Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Digital Forensics and Incident Analyst (Active Top Secret Required)

Agile Defense

Job Description

Job Description

About Agile Defense

At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.

Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.

Requisition #: 

Job Title: Digital Forensics and Incident Analyst

Location: Onsite, Washington, DC

Clearance : Top Secret

Description

The Digital Forensics & Incident Analyst supports the Threat Analysis & Investigations (TA&I) function, analyzing digital evidence and investigating computer security incidents to derive information that supports system and network vulnerability mitigation. The analyst provides Tier 2 and Tier 3 support to the enterprise Security Operations Center (SOC) and coordinates with partner/enterprise security operations centers as required for incident response and advanced analysis. Aligned to the NICE Framework, the role identifies, collects, examines, and preserves digital evidence using controlled and documented analytical and investigative techniques in support of authorized requesting authorities — including oversight bodies, legal and general counsel offices, professional-responsibility offices, FOIA requests, and law enforcement partners. The analyst conducts digital analysis in response to investigations of computer-based crimes and cyber-intrusion incidents, leveraging enterprise forensic and live-monitoring tools while rigorously maintaining chain of custody. Incoming requests are logged into a case management application, and the analyst performs the analytical function supporting the appropriate authorities.

Essential Functions

  • Analyze log files, evidence, and other information to determine the best methods for identifying the perpetrator(s) of a network intrusion. (T0027)
  • Confirm what is known about an intrusion and discover new information via dynamic analysis. (T0036)
  • Provide technical summaries of findings in accordance with established reporting procedures, and deliver written analysis reports to requesting customers. (T0075)
  • Examine recovered data for information relevant to the matter at hand. (T0103)
  • Perform file signature analysis (T0167) and file system forensic analysis across implementations such as NTFS, FAT, and EXT. (T0286)
  • Collect and analyze intrusion artifacts (e.g., source code, malware, system configuration) and use discovered data to enable mitigation of potential cyber defense incidents. (T0432)
  • Conduct malware analysis in the event of a compromise, identify obfuscation techniques, and interpret debugging results to ascertain adversary tactics, techniques, and procedures.
  • Determine the extent of threats and recommend courses of action or countermeasures to mitigate risk; analyze crises to ensure public, personal, and resource protection.
  • Identify data concealment methods (e.g., encryption algorithms, steganography) and conduct memory dumps to extract information.
  • Conduct security event analysis and correlation using enterprise tooling, and apply network security architecture concepts (topology, protocols, components, defense-in-depth) to forensic analysis.
  • Determine physical computer components and architectures, conduct physical disassembly of systems, and identify/modify/manipulate system components within Windows, Unix, or Linux (e.g., passwords, user accounts, files).
  • Apply system administration, network, and operating-system hardening techniques, and use virtual machines (e.g., Hyper-V, VMware vSphere, Citrix Xen, Amazon EC2) in the course of analysis.
  • Conduct hashing for chain-of-custody and validation (e.g., SHA, MD5) and preserve evidence integrity according to standard operating procedures or national standards.
  • Support the full evidence lifecycle — collecting, packaging, transporting, and storing electronic evidence while maintaining chain of custody — and interpret insider-threat investigations, reporting, tools, and applicable laws/regulations.
  • Provide legal governance related to admissibility (e.g., Rules of Evidence) and advise on applicable laws and statutes (e.g., Titles 10, 18, 32, and 50, U.S. Code), Presidential Directives, and executive/administrative/criminal guidelines.
  • Provide risk-management recommendations and apply knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Support forensic application updates and replacements as technology changes; develop workflow diagrams and requirements for continued case management application growth; and support contingency and recovery planning for enterprise forensic and case management applications.
  • Support solution evaluation and piloting — identify key technology components, review and update the System Design Document, assist the ISSO with assessment and authorization (A&A) functions to establish Authority to Test, pilot components to a limited user community, and deliver findings and recommendations to the TA&I Program Manager and staff for review.

Qualifications

  • U.S. citizenship and an active Top Secret (TS) security clearance .
  • Bachelor's degree in Cybersecurity, Computer Science, Digital Forensics, Information Systems, or a related field (additional experience may substitute for degree).
  • 7 years of hands-on digital forensics and incident response (DFIR) experience, ideally in federal or otherwise regulated environments.
  • Required certifications: CFIA and CFIH.
  • Demonstrated expertise with industry-standard forensic and analysis tools (e.g., EnCase, FTK, Autopsy/The Sleuth Kit, X-Ways, Volatility, Wireshark, YARA, and malware reverse-engineering tools such as Ghidra or IDA Pro).
  • Strong command of Windows, Unix, and Linux internals; file systems (NTFS, FAT, EXT); virtualization; and SIEM/event-correlation platforms.
  • Working knowledge of the NICE Framework, NIST guidance, MITRE ATT&CK, chain-of-custody standards, and Rules of Evidence.
  • Excellent technical writing and the ability to present findings clearly to legal, oversight, and investigative authorities.

Our Core Values

Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together.

What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.

  • Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
  • Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
  • Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
  • Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
  • Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
  • Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Digital Forensics and Incident Analyst (Active Top Secret Required) in Washington DC vacancy
  • $104k - $166k

     ...conducts advanced digital technical forensic analysis and...  ...other forensic analysts, law enforcement...  ...bachelor's degree requirement.Must either possess...  ...intrusion activity. Strong critical...  ...citizenship and an active Secret security...  ...Cyber SecurityClearance: Top Secret/SCI
    Digital
    Contract work
    Worldwide
    Overseas
    Shift work

    Peraton Corporation

    Arlington, VA
    3 days ago
  • $104k - $166k

     ...a Mobile Threat Analyst for its' Federal...  ...you will: Conduct forensic examinations of mobile...  ...presentation of digital evidence. Travel...  ...Minimum Requirements:A Bachelor’s degree...  ...pertaining to compromised activity.Demonstrated...  ...required.An active Top Secret security... 
    Digital
    Full time
    Contract work
    Worldwide
    Overseas
    Shift work

    Peraton Corporation

    Arlington, VA
    1 day ago
  • $63.75k - $86.25k

     ...Vehicle Maintenance Analyst Seize your opportunity to make a...  ...YOU'LL NEED TO SUCCEED: Required Experience: 11+ Years'...  ...Security Clearance Level: Active Top Secret with SCI Eligibility Required...  ...offering leading capabilities in digital modernization, AI/ML, Cloud,... 
    Digital
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics

    Washington DC
    1 day ago
  •  ...and new challenges require new solutions....  ...Insider Threat Analyst Location: Onsite...  ...Clearance : Top Secret DESCRIPTION...  ...potential insider threat activity under the...  ...genuine insider threat incidents from false positives...  ...awareness of digital forensics concepts. Understanding... 
    Digital

    Agile Defense

    Washington DC
    19 days ago
  • $86k - $138k

     ...Threat Intelligence Analyst for its Federal Strategic...  ...or malicious activity.Fuse multiple intelligence...  ...forward-deployed incident response and threat...  ...the Cyber Physical Forensics Section as required.Map ICS threat activity...  ...required.An Active Top Secret Security Clearance... 
    Suggested
    Contract work
    Currently hiring
    Shift work

    Peraton Corporation

    Arlington, VA
    2 days ago
  • $80k - $128k

     ...seeking to hire a Watch Analyst for its' Federal...  ...the hub for staying on top of threats and emerging...  ...physical, and communication incidents to identify the...  ...reporting or briefing required. The candidate will work...  ...citizenship is required.An active Top Secret security clearance... 
    Contract work
    Currently hiring
    Work at office
    Local area
    Flexible hours
    Shift work

    Peraton Corporation

    Washington DC
    1 day ago
  • $86k - $138k

     ...level Process Assurance Analyst for its' Federal...  ...manageable risks and resource requirements.Interact with senior...  ...matters.Coordinate activity across organizational...  ...record of reported incidents.Draft organizational...  ...required.An active Top Secret Security Clearance w/... 
    Full time
    Contract work
    Shift work

    Peraton Corporation

    Washington DC
    1 day ago
  • $104k - $166k

     ...seeking an experienced Data Analyst/Cyber Analytics professional...  ...authentication data, phishing activity, threat telemetry) to...  ...translate business and operational requirements into data-driven insights....  ...citizenship required.Active Top Secret security clearance with the... 
    Contract work
    Shift work

    Peraton Corporation

    Arlington, VA
    13 hours ago
  • $112k - $179k

     ...hunting, malware analysis, digital forensics, and incident response within...  ...improvements, and testing activities.Provide subject matter expertise...  ...compliance with security requirements.Fulfill core Peraton management...  ...required.Active Top Secret security clearance.Ability... 
    Digital
    Contract work
    Immediate start
    Shift work

    Peraton Corporation

    Arlington, VA
    2 days ago
  • $100k - $185k

    OverviewLMI is a new breed of digital solutions provider...  ...commitments. Success requires strong compute,...  ...Configuration, change, release, incident, problem, capacity,...  ...50% travel to support activities across multiple...  ...senior leaders. Active Top Secret Clearance (SCI eligibility... 
    Digital
    Contract work
    Night shift

    LMI

    Washington DC
    13 hours ago
  •  ...currently seeking a skilled SOC Analyst with an active Secret or Top Secret clearance to...  ...security events and incidents to evaluate the effectiveness...  ...Top Secret clearance is required.Certifications One or more...  ...training reimbursement, digital mental health and wellbeing... 
    Digital
    Full time
    Local area
    Flexible hours

    Coalfire

    Arlington, VA
    3 days ago
  • $91.4k - $136.9k

     ...Consulting - AI & Data - Data Analyst - Top Secret ClearanceFrom strategy to...  ...business intelligence, and digital analytics built on a blend...  ...and performance measurement activities through advanced analytics....  ...Public Sector, work may be required to be completed at client,... 
    Digital
    For contractors
    Summer holiday
    Work at office
    Local area
    Immediate start
    Flexible hours

    EY (Ernst & Young)

    McLean, VA
    1 day ago
  • Host Forensic Analyst/Host Based Systems Analyst Location...  ..., VA Must have Top Secret Security Clearance...  ...technical assistance on digital evidence matters...  ...documenting on-site incident response activities and providing...  ...suspected malicious code Required Skills U.S.... 
    Digital

    Node.Digital LLC

    Arlington, VA
    1 day ago
  • $80k - $128k

     ...experienced CIRT Tier 1 Analyst to join Peratons'...  ...cyber security events and incidents. Perform triage of...  ...and oversee remediation activities.Conduct shift change briefs...  ...certification required as a condition of employment...  ...required.Active Secret security clearance. Preferred... 
    Contract work
    Local area
    Shift work

    Peraton Corporation

    Beltsville, MD
    1 day ago
  •  ...into opportunity as a Telecommunications Analyst . Shape what’s next for mission-...  ...Equivalent experience •              Required Experience: 2+ Years’ related experience...  ...Security Clearance Level: Active Top Secret with SCI Eligibility •              Required... 

    General Dynamics Information Technology

    Washington DC
    1 day ago
  • $83k - $85k

     ...with printing standards and customer requirements. Determine layout, typography, color...  ...projects. Prepare files for high-speed digital printing by conducting pre-flight...  ...Inserter and Crimper. Qualifications Active Top Secret security clearance. One year of... 
    Digital
    Full time
    Contract work
    Part time
    For contractors
    Remote work

    Akima, LLC

    Washington DC
    1 day ago
  • $130k - $170k

     ...over bureaucracy. Senior Forensic Analyst Location: Washington, DC...  ...Full-time Clearance: Active Top Secret required Salary   Range: $130-...  ...Coordinate with incident response, threat intelligence...  ...degree in Computer Science, Digital Forensics, Information Security... 
    Digital
    Full time
    Work experience placement
    Local area
    Immediate start
    Remote work
    Flexible hours

    Revolutional, LLC

    Washington DC
    29 days ago
  • $148.75k - $201.25k

     ...Currently Possess: Top Secret Clearance Level Must...  ...Public Trust/Other Required: None Job Family...  ...Qualifications: Skills: Active Directory (AD), Azure...  ...critical technical incidents, ensuring the...  ...leading capabilities in digital modernization, AI/ML,... 
    Digital
    Full time
    Temporary work
    Part time
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    GDIT

    Washington DC
    a month ago
  •  ...the United States is seeking a Senior SOC Analyst to monitor, detect, and respond to...  ...senior staff on investigations. This role requires on-site work, DoD clearance readiness,...  ...skills. You will document findings, create incident reports, and support national security... 

    Jobleads-US

    Alexandria, VA
    1 day ago
  • The Clearing, Inc. is seeking an Analyst to support a high-profile, mission-critical project within the Department of War. Analysts...  ...client satisfaction. Successfully candidates will have an active DoD Top Secret clearance (or recent), a bachelor’s degree, 2+ years of... 

    The Clearing, Inc.

    Arlington, VA
    2 days ago
  • $65k - $80k

    Description The Clearing is seeking an Analyst to support a high-profile, mission-critical project within the Department...  ...consulting and The Clearing's methods, techniques, and tools Requirements Active DoD Top Secret Clearance (or have had one within the past two years)... 
    Work experience placement
    Casual work
    Work at office
    Flexible hours
    Afternoon shift

    The Clearing, Inc.

    Arlington, VA
    2 days ago
  • $104k - $166k

     ...an experienced Incident Response Analyst (ICS/OT/SCADA) for...  ...teams, forensic analysts, and mission...  ...to meet mission requirements for incident response...  ...response activities and findings.Prepare...  ...required. Active Top Secret security clearance...  ...performing digital forensics on laptops... 
    Digital
    Contract work
    Currently hiring
    Shift work
    1 day per week

    Peraton Corporation

    Arlington, VA
    2 days ago
  • $90k - $150k

    OverviewLMI is a new breed of digital solutions provider dedicated...  ..., security, and operational requirements. Engineer resilient...  ...Participate in change management, incident response, root-cause analysis...  ...approximately 25-50% travel to support activities across multiple program... 
    Digital
    Contract work
    Remote work
    Night shift

    LMI

    Washington DC
    1 day ago
  •  ...with industry standards and regulatory requirements.  Troubleshoot and resolve issues related...  ...of public/private key cryptography and digital certificates.  Hands-on experience in...  ...Level Must Currently Possess: Top Secret Location: Onsite / occasional hybrid... 
    Digital
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    more than 2 months ago
  • $107.9k - $195.05k

    Leidos' Digital Modernization sector...  ...seeking a SOC Analyst to join our team...  ...a minimum Top Secret with ability to...  ...experience of incident handling/response...  ...headquarters.Required Clearance and...  ...:Must have an active DoD Top Secret...  ...Capture, Network Forensics.Experience... 
    Digital
    Full time
    Work experience placement
    Shift work
    Day shift

    Leidos

    Alexandria, VA
    3 days ago
  •  ...Amentum is seeking SOC / Incident Response Analyst to support our U.S. Department...  ...conduct malicious cyber activities against U.S. energy sector partners.Minimum Requirements (Knowledge, Skills, and...  ...hunting, malware analysis, and digital forensics.Knowledge of MITRE ATT&CK,... 
    Digital
    Contract work
    For contractors

    Amentum Services

    Washington DC
    13 hours ago
  •  ...using your expertise to protect our country from threats. Job Description Communications Logistics Analyst – Active Top Secret / SCI Eligibility Required Seize your opportunity to make a personal impact as a COMMUNICATIONS LOGISTICS ANALYST supporting a... 
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    9 days ago
  • $62k - $141k

    Incident Response Analyst, MidThe Opportunity:Serve as a key member...  ...incident response activities such as alert and incident...  ...IDS/IPS, SOAR, and forensic tools to validate...  ...investigations requiring forensic, malware, and...  ...SOAR platforms, and digital forensics solutionsExperience... 
    Digital
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    6 hours ago
  •  ...Senior Intelligence Data Analyst SiloSmashers is seeking a Senior...  ...the completion of existing requirements as well as the possible...  ...specialized experience) Top Secret Bachelor's degree from an...  ...programs, projects, and/or activities. Ten (10) years or more of... 
    Contract work
    For contractors

    Silo Smashers

    Washington DC
    1 day ago
  • $131.3k - $237.35k

     ...thrive, keep reading!The Digital Modernization Sector...  ...need for a Senior Incident Response Analyst to support the DHS...  ...and adversarial activity on the DHS Enterprise...  ...analysis, or computer forensics.All Department of Homeland...  ...SOC employees are required to favorably pass a... 
    Digital
    Full time
    Flexible hours

    Leidos

    Arlington, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Digital Forensics and Incident Analyst (Active Top Secret Required). Be the first to apply!