Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Digital Forensics and Incident Analyst (TS)

Agile Defense

Job Description

Job Description

About Agile Defense

At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.

Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.

Requisition #: 

Job Title: Digital Forensics and Incident Analyst

Location: Onsite, Washington, DC

Clearance : Top Secret

Description

The Digital Forensics & Incident Analyst supports the Threat Analysis & Investigations (TA&I) function, analyzing digital evidence and investigating computer security incidents to derive information that supports system and network vulnerability mitigation. The analyst provides Tier 2 and Tier 3 support to the enterprise Security Operations Center (SOC) and coordinates with partner/enterprise security operations centers as required for incident response and advanced analysis. Aligned to the NICE Framework, the role identifies, collects, examines, and preserves digital evidence using controlled and documented analytical and investigative techniques in support of authorized requesting authorities — including oversight bodies, legal and general counsel offices, professional-responsibility offices, FOIA requests, and law enforcement partners. The analyst conducts digital analysis in response to investigations of computer-based crimes and cyber-intrusion incidents, leveraging enterprise forensic and live-monitoring tools while rigorously maintaining chain of custody. Incoming requests are logged into a case management application, and the analyst performs the analytical function supporting the appropriate authorities.

Essential Functions

  • Analyze log files, evidence, and other information to determine the best methods for identifying the perpetrator(s) of a network intrusion. (T0027)
  • Confirm what is known about an intrusion and discover new information via dynamic analysis. (T0036)
  • Provide technical summaries of findings in accordance with established reporting procedures, and deliver written analysis reports to requesting customers. (T0075)
  • Examine recovered data for information relevant to the matter at hand. (T0103)
  • Perform file signature analysis (T0167) and file system forensic analysis across implementations such as NTFS, FAT, and EXT. (T0286)
  • Collect and analyze intrusion artifacts (e.g., source code, malware, system configuration) and use discovered data to enable mitigation of potential cyber defense incidents. (T0432)
  • Conduct malware analysis in the event of a compromise, identify obfuscation techniques, and interpret debugging results to ascertain adversary tactics, techniques, and procedures.
  • Determine the extent of threats and recommend courses of action or countermeasures to mitigate risk; analyze crises to ensure public, personal, and resource protection.
  • Identify data concealment methods (e.g., encryption algorithms, steganography) and conduct memory dumps to extract information.
  • Conduct security event analysis and correlation using enterprise tooling, and apply network security architecture concepts (topology, protocols, components, defense-in-depth) to forensic analysis.
  • Determine physical computer components and architectures, conduct physical disassembly of systems, and identify/modify/manipulate system components within Windows, Unix, or Linux (e.g., passwords, user accounts, files).
  • Apply system administration, network, and operating-system hardening techniques, and use virtual machines (e.g., Hyper-V, VMware vSphere, Citrix Xen, Amazon EC2) in the course of analysis.
  • Conduct hashing for chain-of-custody and validation (e.g., SHA, MD5) and preserve evidence integrity according to standard operating procedures or national standards.
  • Support the full evidence lifecycle — collecting, packaging, transporting, and storing electronic evidence while maintaining chain of custody — and interpret insider-threat investigations, reporting, tools, and applicable laws/regulations.
  • Provide legal governance related to admissibility (e.g., Rules of Evidence) and advise on applicable laws and statutes (e.g., Titles 10, 18, 32, and 50, U.S. Code), Presidential Directives, and executive/administrative/criminal guidelines.
  • Provide risk-management recommendations and apply knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Support forensic application updates and replacements as technology changes; develop workflow diagrams and requirements for continued case management application growth; and support contingency and recovery planning for enterprise forensic and case management applications.
  • Support solution evaluation and piloting — identify key technology components, review and update the System Design Document, assist the ISSO with assessment and authorization (A&A) functions to establish Authority to Test, pilot components to a limited user community, and deliver findings and recommendations to the TA&I Program Manager and staff for review.

Qualifications

  • U.S. citizenship and an active Top Secret (TS) security clearance .
  • Bachelor's degree in Cybersecurity, Computer Science, Digital Forensics, Information Systems, or a related field (additional experience may substitute for degree).
  • 7 years of hands-on digital forensics and incident response (DFIR) experience, ideally in federal or otherwise regulated environments.
  • Required certifications: CFIA and CFIH.
  • Demonstrated expertise with industry-standard forensic and analysis tools (e.g., EnCase, FTK, Autopsy/The Sleuth Kit, X-Ways, Volatility, Wireshark, YARA, and malware reverse-engineering tools such as Ghidra or IDA Pro).
  • Strong command of Windows, Unix, and Linux internals; file systems (NTFS, FAT, EXT); virtualization; and SIEM/event-correlation platforms.
  • Working knowledge of the NICE Framework, NIST guidance, MITRE ATT&CK, chain-of-custody standards, and Rules of Evidence.
  • Excellent technical writing and the ability to present findings clearly to legal, oversight, and investigative authorities.

Our Core Values

Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together. 

What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.

  • Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
  • Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
  • Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
  • Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
  • Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
  • Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Digital Forensics and Incident Analyst (TS) in Washington DC vacancy
  • $102.5k - $188.9k

     ...business operations. As a Cyber Exploitation Analyst, you will support cyber defense efforts...  ...threat activity, investigating incidents, assessing vulnerabilities, and help strengthen...  ...traffic analysis, log analysis, digital forensics, Windows, Linux, macOS, common network... 
    Digital
    Work at office

    Deloitte

    Rosslyn, VA
    4 days ago
  •  ...and Impact: Amentum is seeking SOC / Incident Response Analyst to support our U.S. Department of Energy...  ...hunting, malware analysis, and digital forensics.Knowledge of MITRE ATT&CK, NIST Cybersecurity...  ....Security Clearance Required: Active TS/SCI or DOE Q#javelinThis position is... 
    Digital
    Contract work
    For contractors

    Amentum Services

    Washington DC
    4 days ago
  • $86.8k - $198k

    Incident Response Analyst, SeniorThe Opportunity: You will serve as a key member of a 24x7x365 Security...  ...SIEM, EDR, IDS, IPS, SOAR, and forensic tools to validate and escalate security...  ...vulnerability management tools, and digital forensics solutionsExperience with Microsoft... 
    Digital
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    1 day ago
  • $100k - $125k

    A cybersecurity solutions provider is seeking an Incident Response Expert III in Arlington, VA. This role involves serving as a subject matter...  ...response, requiring strong analytical skills and an active TS/SCI clearance. Candidates should have over 8 years of experience... 
    Suggested

    ARGO Cyber Systems

    Arlington, VA
    4 days ago
  • $131.3k - $237.35k

     ...where you can thrive, keep reading!The Digital Modernization Sector brings together...  ...has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program.The Department...  ..., malware analysis, or computer forensics.All Department of Homeland Security... 
    Digital
    Full time
    Flexible hours

    Leidos

    Arlington, VA
    2 days ago
  • $110k - $180k

    OverviewLMI is seeking a Data Analyst responsible for quality delivery of reporting and analysis...  ...deliver reports. LMI is a new breed of digital solutions provider dedicated to...  ...lasting value.This position requires an active TS/SCI clearance; TS/SCI with polygraph preferred... 
    Digital
    Full time
    Contract work
    Work at office

    LMI

    Washington DC
    3 days ago
  • $116.35k - $210.33k

     ...Leidos is seeking a Senior FOIA Analyst to support an Intelligence...  ...program in McLean, VA. An Active TS/SCI with polygraph security...  ...with smarter, more efficient digital and mission innovations. Headquartered...  ...enforcement and report the incident to the U.S. Federal Trade... 
    Digital
    Contract work
    For contractors
    Work at office
    Local area
    Immediate start

    Leidos

    McLean, VA
    3 days ago
  • $88.4k - $154.7k

     ...Parsons is seeking a detail-oriented Agile Delivery Business Analyst to join our Joint Staff Chief Digital and Artificial Intelligence Office (CDAO) team. In this...  ...managementWhat Required Skills You'll Bring:Active TS/SCI security clearanceBachelor’s degree in Business,... 
    Digital
    Full time
    Work at office
    Flexible hours

    Parsons

    Arlington, VA
    2 days ago
  • $140k - $170k

     ...Associate Principal/Cybersecurity & Incident Response (Forensic Services Practice) Boston, MA, United...  ...; Performing forensic analysis of digital information using standard computer...  ...incident responder, network forensic analyst or malware analyst; ~ Experience leading... 
    Digital
    Work at office
    Local area
    Remote work
    Work from home
    3 days per week

    Charles River Associates

    Washington DC
    5 days ago
  •  ...Incident Management AnalystFull-timeQualifications- Must have an active TS/SCI clearance- 5+ years of directly relevant experience in cyber incident management or cybersecurity operations- Knowledge of incident response and handling methodologies- Having close familiarity... 

    Raytheon

    Arlington, VA
    2 days ago
  •  ...Description Job Description Vexterra Group is searching for a Digital Forensic Analysts to provide the following support: ~ Conduct forensic...  ...CCFE, GCFE, GASF, ACE, or CCE etc) Clearance ~ Active TS/SCI ~ Counter Intelligence Polygraph or be willing to obtain... 
    Digital
    Work experience placement

    Vexterra Group

    Bethesda, MD
    29 days ago
  • $104k - $166k

     ...seeking to hire an experienced Incident Response Analyst (ICS/OT/SCADA) for its'...  ...closely with technical teams, forensic analysts, and mission partners...  ....Ability to obtain a TS/SCI for continued employment...  ...Teams.Experience performing digital forensics on laptops/desktops... 
    Digital
    Contract work
    Currently hiring
    Shift work
    1 day per week

    Peraton Corporation

    Arlington, VA
    1 day ago
  • $135k - $175k

     ...leading security investigations, coordinating incident response activities, advancing detection...  .... Conduct threat hunting and forensic investigations to identify malicious, suspicious...  ...of experience in incident response, digital forensics, security operations, or a... 
    Digital
    Full time
    Monday to Friday
    Afternoon shift
    Early shift

    Hogan Lovells

    Washington DC
    3 days ago
  • Cyber Network Forensic Analyst III, TS/SCI Raytheon Technologies provides remote and onsite advanced...  ...assistance, proactive hunting, rapid onsite incident response, and immediate investigation...  ...provide front line response for digital forensics/incident response (DFIR) and... 
    Digital
    Immediate start
    Remote work

    Raytheon Technologies

    Arlington, VA
    4 days ago
  • $120k - $160k

    SAIC is seeking an Intel Analyst located in Bethesda, MD, focused on forensic multimedia and metadata analysis to support...  ...role demands a strong background in digital signal processing and experience...  ...candidate will possess an active TS/SCI with Polygraph clearance. Responsibilities... 
    Digital

    SAIC

    Bethesda, MD
    2 days ago
  • $86.8k - $198k

    Incident Response Analyst, SeniorThe Opportunity:Respond to cybersecurity incidents and proactively prevent the reoccurrence of these incidents. Apply specific functional knowledge to resolve cybersecurity incidents. Analyze or contribute to solutions to a variety of problems... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Washington DC
    2 days ago
  •  ...Pentagon), This is an on-site role with no telecommuting permitted. Core office hours are Monday through Friday.Required Clearance: Active TS/SCISenior Legislative and Strategy AnalystThis role provides expert legislative analysis and strategic support to the Office of the... 
    For contractors
    Work at office
    Remote work
    Monday to Friday
    Flexible hours

    Advanced Decision Vectors

    Arlington, VA
    1 day ago
  • $130k - $152.5k

     ...Senior Associate/Cybersecurity & Incident Response (Forensic Services Practice) Boston, MA, United...  ...; Performing forensic analysis of digital information using standard computer forensics...  ...incident responder, network forensic analyst or malware analyst. ~ Experience... 
    Digital
    Work at office
    Local area
    Work from home
    3 days per week

    Charles River Associates

    Washington DC
    5 days ago
  • Host Forensic Analyst/Host Based Systems Analyst Location: Arlington, VA Must...  ...technical assistance on digital evidence matters and forensic...  ...Tracking and documenting on-site incident response activities and...  ...Citizenshipc` - Must have an active TS/SCI clearance - Must be able... 
    Digital

    Node.Digital

    Arlington, VA
    4 days ago
  • $87.1k - $157.45k

    Leidos is seeking an experienced Incident Response Analyst to support the Defense Manpower Data Center (DMDC) CyberPRIMES program . Leidos is a...  ...government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia,... 
    Digital
    Contract work
    Work at office
    Immediate start

    Koitecc Solutions

    Alexandria, VA
    2 days ago
  • G2IT, LLC. is seeking an experienced Incident Responder to join a mission-focused cyber defense...  ...HGCC in Suitland, MD. You will act as a digital first responder to defend maritime...  ...intelligence, and investigative partners to protect TS/SCI environments, handling escalations,... 
    Digital
    Work at office

    G2IT LLC

    Suitland, MD
    3 days ago
  • $85k - $100k

    Our client, a leading Am Law firm, is seeking a technically minded Forensics Analyst to support growing forensic data needs and hands‑on ESI workflows. This role will lean more heavily toward digital forensics than traditional eDiscovery, with a focus on Microsoft Purview... 
    Digital
    3 days per week

    TruLegal (formerly TRU Staffing)

    Washington DC
    3 days ago
  • $86.6k - $181.8k

     ...timeMinimum Clearance Required to Start: TS/SCIEmployee Type: RegularPercentage of Travel...  ...: CACI is seeking a Technology Data Analyst to support Joint Interagency Task Force 4...  ...computing environments, AI-enabled technologies, digital engineering, Model-Based Systems... 
    Digital
    Contract work
    Work experience placement
    Work at office
    Flexible hours

    CACI International

    Alexandria, VA
    10 hours ago
  •  .... We’re currently seeking a skilled SOC Analyst with an active Secret or Top Secret clearance...  ...) tools to identify security events and incidents to evaluate the effectiveness of current...  ...and training reimbursement, digital mental health and wellbeing support memberships... 
    Digital
    Full time
    Local area
    Flexible hours

    Coalfire

    Arlington, VA
    2 days ago
  • $113k - $188.4k

     ...deliver holistic performance improvement and digital transformation. Join our team of...  ...production issues, and resolve database-related incidents affecting platform operationsManage AWS...  ..., now or at any time in the futureActive TS/SCI with Polygraph security clearance requiredAbility... 
    Digital
    Local area

    Deloitte

    Rosslyn, VA
    5 days ago
  •  ...Host Forensic Analyst/Host Based Systems Analyst Location: Arlington, VA Must...  ...technical assistance on digital evidence matters and forensic...  ...Tracking and documenting on-site incident response activities and...  ...Citizenshipc Must have an active TS/SCI clearance Must be able to... 
    Digital

    Node.Digital

    Arlington, VA
    17 hours ago
  • $164.38k - $189.75k

     ...What You'll Need To Succeed: Security Clearance: Active TS/SCI w/ polygraph On Customer Site Desired Education and...  ...across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development.... 
    Digital
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics

    Washington DC
    4 days ago
  • $85k - $115k

     ...OverviewBy Light has an opening for a CND Analyst - SOC supporting the Army National...  ...the impact of each significant incident and the recovery costs; the...  ...applicationsProvide DMA support services involving forensic analyses on a variety of digital media devices and mediums to... 
    Digital
    Contract work
    Work experience placement
    Remote work
    Worldwide
    Relocation
    Shift work

    By Light Professional IT Services

    Falls Church, VA
    5 days ago
  • $110.18k - $183.63k

     ...currently seeking a Cybersecurity and Risk Analyst to join our team in Arlington, Virginia...  ...(FISMA, HIPAA, PCI-DSS).Contribute to incident response readiness, business continuity,...  ...We are one of the world's leading AI and digital infrastructure providers, with unmatched... 
    Digital
    Full time
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA

    Arlington, VA
    4 days ago
  • $107.9k - $195.05k

    Incident ResponderLocation: Suitland, MDClearance: Active TS/SCI1st Shift Work Hours: 0730 - 1530Leidos is...  ..., you will serve as a digital first responder,...  ...escalations from Tier 1 analysts, conduct spillage response...  ...), GIAC Certified Forensic Analyst (GCFA), GIAC Certified... 
    Digital
    Full time
    Work at office
    Shift work
    Day shift

    Leidos

    Suitland, MD
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Digital Forensics and Incident Analyst (TS). Be the first to apply!