Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Forensics / Incident Response SME

$130k - $155k

Valiant Solutions LLC

Valiant Solutions is seeking a Forensics / Incident Response SME to join our rapidly growing and innovative cybersecurity team!

Do you have experience in IT security and a strong background in Incident Response and Forensics? If so, you may be interested in this dual-focused position that requires active participation in all Incident Response activities, complemented by deep, specialized expertise in Forensic Analysis.

This is your opportunity to join a busy Security Engineering team delivering cutting-edge solutions to a fantastic Government client. Specialized experience in incident response, managing APTs, forensic analysis, and handling evidentiary data is key for this challenging and rewarding role. This role will be responsible for all incident response and management activities, forensic analysis, and other emerging enterprise-wide IT challenges.

We are seeking a motivated individual to join this team, which is constantly evolving and currently developing cloud security solutions in AWS. You’ll be passionate about what you do and will be able to work autonomously to engineer your way out of problems. The IR/Forensics SME shall be responsible for all incident response and management activities, forensic analysis, and other emerging enterprise-wide IT challenges.

Named one of the in the Washington DC area for 12 consecutive years , Valiant is proud of our employee-centric culture and commitment to excellence. If you are interested in learning more about Valiant and this opportunity, we invite you to apply now!

This position allows for 100% remote work. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.

 

Qualifications:

  • 8+ years of specialized experience in incident response, management of the APT, forensic analysis, and handling of evidentiary data, with the most recent experience in the past 4 years.
  • Experience performing IR, Forensics, and post-mortem reports in cloud environments (AWS preferred).
  • Experience with Mobile Device Forensics
  • Ability to identify malware characteristics and conduct reverse engineering in x86 and x64 assembly
  • Ability to demonstrate and conduct Windows memory forensics techniques to analyze malware threats.
  • Strong knowledge of malware code and behavioral analysis.
  • Working knowledge in SIFT, REMnux, or other similar frameworks.
  • Experience in Presentation and Reporting of Evidence and Analysis
  • Experience in File System Timeline Analysis
  • Experience in Live Incident Response and Volatile Evidence Collection
  • Experience in Advanced Windows Registry Analysis
  • Experience in Forensic Imaging and Filesystem Media Analysis
  • Experience performing Advanced Network Event and Protocol analysis and timeline reconstruction
  • Experience and ability to develop, use, and follow Standard Operating Procedures (SOPs)
  • In-depth experience with processing and triage of Security Alerts from multiple sources, but not limited to Endpoint security tools, SIEM, email security solutions, CISA, Threat Intel Sources
  • Demonstrated ability to evaluate events (through a triage process) and identify appropriate prioritization for response
  • Expert understanding of security incident response processes
  • Support and participate in Threat Hunt and Threat Intel operations

 

Responsibilities

  • Participate in a rotating on-call; rotation is based on the number of team members
  • Serve as a hybrid Incident Response Serve (IR) and Digital Forensics (DFIR) function, requiring both real-time incident handling and deep forensic investigative expertise across enterprise and cloud environments. 
  • Provide Incident Management and Forensic Support as required for incidents/investigations, including off-hours
  • Provide Incident Management support, including guidance and expertise to the Incident Response Team and SOC components
  • Development of policies, instructions, standards, and procedures around security functions
  • Develops, maintains, and optimizes the malware and forensic analysis laboratory environment
  • Maintains digital evidence Chain of Custody for forensic activity in accordance with policy, industry standards, and law
  • Perform forensic analysis on a variety of networks, hosts, digital media, and operating systems/environments as but not limited to: Windows, Mac, iOS, Android, Windows Mobile, Linux/Unix, Mainframe, and cloud computing platforms (SaaS, PaaS, IaaS)
  • Prepare detailed written technical reports covering the methodology applied to forensic investigation, findings, and recommendations for further action
  • Provide SME technical analysis for Incident Response and Forensics for Incident / Breach / and Compromise Activities. Including but not limited to malware detection, lateral movement, data collection, and exfiltration detection
  • Provide a complete response to all DFIR tasks
  • Produce and review aggregated performance metrics
  • Work directly with Security and SOC leadership to convert intelligence and results from forensic analysis into useful detection in enterprise security tools
  • Collaborate with the incident response team to rapidly build detection rules as needed
  • Perform customer security assessments
  • Supporting incident response or remediation as needed
  • Participate and develop, and run tabletop exercises
  • Perform lessons learned activities
  • Supporting ad-hoc data and investigation requests
  • Support the enrichment and enhancement of security monitoring tools, including but not limited to evaluation and recommendations on rule tuning and development of new rules/detections

Preferred Certifications:

  • GIAC Certified Forensics Examiner (GCFE)
  • Certified Forensic Analyst (GCFA)
  • Certified Computer Examiner (CCE)
  • AccessData Certified Examiner (ACE) EnCase Certified Examiner (EnCE)
  • Magent Certified Forensic Examiner (MCFE)
  • Magent Certified GRAYKEY Examiner (MCGE)
  • AWS Solution Architect (AWS)
  • SANS GIAC Certified Incident Handler (GCIH)
  • SANS GIAC Certified Intrusion Analyst (GCIA)
  • SANS GIAC Network Forensics Analyst (GNFA)
  • SANS GIAC Certified Enterprise Defender (GCED)
  • SANS GIAC Reverse Engineering Malware (GREM)
  • Carnegie Mellon Certified Computer Incident Handler (CSIH)
  • IACIS Certified Forensic Computer Examiner (CFCE)
  • ISFCE Certified Computer Examiner (CCE)

 

About Valiant Solutions

Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies by Inc. 5000, Washington Technology s Fast 50, and Washington Business Journal s Best Places to Work in the D.C. area, Valiant Solutions prides itself on providing its employees with great benefits and career development opportunities. As a company, we are just as committed to growing careers as we are to building world-class IT solutions, all while enjoying an unparalleled work-life balance. We are in a phase of tremendous growth and building the team that will take us to the next level. We seek people whose talents and accomplishments will contribute to a thriving company, who have the character to support their capacity, and can make a positive impact on our culture. Alongside our talented team, you ll learn to think quickly on your feet and expand your own personal and professional skill set. Our management team will inspire you to consider new perspectives and challenge you to become a better practitioner in the fast-paced industry of IT security. We hire people we respect and we trust them to deliver results leveraging their expertise. If you would enjoy working in a dynamic environment as part of a stellar team of professionals, then we invite you to apply online today.

 

Benefits Snapshot (includes, but not limited to)
Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees
Valiant contributes 25% towards Health Coverage for Family and Dependents
100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees
100% Paid Certifications
401K Matching up to 4%
Paid Time Off
Paid Federal Holidays
Wellness & Fitness Program
Valiant University Online Education and Training Portal
FSA programs for: Medical Costs, Dependent Care, Transit, and Parking
Referral Bonuses

The salary range for this position is a general guideline and not a guarantee of compensation or salary. It has been benchmarked in relation to the scope of the role, market rate, and internal equity. The salary for this role is expected to be in the $130,000 - $155,000 range. Where a candidate falls within the band can be determined based on one or more of the following: skillset, experience level, achievements, education, geographic location, security clearance, involvement in corporate tasks, and other non-discriminatory factors. In addition to the base salary, this role will include benefits as described above. Valiant reserves the right to adjust the salary range, experience requirements, and position responsibilities at any time without prior notice.

 

Remote Work Policy

Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General s effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients.

 

Equal Employment Opportunity

Valiant Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, marital status, or veteran status, in accordance with applicable law.

 

 

 

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Forensics / Incident Response SME in United States vacancy
  •  ...DFIR space that specializes in digital forensics, malware analysis, threat detection, and...  ...fast-paced excitement of supporting incident response activities. As the leader of our Digital...  ..., Incident Response and Threat Hunting SME’s and may have Project Managers, Project... 
    Suggested
    Full time
    Work experience placement
    Immediate start

    CSL

    King of Prussia, PA
    2 days ago
  •  ...Job Description Job Description Incident Response Expert IV (Cyber Eviction Analysts) Location...  ...rapid incident response, advanced forensics, and coordinated recovery operations to...  ...incident response subject matter expert (SME), applying in-depth knowledge on threat... 
    Suggested
    Local area
    Immediate start

    Argo Cyber Systems

    Washington DC
    9 days ago
  • $168k - $243k

    Collaborate with internal and customer teams to investigate and contain incidents.Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations.Lead complex client-facing investigations and examine cloud, endpoint... 
    Suggested
    Remote work

    Google

    California
    1 day ago
  •  ...Cybersecurity Incident Response Specialist We're on the hunt for a Cybersecurity Incident Response Specialist with the curiosity of a...  .... You'll investigate security incidents, perform digital forensics, analyze malware, and help organizations recover from the kind... 
    Suggested
    Remote work

    SafeGraph

    United States
    5 days ago
  • $100k - $126.5k

     ...solutions to complex business concerns.Practice OverviewCRA’s Forensic Services practice primary purpose is to support our clients’...  ...are seeking a Consulting Associate to join our Cyber Incident Response & eDiscovery team in Chicago, Boston, Washington, DC, or New... 
    Suggested
    Work at office
    Work from home
    3 days per week

    CRA International

    Dallas, TX
    2 days ago
  • # Consulting Associate/Cybersecurity & Incident Response (Forensic Services practice)*Charles River Associates***Washington, DC**Onsite · Mid · Internship### The RoleThis consulting role sits within a forensic services practice and involves conducting digital forensic examinations... 
    Internship

    Forensic Focus Limited

    Eastern, KY
    2 days ago
  •  ...seeking an experienced Senior SOC professional to lead 3rd tier incident response for large-scale cyber events. You will analyze compromised...  ...global clients. The role emphasizes incident response, forensics, and development of playbooks and tabletop exercises to strengthen... 

    Check Point Software

    Dallas, TX
    4 days ago
  •  ...Cyber Incident Response Analyst Location: Austin, TX / San Antonio, TX (Onsite) Duration: 12 Months Contract Interview: Onsite Cyber Incident Response, Digital Forensics, Windows & Linux Security, SIEM, EDR, IDS/IPS, Threat Hunting, Malware... 
    Contract work

    3B Staffing LLC

    Austin, TX
    4 days ago
  • Booz Allen Hamilton is seeking a Mid-level Digital Forensic Examiner to join our DFIR team. You will collect, analyze, and present...  ...problems and may guide junior staff. You will conduct cyber incident response investigations, analyze malware and logs, and prepare... 

    Booz Allen Hamilton

    Seattle, WA
    1 day ago
  • AstraZeneca is seeking a Senior Director, Digital Forensics & Incident Response to own the global cyber-incident capability across cloud, on-premises and OT/ICS environments. You’ll build the function, hire the team and set the standards, reporting to senior IT leadership... 

    AstraZeneca GmbH

    Gaithersburg, MD
    2 days ago
  •  ...message the job poster from V Group Inc. Recruiting for NY - MTA, VITA, State of NC, SC, MI, MS, TN at V Group Job Title: Incident Response & Forensics Analyst Duration: 6+ Months Location: Remote with Occasional visit to NYC Position Type: Contract Interview Type: In-... 
    Contract work
    Work at office
    Local area
    Remote work

    V Group Inc.

    New York, NY
    4 days ago
  •  ...Behring seeks a highly technical leader to head the Digital Forensics and eDiscovery team, directing strategy, people, processes and...  ..., Data Loss Prevention and Threat Intelligence to advance incident response capabilities globally. You will lead a global team of digital... 

    CSL Plasma

    King of Prussia, PA
    5 days ago
  • CSL invites a highly technical leader to guide a global Digital Forensics, Incident Response and eDiscovery team. You will own strategy, people, processes, and tech, collaborating with Security Operations, DLP, and Threat Intelligence to defend CSL. You will direct adoption... 

    CSL

    King of Prussia, PA
    2 days ago
  • $100k - $126.5k

     ...launchyour career.Position OverviewCRA’s Forensic Services practice supports companies’...  ...CRA clients, in preparation of, and in response to, data security matters, which may include...  ...breach detection, threat analysis, incident response and malware analysis;Providing... 
    Work at office
    Work from home
    3 days per week

    CRA International

    Boston, MA
    2 days ago
  • About the Role:The Senior Director, Digital Forensics & Incident Response owns AstraZeneca’s global capability to respond to and investigate cyber incidents. This role commands the enterprise response to material incidents across cloud, on-premises and OT/ICS environments... 
    Hourly pay
    Permanent employment
    Full time
    Temporary work
    Work at office
    Flexible hours
    3 days per week

    AstraZeneca

    Gaithersburg, MD
    4 days ago
  • $140k - $170k

     ...launchyour career.Position OverviewCRA’s Forensic Services practice supports companies’...  ...forensic & cyber investigations space, your responsibilities as an Associate Principal may include (...  ...breach detection, threat analysis, incident response and malware analysis;... 
    Work at office
    Local area
    Remote work
    Work from home
    3 days per week

    CRA International

    Chicago, IL
    2 days ago
  • BlueVoyant is seeking a Senior Director, Digital Forensics & Incident Response to spearhead cyber investigations in a client-facing leadership role. This position requires managing complex security incidents while advising executives and legal teams. The ideal candidate... 
    Remote job

    BlueVoyant

    New York, NY
    4 days ago
  • kozmetickesluzby.vecnakraska.sk - Jobboard is seeking a Cyber Triage and Forensics Incident Analyst to lead security incident responses at EY. The role involves performing forensic analysis, malware analysis, and investigating security incidents, ensuring robust incident... 
    Flexible hours

    kozmetickesluzby.vecnakraska.sk - Jobboard

    Los Angeles, CA
    3 days ago
  •  ...and work remotely one day. A member of our recruitment team will provide more details.The Global Director of Autonomous Incident Response and Forensic Analysis leads the strategy, execution, and continuous improvement of a 24/7 global incident response (IR) and digital... 
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Tempe, AZ
    13 hours ago
  • $162.8k - $303k

    Global Incident Response Business Development LeaderThe Opportunity: Serve as the Global Business Development Leader for Booz Allen's commercial...  ...and define and execute the growth strategy for Digital Forensics and Incident Response (DFIR) in the U.S. and European... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Pensacola, FL
    13 hours ago
  • EY leads complex cyber incident response engagements, guiding clients through post-incident review and remediation. The role focuses on data exposure assessment, regulatory obligations, and coordinated communications with stakeholders. You will work with cross-functional... 

    EY

    Woodbridge, NJ
    1 day ago
  • $108.15k - $165.47k

    Rutgers University is hiring a Senior Incident Response Analyst. The analyst runs daily incident detection and response operations for Rutgers...  ...Analysts. Provide expert-level analytic, investigative, and forensic support on complex security incidents. Advise business units... 
    Work at office

    Rutgers University

    Piscataway, NJ
    4 days ago
  •  ...player in cybersecurity is seeking a skilled professional to join their dynamic incident response team. This role focuses on engaging with clients post-cyber-attack, utilizing advanced forensic methodologies to analyze and remediate threats. The ideal candidate will have... 
    Remote job

    Ransomware Recovery

    Houston, TX
    4 days ago
  • Senior Digital Forensic Analyst job at Triskele Labs. Los Angeles, CA. Triskele Labs are one of the leading providers of cybersecurity...  ...completely onshore. The Triskele Labs Digital Forensics and Incident Response (DFIR) team assists clients of all sizes to prevent and... 
    Remote job
    Work at office

    Triskele Labs

    Los Angeles, CA
    2 days ago
  •  ...-focused analyst at Dahlgren, VA, to perform expert digital forensics and cybersecurity investigations on computer systems and networks...  ..., preserving, and reporting on evidence while supporting incident response and tool evaluation. The position is full-time with benefits... 
    Full time
    Contract work

    Strategic Data Systems

    Dahlgren, VA
    3 days ago
  • Nightwing Group is seeking a Cyber Host Forensic Analyst II to support a U.S. Government client in Arlington, VA. The role focuses on onsite incident response, forensic analysis, and documenting findings to drive remediation. The candidate will collect and analyze digital... 

    Nightwing Group

    Arlington, VA
    3 days ago
  • Lead incident response activities through triage, investigation, containment, remediation, recovery, and post-incident analysis Investigate...  ..., email, and SaaS environments Conduct threat hunting and forensic investigations to identify malicious, suspicious, or unauthorized... 
    Afternoon shift
    Early shift

    Jobtailor

    Denver, CO
    3 days ago
  • EY is seeking an experienced Senior to lead client engagements involving cyber incidents, data breaches, and information security events. This role focuses on the post‑incident response phase, helping clients assess impacted data, evaluate legal and regulatory obligations... 

    EY

    Los Angeles, CA
    1 day ago
  • EY is seeking a Senior for Forensics - Crisis and Investigations - Cyber Response to lead client engagements involving cyber incidents and data breaches. You will focus on post-incident activities, assess affected data, and coordinate remediation with cross-functional teams... 

    Ernst & Young Advisory Services Sdn Bhd

    Mc Lean, VA
    4 days ago
  • $88.5k - $184.38k

     ...development through continuous learning in forensic methodologies, threat hunting, and modern security automation Responsibilities Monitor, triage, and analyze security events...  ...alert telemetry, and draft initial incident timelines. Assess security incidents, perform... 
    Work at office
    Flexible hours
    Shift work
    Night shift
    Weekend work

    Yahoo Holdings Inc.

    Richardson, TX
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Forensics / Incident Response SME. Be the first to apply!