perform malware analysis, data/triple-check acquisitions, and cloud-activity investigations...
- ...Job Description The Digital Forensics Analyst is responsible for collecting, preserving, analyzing, and documenting digital evidence associated with cybersecurity incidents, investigations, legal proceedings, and insider threat cases. This position conducts forensic...
- ...Digital Forensics Specialist Alexandria, VA Type: Contract-to-Hire Category: Security Industry: Government Standard Hours: Open Reference ID: JN -082026-108430 Date Posted: 08/30/2026 Shortcut: Description Recommended Jobs Description...Hourly payPermanent employmentContract workLocal area2 days per week3 days per week
- As a Digital Forensics Specialist, you'll be the bridge between our technology and the real-world needs of law enforcement and prosecutors. You'll work closely with our product and engineering teams to ensure ClearPath.AI meets the rigorous standards required for courtroom...
- ...Cyber Network Forensic Analyst III, TS/SCI Raytheon Technologies provides remote and onsite advanced technical assistance, proactive hunting... ...capabilities. Team personnel provide front line response for digital forensics/incident response (DFIR) and proactively hunting...Immediate startRemote work
- Job Description The Digital Forensics Systems Specialist provides technical leadership and operational support for a federal digital forensic laboratory environment supporting active law enforcement and regulatory investigations. This position ensures the availability,...
- ...cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret... .... This position offers various benefits including medical, dental, vision, and a 401K plan. #J-18808-Ljbffr Node.Digital LLC
- MANTECH seeks a motivated, career and customer-oriented Senior Cloud Information System Security Officer (ISSO) to join our team in Washington, D.C., Chantilly, VA or Quantico, VA.. Responsibilities include, but are not limited to: Ensure the day-to-day implementation...Work at office
$104k - $166k
Responsibilities Peraton is currently seeking a Senior Digital Forensic Analyst to support Federal Strategic Cyber programs in the Cyber & Intelligence sector.Location: On-site, Arlington, VAIn this role, you will: Conduct forensic examinations of digital data from...Contract workInterim roleLocal areaShift work- Raytheon Technologies is seeking a Cyber Network Forensic Analyst III to contribute to advanced cybersecurity operations. This role involves monitoring network activity to identify and analyze cyber threats, ensuring the protection of information systems. As part of a...Remote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Digital Forensic Analyst. Be the first to apply!
- digital animation Washington DC
- western digital Washington DC
- digital creative Washington DC
- digital media Washington DC
- digital Washington DC
- digital reporter Washington DC
- chief digital officer Washington DC
- digital media sales Washington DC
- digital media internship Washington DC
- digital accessibility Washington DC


