Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Cyber Defense Forensics Analyst

$110k - $150k

Revolutional, LLC

Job Description

Job Description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.

We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

Lead Cyber Defense Forensics Analyst

Location: Onsite – Government-controlled secure facility

Terms: Full-time

Salary: $110-$150k DOE

Clearance: Active Top Secret/SCI required 

Travel: 0-10%

Project Description

This position serves as the senior forensic practitioner on a federal enterprise cybersecurity program operating within government-controlled secure facilities. The forensics function supports the full cyber defense mission — conducting complex digital forensic investigations, driving incident response analysis, and contributing to threat hunt operations at the classified level. This is a hands-on technical lead role, not an organizational management position.

The core challenge: leading forensic investigations of the highest technical complexity within a classified environment — setting the analytic standard, producing legally defensible findings, and ensuring that forensic work directly informs and accelerates the program's incident response and threat hunt capabilities.

Position Description

As Lead Cyber Defense Forensics Analyst at Revolutional, you are the program's most senior forensic practitioner. You own the most complex investigations, set the technical standard for forensic methodology, and serve as the subject matter authority on computer forensics, network analysis, and evidentiary handling across the cyber defense mission. You work alongside — not above — the SOC Chief, contributing deep technical expertise where it matters most: inside the investigation.

You bring 5 to 7 years of hands-on experience across digital forensics, incident response, and threat hunting, and you operate in full alignment with the NICE Cybersecurity Workforce Framework Cyber Defense Forensics Analyst role (IN-FOR-002). Your core competencies span Computer Forensics, Computer Network Defense, Software Testing and Evaluation, System Administration, and Threat Analysis — and you apply all of them under classified conditions, within government-controlled secure facilities, every day.

Responsibilities
  • Lead digital forensic investigations of the highest technical complexity; conduct end-to-end analysis from evidence acquisition through findings documentation within classified, government-controlled secure facilities
  • Perform host-based forensic analysis: disk and memory acquisition, file system examination, artifact recovery, malware triage, and attack timeline reconstruction across Windows and Linux environments
  • Conduct network forensic analysis: packet capture review, NetFlow correlation, log analysis, and identification of lateral movement, exfiltration, and command-and-control activity
  • Maintain strict chain of custody for all evidence collected and handled; ensure all forensic work meets applicable federal legal and evidentiary standards
  • Provide direct analytical support to incident response operations; contribute forensic findings that drive containment, eradication, and recovery decisions in real time
  • Support threat hunt activities with forensic analysis: investigate hunt leads, validate hypotheses, and extract IOCs that feed detection improvements
  • Apply Software Testing and Evaluation methodology to validate forensic tools and assess new capabilities before operational deployment
  • Apply system administration knowledge across Windows and Linux environments to scope investigations, interpret artifacts, and assess attacker activity accurately
  • Apply Threat Analysis tradecraft to map forensic findings to adversary TTPs using MITRE ATT&CK and other structured frameworks
  • Produce thorough, legally defensible forensic reports documenting methodology, findings, evidence handling, and recommended response actions
  • Maintain current awareness of adversary tradecraft, malware families, forensic evasion techniques, and emerging investigation methodologies
  • Ensure compliance with NICE Cybersecurity Workforce Framework IN-FOR-002 role definition and associated role-based training requirements
What You Bring (Requirements)Baseline Requirements
  • Bachelor's degree in Computer Science, Digital Forensics, Information Security, or related field (or equivalent experience)
  • 5 to 7 years of hands-on experience in digital forensics, incident response, and threat hunting, with demonstrated lead-level technical proficiency
  • Active Top Secret/SCI clearance (Final) required
  • Must work onsite within a government-controlled secure facility
Technical & Domain Capabilities
  • Expert-level Computer Forensics: disk and memory acquisition, file system and artifact analysis, malware triage, timeline reconstruction, and chain of custody management to legal and evidentiary standards
  • Core competency in Computer Network Defense: intrusion detection, alert triage, network traffic analysis, and defensive posture assessment applied to forensic investigation scoping and findings
  • Experience with Software Testing and Evaluation applied to forensic tool validation, capability testing, and pre-deployment assessment of new investigation technologies
  • Working knowledge of System Administration across Windows and Linux environments sufficient to accurately scope investigations, interpret system artifacts, and reconstruct attacker activity
  • Core competency in Threat Analysis: MITRE ATT&CK-based TTP mapping, threat actor profiling, and structured analytic frameworks applied to forensic findings
  • Proficiency with industry-standard forensic tools: EnCase, FTK, Autopsy, Volatility, Wireshark, or equivalent
  • Experience operating within the NICE Cybersecurity Workforce Framework IN-FOR-002 role definition; current on applicable role-based training requirements
Core Strengths
  • Technically elite forensic practitioner — your investigations are thorough, your methodology is sound, and your findings hold up under legal and operational scrutiny
  • Analytically independent: you take complex, ambiguous investigations and drive them to conclusion without needing the situation pre-defined
  • Rigorous in classified environments — chain of custody, access controls, and handling requirements are instinctive, not procedural
  • Effective technical contributor to incident response and threat hunt teams; your forensic findings accelerate the broader mission, not just your own workstream
Certifications

One or more of the following is required or strongly preferred:

  • GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner), EnCE (EnCase Certified Examiner), CFCE (Certified Forensic Computer Examiner), or GCIH (GIAC Certified Incident Handler)
  • Role-based training required per NICE Cybersecurity Workforce Framework IN-FOR-002 — must be current or completed within required timeframes
Nice to Have (Differentiators)
  • GREM (GIAC Reverse Engineering Malware) or equivalent advanced malware analysis credential
  • GNFA (GIAC Network Forensic Analyst) for candidates with deep network forensics depth
  • Experience conducting forensic investigations at TS/SCI level within SCIFs or other government-controlled secure facilities
  • Background in mobile device forensics, cloud forensics, or memory forensics at advanced levels
  • Experience supporting legal proceedings or law enforcement actions with forensic evidence and findings documentation
  • Familiarity with emerging forensic evasion techniques and anti-forensics tradecraft used by advanced threat actors

#DICE #LinkedIn

___________________________________________________________________________________________________________

Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day.  Some of these recognitions include:  

  • Recognized as a Top 20 "Best Place to Work in Virginia"
  • Recipient of Department of Labor's HireVets Gold Medallion
  • Great Place to Work Certification for five years running
  • A Virginia Chamber of Commerce Fantastic 50 company
  • A Northern Virginia Technology Council Tech 100 company 
  • Inc. 5000 list of fastest growing companies for eleven years
  • Two-time SBA SBIR Tibbett's Award winner
  • Virginia Values Veterans (V3) Certification

We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family!   In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to

  • Traditional and HSA- eligible medical insurance plans 
  • 100% employer-paid dental and vision insurance options 
  • 100% employer-sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible-schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental Leave
  • Professional development and career growth opportunities 
  • Team and company-wide events, recognition, and appreciation-- and so much more! 

Check out our Revolutional | LinkedIn to find out a little more about who we are and if we are the right next step for your career!   

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans.  To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily.  Other duties in addition to those listed may be assigned as necessary to meet business needs.  Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job.  If you are in need of an accommodation, please contact View email address on ziprecruiter.com.

"Know Your Rights: Workplace Discrimination is Illegal" Poster | U.S. Equal Employment Opportunity Commission

Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Lead Cyber Defense Forensics Analyst in Washington DC vacancy
  • Sierra Nevada Corporation seeks an AI Threat Analyst III to support Insider Risk and AI-driven security initiatives...  ...surface insider-threat trends, enable proactive defenses, and collaborate with stakeholders across cyber tools and data science. A TS clearance and strong... 
    Cyber

    Sierra Nevada Corporation

    Arlington, VA
    5 days ago
  • $110k - $150k

     ...and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Lead Cyber Defense Forensics Analyst Location: Onsite – Government-controlled secure facility Terms: Full-time Salary: $110-$150k DOE... 
    Cyber
    Full time
    Work experience placement
    Flexible hours

    Revolutional, LLC

    Suitland, MD
    10 days ago
  • $85k - $115k

     ...McLean, VA, By Light supports defense, civilian, and commercial IT...  ...Light has an opening for a CND Analyst - SOC supporting the Army...  ...services. The Guard Enterprise Cyber Operations Support (GECOS) program...  ...support services involving forensic analyses on a variety of... 
    Cyber
    Contract work
    Work experience placement
    Remote work
    Worldwide
    Relocation
    Shift work

    By Light Professional IT Services

    Falls Church, VA
    4 days ago
  • $138k - $209k

     ...Information Sciences) is seeking a qualified Security Architect to lead incident response activities and manage cybersecurity threats...  ...years in incident response and extensive knowledge of digital forensics and malware analysis. Competitive salary range is $138,000-$209... 
    Cyber

    AIS (Applied Information Sciences)

    Alexandria, VA
    2 days ago
  • $69.4k - $158k

    Modeling and Simulation Analyst, LeadThe Opportunity:As a lead modeling and simulation analyst, you will use your passion for uncovering root causes,...  ...simulation activities that support quantitative assessments for defense mission objectives. Using the Advanced Framework for... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Alexandria, VA
    10 hours ago
  •  ...(CSA) is currently seeking an Analyst I to support onsite in the Arlington...  ...support services to meet the defense and federal sector's most...  ...applicable directives.Support cyber and compliance activities, including...  ....Collaborate with government leads, program management, and... 
    Cyber
    Contract work
    For subcontractor
    Work at office
    Remote work

    Client Solution Architects

    Arlington, VA
    2 days ago
  •  ...is hiring a Senior CFIUS-Export Control Analyst to lead our team of qualified, diverse, and highly...  ...the Office of the Under Secretary of Defense, Research and Engineering (OUSD(R&E)). The...  ...foreign ownership, control, influence, cyber penetration, and other exploitation threats... 
    Cyber
    Work at office
    Local area

    Science Applications International Corporation

    Alexandria, VA
    1 day ago
  •  ...seeking a ServiceNow Business Analyst to support the Department of State...  ...and San Diego, CA, CTC is a leading technology company providing...  ...development, DevOps, Test Automation, Cyber Security, and infrastructure...  ...the unique needs of U.S. Defense, Intelligence, and Federal... 
    Cyber
    Full time
    Contract work
    For contractors
    Local area
    Remote work

    Computer Technologies Consultants (CTC)

    Arlington, VA
    1 day ago
  •  ...Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat Emulation...  ...oversee adversary emulation, red team operations, cyber readiness exercises, and threat-informed defense initiatives supporting a federal enterprise... 
    Cyber
    Full time

    cFocus Software Incorporated

    Washington DC
    more than 2 months ago
  •  ...Arlington is seeking a Host Based Systems Analyst IV to provide cybersecurity analysis and response. The role involves leading forensic teams, technical assistance on data collection...  ...will have extensive experience with cyber forensic investigations and must demonstrate... 
    Cyber

    Solutions , LLC

    Arlington, VA
    3 days ago
  • Chenega MIOS is seeking a Security Operations Center Analyst II in Arlington, VA to monitor devices, manage incidents, and analyze network events. You will work with a SIEM toolkit across program networks, ensuring continuous security operations and rapid incident response... 
    Cyber

    Chenega Corporation

    Arlington, VA
    5 days ago
  • $100.5k - $153.25k

     ...seeking a highly skilled Sr. Enterprise Analyst to support Payroll and Time & Absence Management...  ...The best of the best.We don’t just build defense technology—we redefine what’s possible....  ...across air, land, sea, space, and cyber. From AI-powered drones and loitering munitions... 
    Cyber
    Permanent employment
    Full time
    Contract work
    Work experience placement
    Work at office

    AeroVironment

    Arlington, VA
    1 day ago
  • $116.5k - $177.5k

     ...every single day. Together, we are leading the transformation of modern...  ...From Space and Directed Energy to Cyber and Intelligence to C4ISR and Air & Missile Defense, there is no limit to where you...  ...launch a career at AV?As the Program Analyst, you will play a highly visible... 
    Cyber
    Permanent employment
    Full time
    Contract work
    Work experience placement
    For subcontractor
    Remote work

    AeroVironment

    Arlington, VA
    4 days ago
  • Leidos is seeking an experienced Tier 2 Security Operations Center (SOC) Analyst to support the DMDC CyberPRIMES program. You will perform advanced analysis of cybersecurity events escalated from Tier 1, correlate security data, and support incident triage and containment... 
    Cyber

    Leidos

    Alexandria, VA
    3 days ago
  • Chenega MIOS in Arlington, VA seeks a Security Operations Center Analyst I to monitor devices, manage incidents, and coordinate recovery across government networks. The role requires DoD IAT Level II certification and a DoD Secret Clearance with potential TS/SCI eligibility... 
    Cyber

    NJVC

    Arlington, VA
    5 days ago
  • Systems Planning and Analysis, Inc. (SPA) is seeking a mid-level Cyber Security Analyst in Alexandria, VA or Washington Navy Yard. You will support RMF, develop analytical methodologies, and protect data across multi-technology environments. The role requires U.S. citizenship... 
    Cyber

    Systems Planning and Analysis, Inc.

    Alexandria, VA
    4 days ago
  •  ...headquartered in Reston, Virginia, SOSi is a private defense and government solutions business...  ...a highly qualified senior-level Team Lead to support the region of China for a contract...  ...on the PRC across all-source, C4I, cyber, HUMINT, SIGINT, GEOINT, TECHINT, and technology... 
    Cyber
    Contract work
    For contractors
    Work at office

    SOSi

    Washington DC
    1 day ago
  • Cydecor, Inc. is seeking an Integrated Air and Missile Defense (IAMD) Capabilities Support to work in the Pentagon supporting OPNAV N99....  ...will assist in assessing programmatic requirements, reviewing EW, cyber operations, TDL and space policy, and preparing cogent... 
    Cyber

    Cydecor, Inc.

    Arlington, VA
    5 days ago
  •  ...technology and services integrators in the defense and government services industry. We...  ...SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and...  ...visibility into security weaknesses and cyber risk.Responsibilities· Perform vulnerability... 
    Cyber
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    1 day ago
  • Leidos is seeking a Security Operations Center Lead for the DISA GSM-O program in Alexandria, VA. The role directs day-to-day SOC activities, coordinates 24x7 incident handling, and ensures strict adherence to incident response processes. Qualified candidates will have... 
    Cyber

    Via Logic LLC

    Alexandria, VA
    1 day ago
  •  ...advanced C5ISR and security solutions to enhance defense and mission capabilities, addressing threats across physical, electronic, cyber, and communications security for commercial...  ...Summary: As a senior technician, the Lead Security Systems Technician is responsible... 
    Cyber
    Hourly pay
    Night shift

    Active Security Consulting

    Silver Spring, MD
    4 days ago
  • Our Mission At Dobbs Defense, we deliver mission-centric IT, Cyber, and data analytics solutions for our government and commercial clients through the convergence...  ...Dobbs Defense Solutions is seeking a Business Analyst to provide support to senior resources on the team in... 
    Cyber
    Work at office

    Dobbs Defense Solutions, LLC

    Washington DC
    1 day ago
  •  ...Inc.is seeking a Senior Legislative Rearch Analyst to support the full range of...  ...understanding and generate Congressional support for Defense Intelligence resources and legislative...  ...advancements in Logistics, Human Capital, Cyber, Intelligence & Technology. EOE Statement... 
    Cyber

    Rividium

    Washington DC
    4 days ago
  • Lumifi Cyber seeks a Lead Consultant for the IR/Forensics Practice, primarily conducting incident response and forensic investigations. The role requires availability for 24/7 on-call IR work, managing customer recovery, and leading response efforts. Ideal candidates will... 
    Cyber
    Remote job

    Lumifi Cyber

    Arlington, VA
    4 days ago
  •  ...Position Title Cyber Threat Intelligence & Threat Hunting Lead Position Overview The Cyber Threat Intelligence & Threat Hunting Lead will oversee...  ...threat hunting operations supporting enterprise cyber defense missions. The Lead will drive development of... 
    Cyber
    Full time

    cFocus Software Incorporated

    Washington DC
    more than 2 months ago
  •  ...support services across the Department of Defense, Federal Civilian, and international...  ...a future need for an Operations Research Analyst to assist with systems engineering (SE) and...  ...acquisition programs, especially in Reliability, Cyber Resilience, AI, and Human Systems... 
    Cyber
    Temporary work
    Work at office

    Systems Planning & Analysis

    Alexandria, VA
    2 days ago
  •  ...&A Company, is seeking a Counterintelligence (CI) Senior Analyst to support the Defense Advanced Research Projects Agency (DARPA) Program Security...  ...and impactful opportunity. Responsibilities include leading and mentoring CI Analysts, planning analytical projects,... 

    Kinsley Power Systems

    Arlington, VA
    2 days ago
  • Systems Planning & Analysis in Arlington, VA, is seeking a Sr. Operations Research Analyst to support joint missile defense simulation and analysis at the Pentagon. This role includes leading a team in high-profile, classified environments to provide insightful... 

    Systems Planning & Analysis

    Arlington, VA
    2 days ago
  • $160k - $190k

     ...Planning and Analysis, Inc. in Arlington, Virginia, seeks a senior IAMD Technical Analyst to support AF/A10 with analysis, policies, and staff products for integrated air and missile defense. The role requires 8+ years in IAMD or defense analysis, a Bachelor's in a... 

    Systems Planning and Analysis, Inc.

    Arlington, VA
    4 days ago
  •  ...the fastest growing areas of our business, and our global Cyber Investigation and Forensic Response (CIFR) practice is at the heart of how we help clients...  ...maturing the offering, and growing the practice.The Work:Lead enterprise recovery engagements during active cyber... 
    Cyber
    Full time
    Live in
    Work at office
    Local area
    Shift work

    Accenture

    Arlington, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Cyber Defense Forensics Analyst. Be the first to apply!