Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Forensics Analyst - TS/SCI

Beyond SOF

Cyber Forensics Analysts

Client seeking Cyber Forensics Analysts to support the DHS Hunt and Incident Response Team (HIRT). This team secures the Nation's cyber and communications infrastructure while providing front line response for cyber incidents and hunting for malicious cyber activity. The client, as a prime contractor to DHS, performs HIRT investigations to develop a diagnosis of the severity of breaches. Contract personnel provide front line response for digital forensics/incident response and proactively hunting for malicious cyber activity for this critical customer mission.

Responsibilities:

  • Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack
  • Assess network topology and device configurations identifying critical security concerns and providing security best practice recommendations
  • Collect network intrusion artifacts (e.g., PCAP, domains, URI's, certificates, etc.) and use discovered data to enable mitigation of potential incidents
  • Collect network device integrity data and analyze for signs of tampering or compromise
  • Analyze identified malicious network and system log activity to determine weaknesses exploited, exploitation methods, effects on system and information
  • Tracking and documenting on-site incident response activities and providing updates to leadership through executive summaries and in-depth technical reports
  • Planning, coordinating and directing the inventory, examination and comprehensive technical analysis of computer related evidence
  • Serving as technical forensics liaison to stakeholders and explaining investigation details

Required Skills:

  • U.S. Citizenship
  • Must have an active Secret clearance (TS/SCI eligible) and be able to obtain DHS Suitability
  • 8+ years of directly relevant experience in cyber forensic and network investigations using leading edge technologies and industry standard forensic tools
  • Experience with reconstructing a malicious attack or activity
  • Ability to characterize and analyze network traffic, identify anomalous activity / potential threats, analyze anomalies in network traffic using metadata
  • Ability to create forensically sound duplicates of evidence (forensic images)
  • Able to write cyber investigative reports documenting forensics findings
  • In depth knowledge and experience of:
    • Identifying different classes and characterization of attacks and attack stages
    • CND policies, procedures and regulations
    • Proactive analysis of systems and networks, to include creating trust levels of critical resources
    • System and application security threats and vulnerabilities
    • Network topologies, Wi-Fi Networking, and TCP/IP protocols
    • Splunk (or other SIEMs)
    • Vulnerability scanning, assessment and monitoring tools such as Security Center, Nessus, and Endgame
    • MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
  • Must be able to work collaboratively across physical locations.

Desired Skills:

  • Experience and proficiency with the following tools and techniques:
    • EnCase, FTK, SIFT, X-Ways, Volatility, WireShark, Sleuth Kit/Autopsy, and Snort
    • EDR Tools: Crowdstrike, Carbon Black, Etc
    • Carving and extracting information from PCAP data
    • Non-traditional network traffic: Command and Control
    • Preserving evidence integrity according to national standards
    • Designing cyber security systems and environments in a Linux environment
    • Virtualized environments
    • Conducting all-source research
  • Required Education: 8+ years of experience and BS Computer Science, Cybersecurity, Computer Engineering or related degree; or HS Diploma and 10+ years of host or digital forensics or network forensic experience
  • Desired Certifications:

    • GCFA, GCFE, EnCE, CCE, CFCE, CEH, CCNA, CCSP, CCIE, OSCP, GNFA
Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Cyber Forensics Analyst - TS/SCI in Arlington, VA vacancy
  • A cybersecurity firm is seeking a Cyber Network Defense Analyst with cloud forensics experience in Arlington, Virginia. The role requires a minimum of a TS/SCI clearance and a strong background in cyber forensic investigations. Responsibilities include conducting forensic... 
    Suggested

    ARGO Cyber Systems, LLC

    Arlington, VA
    12 hours ago
  •  ...Arlington, VA Clearance Required: TS/SCI minimum (US Citizen)...  ...enforcement. Our mission is to empower analysts and decision-makers through...  ...a highly skilled Senior Cyber Threat Analyst to join our...  ...all-source analysis using forensics, network vulnerability assessments... 
    Suggested
    Full time
    Local area

    Praescient Analytics

    Arlington, VA
    3 days ago
  •  ...Host Based Systems Analyst - IV The client provides remote and...  ...front line response for digital forensics/incident response (DFIR) and...  ...hunting for malicious cyber activity. We are seeking Cyber...  ...U.S. Citizenship ~ Active TS/SCI clearance ~ Ability to obtain... 
    Suggested
    Immediate start
    Remote work

    Beyond SOF

    Arlington, VA
    a month ago
  •  ...firm in Arlington, Virginia is seeking professionals to manage cyber incidents for U.S. Government clients. Responsibilities include...  ...techniques. Candidates must possess U.S. citizenship, an active TS/SCI clearance, and 5+ years of relevant experience in cyber incident... 
    Suggested

    Limelight Health

    Arlington, VA
    1 day ago
  • Nalley Consulting is seeking a Cyber Analyst at Joint Base Anacostia-Bolling. This mid-level position requires a TS/SCI clearance and involves conducting intelligence analysis on national security issues. Candidates should have at least 3 years of relevant experience in... 
    Suggested

    Nalley Consulting

    Washington DC
    3 days ago
  •  ...community. The Perks: As recognized members of the Cyber Elite, we work together in partnership to defend our nation's...  ...we're looking for: We are seeking an Expert Cyber Defense Analyst (TS/SCI Clearance) to analyze cyber events and support threat mitigation... 

    ShorePoint Inc

    Washington DC
    1 day ago
  •  ...technology solutions provider in Arlington, VA is seeking a Cyber Threat Intelligence Analyst. The role involves gathering and analyzing cyber threat...  .... Candidates must be U.S. citizens with an active TS/SCI clearance and have at least 5 years of relevant experience... 

    Nightwing Group

    Arlington, VA
    3 days ago
  •  ...consulting firm is seeking an Incident Manager with a focus on Cyber Threat Intelligence in Arlington, VA. The role involves gathering...  ...and improve vulnerability management. Candidates should have a TS/SCI clearance, 2+ years of relevant experience, and a Bachelor's degree... 

    Node.Digital LLC

    Arlington, VA
    1 day ago
  •  ...leading defense contractor is seeking a Senior All-Source Analyst to support USCYBERCOM J2 in the National Capital...  ...experience in intelligence analysis, an active TS/SCI clearance, and a strong understanding of cyber threats. This role involves conducting various analyses... 
    For contractors

    Kinsley Power Systems

    Alexandria, VA
    12 hours ago
  •  ...looking for a Cybersecurity Defensive Cyber Operations (CDO) Analyst to join our team of experts to assist with building state of the art data platforms...  .... Qualifications: Required Skills: ~ Clearance: TS/SCI ~ Bachelor's degree in Cybersecurity, Information... 

    André Global, Inc.

    Alexandria, VA
    4 days ago
  • $155k - $170k

     ...Job Type Full-time Description Job Title: Senior Cyber Security Analyst Place of Performance: Washington, DC 20392 Mandatory Requirements: Top Secret Clearance with SCI Eligibility Experience Level: Senior-Level (8+ years in cybersecurity, 3... 
    Full time
    Temporary work
    Local area
    Immediate start
    Flexible hours

    JFL Consulting

    Washington DC
    5 days ago
  •  ...Job Description We are seeking a Cyber Security Analyst . This position provides 24x7...  ...an active DoD TOP Secret security w/ SCI clearance eligibility. Preferred...  ...IDS/IPS, Full Packet Capture, Network Forensics. Experience with malware analysis... 
    Work experience placement
    Shift work

    Nicholson Strategic Solutions

    Arlington, VA
    5 days ago
  •  ...contracting firm in Arlington, VA, is seeking an IT/Telecommunications Analyst to conduct cybersecurity research and analysis. The role...  ...8+ years in telecommunications and cybersecurity. An active TS/SCI clearance is required. #J-18808-Ljbffr Systems Planning & Analysis

    Systems Planning & Analysis

    Arlington, VA
    4 days ago
  • $131.3k - $237.35k

    Koitecc Solutions in Alexandria, Virginia is seeking a skilled SME Penetration Testing Analyst with active TS/SCI clearance and a strong background in cybersecurity. The role involves conducting and coordinating penetration tests, collaborating with DoD organizations,... 

    Koitecc Solutions

    Alexandria, VA
    2 days ago
  • Acclaim Technical Services is seeking Technical Targeting Analysts with TS/SCI clearance and polygraph for projects in Northern Virginia. You will utilize intelligence methodologies, analyzing vulnerabilities in key internet infrastructure. Ideal candidates will have 8... 

    Acclaim Technical Services

    Mc Lean, VA
    2 days ago
  • A leading technology services company is seeking a Technical Targeting Analyst with TS/SCI clearance and polygraph. The role involves utilizing a multi-disciplinary approach to identify intelligence opportunities and conducting data analysis to support technical operations... 

    Acclaim Technical Services

    Mc Lean, VA
    3 days ago
  • A cybersecurity firm is seeking a Cloud Forensics Analyst to support the U.S. Government with incident responses related to cyber-attacks. This role involves acquiring computer...  ...forensics, U.S. citizenship, and an active TS/SCI clearance. Advanced knowledge in cloud environments... 

    Nightwing

    Arlington, VA
    2 days ago
  • A leading cybersecurity firm is seeking experienced Cyber Network Defense Analysts to conduct forensic analysis and respond to cloud security incidents. The...  ...knowledge of hybrid identity security, and possess an active TS/SCI clearance. This position offers an opportunity to... 

    ARGO Cyber Systems, LLC

    Arlington, VA
    12 hours ago
  •  ...cybersecurity firm located in Arlington, VA, is seeking a Cloud Forensics Analyst to support U.S. Government agency missions. The role requires...  ...collaboratively across teams. Candidates must hold an active TS/SCI clearance and possess a degree in Computer Science or a... 

    Nightwing

    Arlington, VA
    4 days ago
  • Security Clearance Requirement TS, WITH SCI ELIGIBILITY US Citizenship Requirement ***POSITION REQUIRES US CITIZENSHIP*** Program Description...  ...and Authorization (A&A), Vulnerability Management, and Cyber Defense support. Position Description We are seeking a Senior... 
    Contract work
    Work experience placement

    Redtracetech

    Washington DC
    4 days ago
  • A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit... 

    Node.Digital LLC

    Arlington, VA
    3 days ago
  •  ...front line response for digital forensics/incident response (DFIR) and...  ...proactively hunting for malicious cyber activity. They are seeking Cyber Network Defense Analysts (CNDA) to support this...  ...~ US Citizenship ~ Active TS/SCI Clearance ~ Ability to obtain... 
    Immediate start
    Remote work

    New Gen

    Arlington, VA
    5 days ago
  •  ...Cyber Network Defense Analyst (CNDA) - Cloud Forensics Location: Remote / Onsite (as required) Clearance: Active TS/SCI (DHS EOD eligibility required) Company: Argo Cyber Systems, LLC - A Service-Disabled Veteran-Owned Small Business (SDVOSB) About Argo... 
    Remote work

    Argo Cyber Systems

    Arlington, VA
    2 days ago
  •  ...provides technically advanced full-spectrum cyber, data operations, systems integration...  .... Nightwing is seeking a Network Forensics Analyst to support this critical customer mission...  ...S. Citizenship - Must have an active TS/SCI clearance - Must be able to obtain DHS... 
    Contract work
    Immediate start

    Nightwing

    Arlington, VA
    3 days ago
  •  ...technology identification and workflows in Arlington, Virginia. Candidates must have a minimum of 12 years of relevant experience, active TS/SCI clearance, and strong skills in systems engineering and cybersecurity. Your role will involve creating detailed diagrams to... 

    Base One Technologies

    Arlington, VA
    1 day ago
  •  ...Cyber Network Defense Analysts (CNDA) Our partner provides remote and onsite advanced technical assistance...  ...front line response for digital forensics/incident response (DFIR) and proactively...  ...: ~ U.S. Citizenship ~ Active TS/SCI Clearance ~ Ability to obtain... 
    Immediate start
    Remote work

    NewGen Technologies (Maryland)

    Arlington, VA
    3 days ago
  • A leading cybersecurity firm in Arlington, VA, seeks a Network-Based System Analyst to engage in advanced cybersecurity analysis and network defense. Candidates must possess an active Top Secret Security Clearance and have at least 5 years of experience in network investigations... 

    Node

    Arlington, VA
    12 hours ago
  •  ...for security issues. Candidates must have a BS in a related field and at least 8 years of relevant experience, along with an active TS/SCI clearance. This position will leverage knowledge in network security architecture and various protocols to mitigate risks and... 

    Nightwing

    Arlington, VA
    2 days ago
  • A technology firm is seeking an experienced Cyber Incident Manager in Arlington, VA. The role involves correlating incident data, performing...  ...must have 5+ years of relevant experience and an active TS/SCI clearance. This position plays a critical role in supporting onsite... 

    Node.Digital LLC

    Arlington, VA
    1 day ago
  •  ...Virginia, is seeking an experienced professional for a role in cyber incident management. The candidate will support the management of...  ...+ years of experience in cybersecurity operations and an active TS/SCI clearance. Excellent communication skills are essential for this... 

    Base One Technologies

    Arlington, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Forensics Analyst - TS/SCI. Be the first to apply!