Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Cyber Defense Forensics Analyst

$110k - $150k

Revolutional, LLC

Job Description

Job Description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.

We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

Lead Cyber Defense Forensics Analyst

Location: Onsite – Government-controlled secure facility

Terms: Full-time

Salary: $110-$150k DOE

Clearance: Active Top Secret/SCI required

Travel: 0-10%

Project Description

This position serves as the senior forensic practitioner on a federal enterprise cybersecurity program operating within government-controlled secure facilities. The forensics function supports the full cyber defense mission — conducting complex digital forensic investigations, driving incident response analysis, and contributing to threat hunt operations at the classified level. This is a hands-on technical lead role, not an organizational management position.

The core challenge: leading forensic investigations of the highest technical complexity within a classified environment — setting the analytic standard, producing legally defensible findings, and ensuring that forensic work directly informs and accelerates the program's incident response and threat hunt capabilities.

Position Description

As Lead Cyber Defense Forensics Analyst at Revolutional, you are the program's most senior forensic practitioner. You own the most complex investigations, set the technical standard for forensic methodology, and serve as the subject matter authority on computer forensics, network analysis, and evidentiary handling across the cyber defense mission. You work alongside — not above — the SOC Chief, contributing deep technical expertise where it matters most: inside the investigation.

You bring 5 to 7 years of hands-on experience across digital forensics, incident response, and threat hunting, and you operate in full alignment with the NICE Cybersecurity Workforce Framework Cyber Defense Forensics Analyst role (IN-FOR-002). Your core competencies span Computer Forensics, Computer Network Defense, Software Testing and Evaluation, System Administration, and Threat Analysis — and you apply all of them under classified conditions, within government-controlled secure facilities, every day.

Responsibilities
  • Lead digital forensic investigations of the highest technical complexity; conduct end-to-end analysis from evidence acquisition through findings documentation within classified, government-controlled secure facilities
  • Perform host-based forensic analysis: disk and memory acquisition, file system examination, artifact recovery, malware triage, and attack timeline reconstruction across Windows and Linux environments
  • Conduct network forensic analysis: packet capture review, NetFlow correlation, log analysis, and identification of lateral movement, exfiltration, and command-and-control activity
  • Maintain strict chain of custody for all evidence collected and handled; ensure all forensic work meets applicable federal legal and evidentiary standards
  • Provide direct analytical support to incident response operations; contribute forensic findings that drive containment, eradication, and recovery decisions in real time
  • Support threat hunt activities with forensic analysis: investigate hunt leads, validate hypotheses, and extract IOCs that feed detection improvements
  • Apply Software Testing and Evaluation methodology to validate forensic tools and assess new capabilities before operational deployment
  • Apply system administration knowledge across Windows and Linux environments to scope investigations, interpret artifacts, and assess attacker activity accurately
  • Apply Threat Analysis tradecraft to map forensic findings to adversary TTPs using MITRE ATT&CK and other structured frameworks
  • Produce thorough, legally defensible forensic reports documenting methodology, findings, evidence handling, and recommended response actions
  • Maintain current awareness of adversary tradecraft, malware families, forensic evasion techniques, and emerging investigation methodologies
  • Ensure compliance with NICE Cybersecurity Workforce Framework IN-FOR-002 role definition and associated role-based training requirements
What You Bring (Requirements)Baseline Requirements
  • Bachelor's degree in Computer Science, Digital Forensics, Information Security, or related field (or equivalent experience)
  • 5 to 7 years of hands-on experience in digital forensics, incident response, and threat hunting, with demonstrated lead-level technical proficiency
  • Active Top Secret/SCI clearance (Final) required
  • Must work onsite within a government-controlled secure facility
Technical & Domain Capabilities
  • Expert-level Computer Forensics: disk and memory acquisition, file system and artifact analysis, malware triage, timeline reconstruction, and chain of custody management to legal and evidentiary standards
  • Core competency in Computer Network Defense: intrusion detection, alert triage, network traffic analysis, and defensive posture assessment applied to forensic investigation scoping and findings
  • Experience with Software Testing and Evaluation applied to forensic tool validation, capability testing, and pre-deployment assessment of new investigation technologies
  • Working knowledge of System Administration across Windows and Linux environments sufficient to accurately scope investigations, interpret system artifacts, and reconstruct attacker activity
  • Core competency in Threat Analysis: MITRE ATT&CK-based TTP mapping, threat actor profiling, and structured analytic frameworks applied to forensic findings
  • Proficiency with industry-standard forensic tools: EnCase, FTK, Autopsy, Volatility, Wireshark, or equivalent
  • Experience operating within the NICE Cybersecurity Workforce Framework IN-FOR-002 role definition; current on applicable role-based training requirements
Core Strengths
  • Technically elite forensic practitioner — your investigations are thorough, your methodology is sound, and your findings hold up under legal and operational scrutiny
  • Analytically independent: you take complex, ambiguous investigations and drive them to conclusion without needing the situation pre-defined
  • Rigorous in classified environments — chain of custody, access controls, and handling requirements are instinctive, not procedural
  • Effective technical contributor to incident response and threat hunt teams; your forensic findings accelerate the broader mission, not just your own workstream
Certifications

One or more of the following is required or strongly preferred:

  • GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner), EnCE (EnCase Certified Examiner), CFCE (Certified Forensic Computer Examiner), or GCIH (GIAC Certified Incident Handler)
  • Role-based training required per NICE Cybersecurity Workforce Framework IN-FOR-002 — must be current or completed within required timeframes
Nice to Have (Differentiators)
  • GREM (GIAC Reverse Engineering Malware) or equivalent advanced malware analysis credential
  • GNFA (GIAC Network Forensic Analyst) for candidates with deep network forensics depth
  • Experience conducting forensic investigations at TS/SCI level within SCIFs or other government-controlled secure facilities
  • Background in mobile device forensics, cloud forensics, or memory forensics at advanced levels
  • Experience supporting legal proceedings or law enforcement actions with forensic evidence and findings documentation
  • Familiarity with emerging forensic evasion techniques and anti-forensics tradecraft used by advanced threat actors

#DICE #LinkedIn

___________________________________________________________________________________________________________

Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include:

  • Recognized as a Top 20 "Best Place to Work in Virginia"
  • Recipient of Department of Labor's HireVets Gold Medallion
  • Great Place to Work Certification for five years running
  • A Virginia Chamber of Commerce Fantastic 50 company
  • A Northern Virginia Technology Council Tech 100 company
  • Inc. 5000 list of fastest growing companies for eleven years
  • Two-time SBA SBIR Tibbett's Award winner
  • Virginia Values Veterans (V3) Certification

We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to

  • Traditional and HSA- eligible medical insurance plans
  • 100% employer-paid dental and vision insurance options
  • 100% employer-sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible-schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental Leave
  • Professional development and career growth opportunities
  • Team and company-wide events, recognition, and appreciation-- and so much more!

Check out our Revolutional | LinkedIn to find out a little more about who we are and if we are the right next step for your career!

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact View email address on ziprecruiter.com.

Vacancy posted 13 days ago
Similar jobs that could be interesting for youBased on the Lead Cyber Defense Forensics Analyst in Suitland, MD vacancy
  • Node.Digital LLC is seeking a Host Forensic Analyst to support critical federal engagements in Arlington, VA. The role requires leading forensic teams, conducting cyber investigations, and delivering detailed reports on findings. Candidates must have a TS/SCI clearance,... 
    Cyber

    Node.Digital LLC

    Arlington, VA
    4 days ago
  • $138k - $209k

     ...Information Sciences) is seeking a qualified Security Architect to lead incident response activities and manage cybersecurity threats...  ...years in incident response and extensive knowledge of digital forensics and malware analysis. Competitive salary range is $138,000-$209... 
    Cyber

    AIS (Applied Information Sciences)

    Alexandria, VA
    3 days ago
  • bcmcllc is seeking Host Forensics Analysts to support the DHS’s Hunt and Incident Response Team (HIRT). This role focuses on forensic investigations...  ...Candidates should possess at least 8 years of experience in cyber forensic investigations, with specific knowledge of forensic... 
    Cyber

    bcmcllc

    Arlington, VA
    3 days ago
  • $92k - $153k

    Job Family:IT Cyber SecurityTravel Required:Up to 10%Clearance Required:Ability to Obtain...  ...or high-risk incidents to senior analysts or incident response teams when appropriate...  ...related field preferred.Have prior experience leading SOC shifts and mentoring jr. analysts.Must... 
    Cyber
    Full time
    Work experience placement
    Flexible hours
    Shift work

    Guidehouse

    Washington DC
    1 day ago
  • A leading social media company is seeking a Lead Cyber Security Operations Center Analyst to oversee incident responses and investigations. This role involves leading a team of analysts, developing detection strategies, and ensuring the safety of user data on the platform... 
    Cyber

    Tik Tok

    Washington DC
    2 days ago
  • $157k - $224k

    Systemstechnologyresearch is seeking a Lead All-source Analyst and Modeling Engineer to develop models of cyber physical systems. Candidates must have an Active Top Secret security clearance and at least 8 years of relevant experience in a technical field like Computer... 
    Cyber

    Systemstechnologyresearch

    Arlington, VA
    4 days ago
  •  ...Resilience team is looking to hire an Incident / Crisis Management Lead to help drive the continuous enhancement of the crisis event...  ...response to major disruption events (e.g., global technology outages, cyber-attacks, geopolitical issues etc). Coordinate cross-... 
    Cyber
    Temporary work
    Local area
    Visa sponsorship
    Work visa
    Flexible hours

    WTW inc.

    Arlington, VA
    1 day ago
  • $69.4k - $158k

    Modeling and Simulation Analyst, LeadThe Opportunity:As a lead modeling and simulation analyst, you will use your passion for uncovering root causes,...  ...simulation activities that support quantitative assessments for defense mission objectives. Using the Advanced Framework for... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Alexandria, VA
    20 hours ago
  • DescriptionJob DescriptionAre you ready to make an impact on defense policy? The Red Gate Group is seeking a Legislative Analyst to support the Acquisition Policy & Innovation (...  ...) (OUSD(A&S)). In this pivotal role, you will lead a team of legislative analysts to provide expert... 
    Work at office
    Local area
    Immediate start
    Flexible hours

    Red Gate

    Arlington, VA
    20 hours ago
  • Zachary Piper Solutions seeks a SOC Lead to oversee 24/7 security operations for a DOE/NNSA-focused program. You will mentor a team of cybersecurity professionals, drive incident response, and enhance enterprise security operations in a mission-critical setting. Ideal... 
    Cyber

    Zachary Piper Solutions

    Washington DC
    7 hours ago
  • $166k - $220k

    Anduril Industries is a defense technology company with a mission to transform U.S. and allied...  ...not years.ABOUT THE TEAMThe Operations, Cyber & Security team is responsible for safely...  ....ABOUT THE JOBWe are hiring a Deployment Lead to own end-to-end readiness and the day-... 
    Cyber
    Full time
    Work experience placement
    Local area
    Immediate start

    Anduril Industries

    Washington DC
    1 day ago
  •  ...is hiring a Senior CFIUS-Export Control Analyst to lead our team of qualified, diverse, and highly...  ...the Office of the Under Secretary of Defense, Research and Engineering (OUSD(R&E)). The...  ...foreign ownership, control, influence, cyber penetration, and other exploitation threats... 
    Cyber
    Work at office
    Local area

    Science Applications International Corporation

    Alexandria, VA
    2 days ago
  •  ...(CSA) is currently seeking an Analyst I to support onsite in the Arlington...  ...support services to meet the defense and federal sector's most...  ...applicable directives.Support cyber and compliance activities, including...  ....Collaborate with government leads, program management, and... 
    Cyber
    Contract work
    For subcontractor
    Work at office
    Remote work

    Client Solution Architects

    Arlington, VA
    3 days ago
  •  ...Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat Emulation...  ...oversee adversary emulation, red team operations, cyber readiness exercises, and threat-informed defense initiatives supporting a federal enterprise... 
    Cyber
    Full time

    cFocus Software Incorporated

    Washington DC
    a month ago
  • $157k - $224k

    STR is seeking a Lead All-source Analyst and Modeling Engineer who has a passion for research and development of models of cyber physical systems. Work must be performed onsite. What you will do: Develop tools to help sift through large datasets to identify information... 
    Cyber
    Full time
    Work experience placement
    Work at office
    Local area

    Systemstechnologyresearch

    Arlington, VA
    4 days ago
  •  ...Zero Trust Analyst Zero Trust Analyst Location: Arlington, VA (On-Site) Citizenship...  ...Suitability required) Company: Argo Cyber Systems, LLC - Service-Disabled Veteran-Owned...  ...rapid incident response, advanced forensics, and coordinated recovery operations to protect... 
    Cyber
    Contract work
    For contractors

    Argo Cyber Systems

    Arlington, VA
    3 days ago
  • $150k - $170k

     ...Zachary Piper Solutions is seeking a SOC Lead to support a company focused on federal cybersecurity operations, network defense, and protection of critical national security...  ...defending sensitive systems against evolving cyber threats. Responsibilities for the SOC Lead... 
    Cyber
    Night shift

    Piper Companies

    Washington DC
    2 days ago
  • $90k - $100k

     ...Overview Job Title: Program Analyst Location: Arlington, VA Introduction: Rivet Operations Company...  ...an exceptional industry partner to the Department of Defense (DoD) and a leader in physical and cyber security, IT management, logistics, supply chain management... 
    Cyber
    Work at office
    Long distance

    Rivet Industries

    Arlington, VA
    3 days ago
  •  ...Military Forces Analyst Bridge Defense is redefining how modern defense technology is delivered. Based in Washington, D.C., we are built for...  ...data center operations, scientific analysis, cutting-edge cyber defense, and intelligence analysis. We are led by technologists... 
    Cyber
    Relocation
    Flexible hours

    ClearanceJobs

    Washington DC
    1 day ago
  •  ...Arlington is seeking a Host Based Systems Analyst IV to provide cybersecurity analysis and response. The role involves leading forensic teams, technical assistance on data collection...  ...will have extensive experience with cyber forensic investigations and must demonstrate... 
    Cyber

    Solutions , LLC

    Arlington, VA
    4 days ago
  •  ...Inc.is seeking a Senior Legislative Rearch Analyst to support the full range of...  ...understanding and generate Congressional support for Defense Intelligence resources and legislative...  ...advancements in Logistics, Human Capital, Cyber, Intelligence & Technology. EOE Statement... 
    Cyber

    Rividium Inc

    Washington DC
    4 days ago
  • $100.5k - $153.25k

     ...seeking a highly skilled Sr. Enterprise Analyst to support Payroll and Time & Absence Management...  ...The best of the best.We don’t just build defense technology—we redefine what’s possible....  ...across air, land, sea, space, and cyber. From AI-powered drones and loitering munitions... 
    Cyber
    Permanent employment
    Full time
    Contract work
    Work experience placement
    Work at office

    AeroVironment

    Arlington, VA
    2 days ago
  •  ...headquartered in Reston, Virginia, SOSi is a private defense and government solutions business...  ...a highly qualified senior-level Team Lead to support a designated Operations office...  ...disciplinary intelligence (all-source, C4I, cyber, HUMINT, SIGINT, GEOINT, OSINT, etc.).... 
    Cyber
    Contract work
    For contractors
    Work at office

    SOSi

    Washington DC
    1 day ago
  • $116.5k - $177.5k

     ...every single day. Together, we are leading the transformation of modern...  ...From Space and Directed Energy to Cyber and Intelligence to C4ISR and Air & Missile Defense, there is no limit to where you...  ...launch a career at AV?As the Program Analyst, you will play a highly visible... 
    Cyber
    Permanent employment
    Full time
    Contract work
    Work experience placement
    For subcontractor
    Remote work

    AeroVironment

    Arlington, VA
    4 days ago
  • A leading cybersecurity firm in Washington, DC, is seeking a mid-level Cyber Defense Forensics Analyst to enhance their security team for a long-term contract. The role involves threat detection, forensics analysis, and supporting governmental cybersecurity initiatives... 
    Cyber
    Long term contract

    ECS

    Washington DC
    2 days ago
  • Chenega MIOS in Washington, DC is seeking an Intermediate Threat Hunt Analyst to analyze detailed information on known and emerging APT actors, develop attack hypotheses, and conduct threat hunting using threat intelligence, MITRE ATT&CK, and related methods. The role collaborates... 
    Cyber

    Chenega Agile Real Time Solutions, LLC

    Washington DC
    4 days ago
  • A defense contracting firm seeks a Senior All-Source Analyst to support USCYBERCOM J2. The role involves conducting intelligence analysis, providing analytic support for national security, and requires a minimum of 12 years of experience, alongside an active TS/SCI clearance... 
    Cyber
    Work at office

    Kinsley Power Systems

    Alexandria, VA
    3 days ago
  • $100k - $120k

    SkyePoint Decisions, Inc. is seeking a Mobile Threat Analyst in Arlington, VA, to support the Diplomatic Security Cyber Mission. The role involves conducting forensic examinations of mobile devices and analyzing malicious behavior within applications. Candidates should... 
    Cyber
    Flexible hours

    SkyePoint Decisions

    Arlington, VA
    2 days ago
  • Cydecor, Inc. is seeking an Integrated Air and Missile Defense (IAMD) Capabilities Support to work in the Pentagon supporting OPNAV N99....  ...will assist in assessing programmatic requirements, reviewing EW, cyber operations, TDL and space policy, and preparing cogent... 
    Cyber

    Cydecor, Inc.

    Arlington, VA
    1 day ago
  • Booz Allen Hamilton is seeking a Business Strategy Analyst to shape growth and direction for the National Security Sector’s Cyber Department of War Account. You will conduct strategic analysis, evaluate market and competitive dynamics, and translate insights into actionable... 
    Cyber

    Booz Allen Hamilton

    Arlington, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Cyber Defense Forensics Analyst. Be the first to apply!