Lead Cyber Defense Forensics Analyst
$110k - $150kRevolutional, LLC
Job Description
Job Description
Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.
We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.
Lead Cyber Defense Forensics AnalystLocation: Onsite – Government-controlled secure facility
Terms: Full-time
Salary: $110-$150k DOE
Clearance: Active Top Secret/SCI required
Travel: 0-10%
Project DescriptionThis position serves as the senior forensic practitioner on a federal enterprise cybersecurity program operating within government-controlled secure facilities. The forensics function supports the full cyber defense mission — conducting complex digital forensic investigations, driving incident response analysis, and contributing to threat hunt operations at the classified level. This is a hands-on technical lead role, not an organizational management position.
The core challenge: leading forensic investigations of the highest technical complexity within a classified environment — setting the analytic standard, producing legally defensible findings, and ensuring that forensic work directly informs and accelerates the program's incident response and threat hunt capabilities.
Position DescriptionAs Lead Cyber Defense Forensics Analyst at Revolutional, you are the program's most senior forensic practitioner. You own the most complex investigations, set the technical standard for forensic methodology, and serve as the subject matter authority on computer forensics, network analysis, and evidentiary handling across the cyber defense mission. You work alongside — not above — the SOC Chief, contributing deep technical expertise where it matters most: inside the investigation.
You bring 5 to 7 years of hands-on experience across digital forensics, incident response, and threat hunting, and you operate in full alignment with the NICE Cybersecurity Workforce Framework Cyber Defense Forensics Analyst role (IN-FOR-002). Your core competencies span Computer Forensics, Computer Network Defense, Software Testing and Evaluation, System Administration, and Threat Analysis — and you apply all of them under classified conditions, within government-controlled secure facilities, every day.
Responsibilities- Lead digital forensic investigations of the highest technical complexity; conduct end-to-end analysis from evidence acquisition through findings documentation within classified, government-controlled secure facilities
- Perform host-based forensic analysis: disk and memory acquisition, file system examination, artifact recovery, malware triage, and attack timeline reconstruction across Windows and Linux environments
- Conduct network forensic analysis: packet capture review, NetFlow correlation, log analysis, and identification of lateral movement, exfiltration, and command-and-control activity
- Maintain strict chain of custody for all evidence collected and handled; ensure all forensic work meets applicable federal legal and evidentiary standards
- Provide direct analytical support to incident response operations; contribute forensic findings that drive containment, eradication, and recovery decisions in real time
- Support threat hunt activities with forensic analysis: investigate hunt leads, validate hypotheses, and extract IOCs that feed detection improvements
- Apply Software Testing and Evaluation methodology to validate forensic tools and assess new capabilities before operational deployment
- Apply system administration knowledge across Windows and Linux environments to scope investigations, interpret artifacts, and assess attacker activity accurately
- Apply Threat Analysis tradecraft to map forensic findings to adversary TTPs using MITRE ATT&CK and other structured frameworks
- Produce thorough, legally defensible forensic reports documenting methodology, findings, evidence handling, and recommended response actions
- Maintain current awareness of adversary tradecraft, malware families, forensic evasion techniques, and emerging investigation methodologies
- Ensure compliance with NICE Cybersecurity Workforce Framework IN-FOR-002 role definition and associated role-based training requirements
- Bachelor's degree in Computer Science, Digital Forensics, Information Security, or related field (or equivalent experience)
- 5 to 7 years of hands-on experience in digital forensics, incident response, and threat hunting, with demonstrated lead-level technical proficiency
- Active Top Secret/SCI clearance (Final) required
- Must work onsite within a government-controlled secure facility
- Expert-level Computer Forensics: disk and memory acquisition, file system and artifact analysis, malware triage, timeline reconstruction, and chain of custody management to legal and evidentiary standards
- Core competency in Computer Network Defense: intrusion detection, alert triage, network traffic analysis, and defensive posture assessment applied to forensic investigation scoping and findings
- Experience with Software Testing and Evaluation applied to forensic tool validation, capability testing, and pre-deployment assessment of new investigation technologies
- Working knowledge of System Administration across Windows and Linux environments sufficient to accurately scope investigations, interpret system artifacts, and reconstruct attacker activity
- Core competency in Threat Analysis: MITRE ATT&CK-based TTP mapping, threat actor profiling, and structured analytic frameworks applied to forensic findings
- Proficiency with industry-standard forensic tools: EnCase, FTK, Autopsy, Volatility, Wireshark, or equivalent
- Experience operating within the NICE Cybersecurity Workforce Framework IN-FOR-002 role definition; current on applicable role-based training requirements
- Technically elite forensic practitioner — your investigations are thorough, your methodology is sound, and your findings hold up under legal and operational scrutiny
- Analytically independent: you take complex, ambiguous investigations and drive them to conclusion without needing the situation pre-defined
- Rigorous in classified environments — chain of custody, access controls, and handling requirements are instinctive, not procedural
- Effective technical contributor to incident response and threat hunt teams; your forensic findings accelerate the broader mission, not just your own workstream
One or more of the following is required or strongly preferred:
- GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner), EnCE (EnCase Certified Examiner), CFCE (Certified Forensic Computer Examiner), or GCIH (GIAC Certified Incident Handler)
- Role-based training required per NICE Cybersecurity Workforce Framework IN-FOR-002 — must be current or completed within required timeframes
- GREM (GIAC Reverse Engineering Malware) or equivalent advanced malware analysis credential
- GNFA (GIAC Network Forensic Analyst) for candidates with deep network forensics depth
- Experience conducting forensic investigations at TS/SCI level within SCIFs or other government-controlled secure facilities
- Background in mobile device forensics, cloud forensics, or memory forensics at advanced levels
- Experience supporting legal proceedings or law enforcement actions with forensic evidence and findings documentation
- Familiarity with emerging forensic evasion techniques and anti-forensics tradecraft used by advanced threat actors
#DICE #LinkedIn
___________________________________________________________________________________________________________
Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include:
- Recognized as a Top 20 "Best Place to Work in Virginia"
- Recipient of Department of Labor's HireVets Gold Medallion
- Great Place to Work Certification for five years running
- A Virginia Chamber of Commerce Fantastic 50 company
- A Northern Virginia Technology Council Tech 100 company
- Inc. 5000 list of fastest growing companies for eleven years
- Two-time SBA SBIR Tibbett's Award winner
- Virginia Values Veterans (V3) Certification
We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to
- Traditional and HSA- eligible medical insurance plans
- 100% employer-paid dental and vision insurance options
- 100% employer-sponsored STD, LTD, and life insurance
- 5% 401(k) company matching
- Flexible-schedules and teleworking options
- Paid holidays and PTO Accrual Plans
- Paid Parental Leave
- Professional development and career growth opportunities
- Team and company-wide events, recognition, and appreciation-- and so much more!
Check out our Revolutional | LinkedIn to find out a little more about who we are and if we are the right next step for your career!
Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact View email address on ziprecruiter.com.
"Know Your Rights: Workplace Discrimination is Illegal" Poster | U.S. Equal Employment Opportunity Commission
$157.1k - $353.6k
...Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider... ...an Associate Director in Information Security, this position leads the application of AI engineering within a global technology program...CyberFull timeWork experience placementSummer holidayLocal areaImmediate startFlexible hours$85k - $115k
...McLean, VA, By Light supports defense, civilian, and commercial IT... ...Light has an opening for a CND Analyst - SOC supporting the Army... ...services. The Guard Enterprise Cyber Operations Support (GECOS) program... ...support services involving forensic analyses on a variety of...CyberContract workWork experience placementRemote workWorldwideRelocationShift work$138k - $209k
...Information Sciences) is seeking a qualified Security Architect to lead incident response activities and manage cybersecurity threats... ...years in incident response and extensive knowledge of digital forensics and malware analysis. Competitive salary range is $138,000-$209...Cyber- ...Resilience team is looking to hire an Incident / Crisis Management Lead to help drive the continuous enhancement of the crisis event... ...response to major disruption events (e.g., global technology outages, cyber-attacks, geopolitical issues etc). Coordinate cross-...CyberTemporary workLocal areaVisa sponsorshipWork visaFlexible hours
$69.4k - $158k
Modeling and Simulation Analyst, LeadThe Opportunity:As a lead modeling and simulation analyst, you will use your passion for uncovering root causes,... ...simulation activities that support quantitative assessments for defense mission objectives. Using the Advanced Framework for...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- ...Description Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat... ...oversee adversary emulation, red team operations, cyber readiness exercises, and threat-informed defense initiatives supporting a federal enterprise...Cyber
- ...Johns Hopkins Applied Physics Laboratory (APL) seeks a Military Cyber Engineering Lead to guide multi-disciplinary teams in engineering resilient military systems with strong cyber defenses. You will work with government sponsors, shape architecture, and define robust...Cyber
$104k - $166k
ResponsibilitiesThe Cyber Threat Analysis Division (DS/CTI/CTAD)... ...conducts advanced digital technical forensic analysis and application... ...with other forensic analysts, law enforcement officers, and... ...of the galaxy. As the world’s leading mission capability integrator...CyberContract workWorldwideOverseasShift work- ...ZP Group is seeking a SOC Lead to support federal cybersecurity operations, network defense, and protection of critical national security infrastructure. This on-site role is based in Manassas, VA and Washington, DC, where you will oversee security operations and incident...Cyber
- ...(CSA) is currently seeking an Analyst I to support onsite in the Arlington... ...support services to meet the defense and federal sector's most... ...applicable directives. Support cyber and compliance activities,... ...Collaborate with government leads, program management, and subcontractor...CyberFull timeContract workFor subcontractorWork at officeRemote work
$100.5k - $153.25k
...seeking a highly skilled Sr. Enterprise Analyst to support Payroll and Time & Absence Management... ...The best of the best.We don’t just build defense technology—we redefine what’s possible.... ...across air, land, sea, space, and cyber. From AI-powered drones and loitering munitions...CyberPermanent employmentFull timeContract workWork experience placementWork at office$116.5k - $177.5k
...every single day. Together, we are leading the transformation of modern... ...From Space and Directed Energy to Cyber and Intelligence to C4ISR and Air & Missile Defense, there is no limit to where you... ...launch a career at AV?As the Program Analyst, you will play a highly visible...CyberPermanent employmentFull timeContract workWork experience placementFor subcontractorRemote work- ...Arlington is seeking a Host Based Systems Analyst IV to provide cybersecurity analysis and response. The role involves leading forensic teams, technical assistance on data collection... ...will have extensive experience with cyber forensic investigations and must demonstrate...Cyber
- ...Leidos is seeking a Cyber Defense Infrastructure Support Engineer to join the ONI Hopper Global Communications Center in Suitland, MD. You... ...technical resource with Tier 3 escalation support. You will lead engineering and administration of cybersecurity capabilities...Cyber
- Peraton is seeking a Mobile Threat Analysis specialist within the Cyber Threat Analysis Division to perform advanced mobile forensics and app assessments. You will examine mobile devices end-to-end, analyze artifacts for indicators of compromise, and craft comprehensive...Cyber
- ...headquartered in Reston, Virginia, SOSi is a private defense and government solutions business... ...a highly qualified senior-level Team Lead to support a designated Operations office... ...disciplinary intelligence (all-source, C4I, cyber, HUMINT, SIGINT, GEOINT, OSINT, etc.)....CyberContract workFor contractorsWork at office
$87.1k - $157.45k
...Description Position: Information Assurance Analyst Location: Alexandria, VA Make an... ...a MissionFocused Environment The Leidos Defense Sector provides advanced systems, solutions... ...networks, and applications in coordination with cyber professionals, network staff, teammates,...CyberContract workLocal areaImmediate startRemote work- ...advanced C5ISR and security solutions to enhance defense and mission capabilities, addressing threats across physical, electronic, cyber, and communications security for commercial... ...Summary: As a senior technician, the Lead Security Systems Technician is responsible...CyberHourly payNight shift
$150k - $170k
...Zachary Piper Solutions is seeking a SOC Lead to support a company focused on federal cybersecurity operations, network defense, and protection of critical national security... ...defending sensitive systems against evolving cyber threats. Responsibilities for the SOC Lead...CyberNight shift$86.8k - $198k
...Team LeadThe Opportunity:As a defense mission professional, you ask... ...Supply Chain Risk Management Team Lead, you’ll bring your analytical... ...and processesExperience with Cyber Supply Chain Risk... ...engineers, defense and intelligence analysts, scientists, and uniformed military...CyberFull timeContract workPart timeLocal areaRemote work- ...Description Senior Data Analyst Req ID 003-25 v1.0 HazeGrayCyber, LLC is focused on delivering Cyber Security and Zero Trust Solutions to the US National Defense community and our allies and partners. This position will provide Information and Task...CyberFor contractorsOverseas
$115k - $128k
...research and technology in the cyber arena, CPMG focuses on using... ...integrative solutions for Department of Defense (DoD) contractors, among... .... Summary: The Program Analyst will perform the gamut of Action... ...the WHA/MA team, assist with leading WHA’s coordination within the...CyberContract workFor contractorsWork experience placementWork at officeFlexible hours- Cydecor, Inc. is seeking an Integrated Air and Missile Defense (IAMD) Capabilities Support to work in the Pentagon supporting OPNAV N99.... ...will assist in assessing programmatic requirements, reviewing EW, cyber operations, TDL and space policy, and preparing cogent...Cyber
$164.38k - $189.75k
...Risk Mitigation Specialist Senior to engage in defense and security efforts within the Pacific theater. You will lead the development and execution of Foreign Ownership... ...in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients...CyberTemporary workImmediate startRemote workWorldwideFlexible hours- ...Our Mission At Dobbs Defense, we deliver mission-centric IT, Cyber, and data analytics solutions for our government and commercial clients through the... ...Description Dobbs Defense Solutions is seeking a Business Analyst to provide support to senior resources on the team in...CyberFull timeWork at office
- ...Position Title Cyber Threat Intelligence & Threat Hunting Lead Position Overview The Cyber Threat Intelligence & Threat Hunting Lead will oversee... ...threat hunting operations supporting enterprise cyber defense missions. The Lead will drive development of...CyberFull time
$99k - $225k
...And when that plan needs to protect our defense infrastructure, we need strategic policy... ...analyze the policies that determine our cyber resilience.As a cyber strategic planning... ...communications technology SCRM policyAbility to lead cross-functional initiatives where goals...CyberFull timeContract workPart timeWork at officeLocal areaRemote work$150k - $175k
...and other secured, classified environments for the defense and national security community. We work with the... ...your site. You do not just manage a building; you lead a resident, cross-functional team of Security, IT/Cyber, Finance, Hospitality, Customer Success, Growth, and...CyberFor contractorsWork at officeLocal areaImmediate startShift work- ...Command, Control, Communications, Computers, Cyber, Intelligence, Surveillance, and... ...Reconnaissance (C5ISR), and Air Domain Awareness & Defense (ADAD) mission areas. Our unique services... ...OWT Global LLC is seeking a Procurement Lead to manage the full procurement lifecycle...CyberContract workTemporary workFor contractorsImmediate start
$94.4k - $217.04k
...Performed: AnaVation is seeking a Cyber Security SME responsible for the overall security defense and monitoring of the... ...assurance program. Experience leading defensive cyber operations... ...Demonstrated ability to mentor junior analysts and guide technical teams...CyberTemporary workWork experience placementLocal areaImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Cyber Defense Forensics Analyst. Be the first to apply!
- information security consultant Washington DC
- cyber security analyst Washington DC
- remote cyber security analyst Washington DC
- cyber forensics Washington DC
- cyber threat intelligence analyst Washington DC
- cyber Washington DC
- cyber sales Washington DC
- defense Washington DC
- defense investigator Washington DC
- criminal defense Washington DC




