Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Cyber Defense Forensics Analyst

$110k - $150k

Revolutional, LLC

Job Description

Job Description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.

We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

Lead Cyber Defense Forensics Analyst

Location: Onsite – Government-controlled secure facility

Terms: Full-time

Salary: $110-$150k DOE

Clearance: Active Top Secret/SCI required 

Travel: 0-10%

Project Description

This position serves as the senior forensic practitioner on a federal enterprise cybersecurity program operating within government-controlled secure facilities. The forensics function supports the full cyber defense mission — conducting complex digital forensic investigations, driving incident response analysis, and contributing to threat hunt operations at the classified level. This is a hands-on technical lead role, not an organizational management position.

The core challenge: leading forensic investigations of the highest technical complexity within a classified environment — setting the analytic standard, producing legally defensible findings, and ensuring that forensic work directly informs and accelerates the program's incident response and threat hunt capabilities.

Position Description

As Lead Cyber Defense Forensics Analyst at Revolutional, you are the program's most senior forensic practitioner. You own the most complex investigations, set the technical standard for forensic methodology, and serve as the subject matter authority on computer forensics, network analysis, and evidentiary handling across the cyber defense mission. You work alongside — not above — the SOC Chief, contributing deep technical expertise where it matters most: inside the investigation.

You bring 5 to 7 years of hands-on experience across digital forensics, incident response, and threat hunting, and you operate in full alignment with the NICE Cybersecurity Workforce Framework Cyber Defense Forensics Analyst role (IN-FOR-002). Your core competencies span Computer Forensics, Computer Network Defense, Software Testing and Evaluation, System Administration, and Threat Analysis — and you apply all of them under classified conditions, within government-controlled secure facilities, every day.

Responsibilities
  • Lead digital forensic investigations of the highest technical complexity; conduct end-to-end analysis from evidence acquisition through findings documentation within classified, government-controlled secure facilities
  • Perform host-based forensic analysis: disk and memory acquisition, file system examination, artifact recovery, malware triage, and attack timeline reconstruction across Windows and Linux environments
  • Conduct network forensic analysis: packet capture review, NetFlow correlation, log analysis, and identification of lateral movement, exfiltration, and command-and-control activity
  • Maintain strict chain of custody for all evidence collected and handled; ensure all forensic work meets applicable federal legal and evidentiary standards
  • Provide direct analytical support to incident response operations; contribute forensic findings that drive containment, eradication, and recovery decisions in real time
  • Support threat hunt activities with forensic analysis: investigate hunt leads, validate hypotheses, and extract IOCs that feed detection improvements
  • Apply Software Testing and Evaluation methodology to validate forensic tools and assess new capabilities before operational deployment
  • Apply system administration knowledge across Windows and Linux environments to scope investigations, interpret artifacts, and assess attacker activity accurately
  • Apply Threat Analysis tradecraft to map forensic findings to adversary TTPs using MITRE ATT&CK and other structured frameworks
  • Produce thorough, legally defensible forensic reports documenting methodology, findings, evidence handling, and recommended response actions
  • Maintain current awareness of adversary tradecraft, malware families, forensic evasion techniques, and emerging investigation methodologies
  • Ensure compliance with NICE Cybersecurity Workforce Framework IN-FOR-002 role definition and associated role-based training requirements
What You Bring (Requirements)Baseline Requirements
  • Bachelor's degree in Computer Science, Digital Forensics, Information Security, or related field (or equivalent experience)
  • 5 to 7 years of hands-on experience in digital forensics, incident response, and threat hunting, with demonstrated lead-level technical proficiency
  • Active Top Secret/SCI clearance (Final) required
  • Must work onsite within a government-controlled secure facility
Technical & Domain Capabilities
  • Expert-level Computer Forensics: disk and memory acquisition, file system and artifact analysis, malware triage, timeline reconstruction, and chain of custody management to legal and evidentiary standards
  • Core competency in Computer Network Defense: intrusion detection, alert triage, network traffic analysis, and defensive posture assessment applied to forensic investigation scoping and findings
  • Experience with Software Testing and Evaluation applied to forensic tool validation, capability testing, and pre-deployment assessment of new investigation technologies
  • Working knowledge of System Administration across Windows and Linux environments sufficient to accurately scope investigations, interpret system artifacts, and reconstruct attacker activity
  • Core competency in Threat Analysis: MITRE ATT&CK-based TTP mapping, threat actor profiling, and structured analytic frameworks applied to forensic findings
  • Proficiency with industry-standard forensic tools: EnCase, FTK, Autopsy, Volatility, Wireshark, or equivalent
  • Experience operating within the NICE Cybersecurity Workforce Framework IN-FOR-002 role definition; current on applicable role-based training requirements
Core Strengths
  • Technically elite forensic practitioner — your investigations are thorough, your methodology is sound, and your findings hold up under legal and operational scrutiny
  • Analytically independent: you take complex, ambiguous investigations and drive them to conclusion without needing the situation pre-defined
  • Rigorous in classified environments — chain of custody, access controls, and handling requirements are instinctive, not procedural
  • Effective technical contributor to incident response and threat hunt teams; your forensic findings accelerate the broader mission, not just your own workstream
Certifications

One or more of the following is required or strongly preferred:

  • GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner), EnCE (EnCase Certified Examiner), CFCE (Certified Forensic Computer Examiner), or GCIH (GIAC Certified Incident Handler)
  • Role-based training required per NICE Cybersecurity Workforce Framework IN-FOR-002 — must be current or completed within required timeframes
Nice to Have (Differentiators)
  • GREM (GIAC Reverse Engineering Malware) or equivalent advanced malware analysis credential
  • GNFA (GIAC Network Forensic Analyst) for candidates with deep network forensics depth
  • Experience conducting forensic investigations at TS/SCI level within SCIFs or other government-controlled secure facilities
  • Background in mobile device forensics, cloud forensics, or memory forensics at advanced levels
  • Experience supporting legal proceedings or law enforcement actions with forensic evidence and findings documentation
  • Familiarity with emerging forensic evasion techniques and anti-forensics tradecraft used by advanced threat actors

#DICE #LinkedIn

___________________________________________________________________________________________________________

Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day.  Some of these recognitions include:  

  • Recognized as a Top 20 "Best Place to Work in Virginia"
  • Recipient of Department of Labor's HireVets Gold Medallion
  • Great Place to Work Certification for five years running
  • A Virginia Chamber of Commerce Fantastic 50 company
  • A Northern Virginia Technology Council Tech 100 company 
  • Inc. 5000 list of fastest growing companies for eleven years
  • Two-time SBA SBIR Tibbett's Award winner
  • Virginia Values Veterans (V3) Certification

We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family!   In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to

  • Traditional and HSA- eligible medical insurance plans 
  • 100% employer-paid dental and vision insurance options 
  • 100% employer-sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible-schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental Leave
  • Professional development and career growth opportunities 
  • Team and company-wide events, recognition, and appreciation-- and so much more! 

Check out our Revolutional | LinkedIn to find out a little more about who we are and if we are the right next step for your career!   

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans.  To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily.  Other duties in addition to those listed may be assigned as necessary to meet business needs.  Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job.  If you are in need of an accommodation, please contact View email address on ziprecruiter.com.

"Know Your Rights: Workplace Discrimination is Illegal" Poster | U.S. Equal Employment Opportunity Commission

Vacancy posted 22 days ago
Similar jobs that could be interesting for youBased on the Lead Cyber Defense Forensics Analyst in Suitland, MD vacancy
  • $138k - $209k

     ...Information Sciences) is seeking a qualified Security Architect to lead incident response activities and manage cybersecurity threats...  ...years in incident response and extensive knowledge of digital forensics and malware analysis. Competitive salary range is $138,000-$209... 
    Cyber

    AIS (Applied Information Sciences)

    Alexandria, VA
    2 days ago
  •  ...advanced C5ISR and security solutions to enhance defense and mission capabilities, addressing threats across physical, electronic, cyber, and communications security for commercial...  ...Summary: As a senior technician, the Lead Security Systems Technician is responsible... 
    Cyber
    Hourly pay
    Night shift

    Active Security Consulting

    Oxon Hill, MD
    4 days ago
  • Maania Consultancy Services seeks a seasoned intelligence analyst specializing in cyber threat intelligence (CTI) with a focus on China-related cyber threats. The role emphasizes collecting, analyzing, and reporting threat information to clients in a consulting setting.... 
    Cyber

    Maania Consultancy Services

    Arlington, VA
    3 days ago
  • $69.4k - $158k

    Modeling and Simulation Analyst, LeadThe Opportunity:As a lead modeling and simulation analyst, you will use your passion for uncovering root causes,...  ...simulation activities that support quantitative assessments for defense mission objectives. Using the Advanced Framework for... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Alexandria, VA
    5 days ago
  •  ...(CSA) is currently seeking an Analyst I to support onsite in the Arlington...  ...support services to meet the defense and federal sector's most...  ...applicable directives.Support cyber and compliance activities, including...  ....Collaborate with government leads, program management, and... 
    Cyber
    Contract work
    For subcontractor
    Work at office
    Remote work

    Client Solution Architects

    Arlington, VA
    2 days ago
  •  ...Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat Emulation...  ...oversee adversary emulation, red team operations, cyber readiness exercises, and threat-informed defense initiatives supporting a federal enterprise... 
    Cyber
    Full time

    cFocus Software Incorporated

    Washington DC
    a month ago
  •  ...is hiring a Senior CFIUS-Export Control Analyst to lead our team of qualified, diverse, and highly...  ...the Office of the Under Secretary of Defense, Research and Engineering (OUSD(R&E)). The...  ...foreign ownership, control, influence, cyber penetration, and other exploitation threats... 
    Cyber
    Work at office
    Local area

    Science Applications International Corporation

    Alexandria, VA
    1 day ago
  •  ...seeking a ServiceNow Business Analyst to support the Department of State...  ...and San Diego, CA, CTC is a leading technology company providing...  ...development, DevOps, Test Automation, Cyber Security, and infrastructure...  ...the unique needs of U.S. Defense, Intelligence, and Federal... 
    Cyber
    Full time
    Contract work
    For contractors
    Local area
    Remote work

    Computer Technologies Consultants (CTC)

    Arlington, VA
    1 day ago
  • Security Operations Center, Analyst- Costa Rica As a SOC Analyst, you will play a pivotal...  ...Responsibilities: Cybersecurity Operations: Lead and manage cybersecurity operations...  ...understanding of industry trends, emerging cyber threats, and new solutions that may impact... 
    Cyber
    Permanent employment
    Full time
    Contract work
    For contractors
    Interim role
    Immediate start
    Relocation

    CRDF Global

    Arlington, VA
    4 days ago
  • $105.79k - $141.05k

     ...Lotus Labs has an opening for a Lead Information Security Engineer...  ...detection. Work with cyber operators and senior researchers...  ...repeatable workflows that combine analyst expertise, automation, and AI‑...  ...experience with Department of Defense (DoD), Intelligence Community,... 
    Cyber
    Temporary work
    Work experience placement
    Remote work
    Work from home

    Lumen Technologies

    Fort Washington, MD
    1 day ago
  • $100.5k - $153.25k

     ...seeking a highly skilled Sr. Enterprise Analyst to support Payroll and Time & Absence Management...  ...The best of the best.We don’t just build defense technology—we redefine what’s possible....  ...across air, land, sea, space, and cyber. From AI-powered drones and loitering munitions... 
    Cyber
    Permanent employment
    Full time
    Contract work
    Work experience placement
    Work at office

    AeroVironment

    Arlington, VA
    1 day ago
  • $90k - $100k

     ...Overview Job Title: Program Analyst Location: Arlington, VA Introduction: Rivet Operations Company...  ...an exceptional industry partner to the Department of Defense (DoD) and a leader in physical and cyber security, IT management, logistics, supply chain management... 
    Cyber
    Work at office
    Long distance

    Rivet Industries

    Arlington, VA
    2 days ago
  • $116.5k - $177.5k

     ...every single day. Together, we are leading the transformation of modern...  ...From Space and Directed Energy to Cyber and Intelligence to C4ISR and Air & Missile Defense, there is no limit to where you...  ...launch a career at AV?As the Program Analyst, you will play a highly visible... 
    Cyber
    Permanent employment
    Full time
    Contract work
    Work experience placement
    For subcontractor
    Remote work

    AeroVironment

    Arlington, VA
    4 days ago
  •  ...headquartered in Reston, Virginia, SOSi is a private defense and government solutions business...  ...a highly qualified senior-level Team Lead to support the American regional office on...  ...intelligence (all-source, C4I, cyber, HUMINT, SIGINT, GEOINT, OSINT, etc.).Familiarity... 
    Cyber
    Contract work
    For contractors
    Work at office

    SOSi

    Washington DC
    1 day ago
  • A defense contracting firm seeks a Senior All-Source Analyst to support USCYBERCOM J2. The role involves conducting intelligence analysis, providing analytic support for national security, and requires a minimum of 12 years of experience, alongside an active TS/SCI clearance... 
    Cyber
    Work at office

    Kinsley Power Systems

    Alexandria, VA
    2 days ago
  •  ...Our Mission At Dobbs Defense, we deliver mission-centric IT, Cyber, and data analytics solutions for our government and commercial clients through the...  ...Description Dobbs Defense Solutions is seeking a Business Analyst to provide support to senior resources on the team in... 
    Cyber
    Work at office

    Dobbs Defense Solutions, LLC

    Washington DC
    1 day ago
  •  ...Cyber Defense & Incident Responder (SOC Analyst) 100% work on site - no remote work Secret clearance with the ability to acquire a TS Locations near the Pentagon or Mayfield VA Customer DEA Intermediate SOC Analyst 6 years with Bachelor The Cyber Defense... 
    Cyber
    Remote work

    Gormat

    Arlington, VA
    1 day ago
  • Leidos in Alexandria, VA is seeking a Security Operations Center Lead to oversee 24x7 incident handling, fusion analysis, and malware/forensic work on the DISA GSM-O program. The role requires a TS/SCI clearance, a bachelor's degree, and 10+ years in cybersecurity with... 
    Cyber

    Leidos

    Alexandria, VA
    16 hours ago
  • Leidos is seeking a Security Operations Center Lead for the DISA GSM-O program in Alexandria, VA. The role directs day-to-day SOC activities, coordinates 24x7 incident handling, and ensures strict adherence to incident response processes. Qualified candidates will have... 
    Cyber

    Via Logic LLC

    Alexandria, VA
    1 day ago
  •  ...technology and services integrators in the defense and government services industry. We...  ...SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and...  ...visibility into security weaknesses and cyber risk.Responsibilities· Perform vulnerability... 
    Cyber
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    1 day ago
  • A defense contractor is seeking a Senior All-Source Analyst (Production / Janus/Hard Target) to support USCYBERCOM J2 in the National Capital Region. The role demands...  ...with a bachelor's degree, alongside knowledge in cyber threat analysis and the ability to work... 
    Cyber
    For contractors

    Kinsley Power Systems

    Alexandria, VA
    2 days ago
  • Nightwing Group seeks a Cyber Host Forensic Analyst IV to join ourStrike team in Arlington, VA. The role...  ...serving as an incident response SME, leading high-priority investigations, and...  ...hunting, forensic analysis, and proactive defense to secure critical infrastructure. A... 
    Cyber

    Nightwing Group

    Arlington, VA
    2 days ago
  • $90k - $102k

     ...Data Analyst A leader in cutting-edge research and technology in the cyber arena, CPMG focuses on using business drivers to guide...  ...integrative solutions for Department of Defense (DoD) contractors, among...  ..., platforms, and products. Leading data driven analytic... 
    Cyber
    For contractors
    Work at office
    Remote work
    Flexible hours

    C.P. MARINE, INC.

    Washington DC
    2 days ago
  • A leading defense contractor is seeking a Senior Collection Manager (CI/HUMINT Reports Officer) to support USCYBERCOM J2 in the National Capital Region. This role involves ensuring effective HUMINT operations, consolidating reporting, and maintaining critical communication... 
    Cyber
    For contractors

    Kinsley Power Systems

    Alexandria, VA
    2 days ago
  •  ...Position Title Cyber Threat Intelligence & Threat Hunting Lead Position Overview The Cyber Threat Intelligence & Threat Hunting Lead will oversee...  ...threat hunting operations supporting enterprise cyber defense missions. The Lead will drive development of... 
    Cyber
    Full time

    cFocus Software Incorporated

    Washington DC
    a month ago
  •  ...Description Senior Data Analyst Req ID 003-25 v1.0 HazeGrayCyber, LLC is focused on delivering Cyber Security and Zero Trust Solutions to the US National Defense community and our allies and partners. This position will provide Information and Task... 
    Cyber
    For contractors
    Overseas

    HazeGrayCyber

    Washington DC
    2 days ago
  • Lumifi Cyber seeks a Lead Consultant for the IR/Forensics Practice, primarily conducting incident response and forensic investigations. The role requires availability for 24/7 on-call IR work, managing customer recovery, and leading response efforts. Ideal candidates will... 
    Cyber
    Remote job

    Lumifi Cyber

    Arlington, VA
    4 days ago
  • $132.23k - $176.31k

     ...Labs has an opening for a Senior Lead Security Engineer that will...  ...automating detection. Work with cyber operators, when requested, to...  ...workflows that combine analyst expertise, automation, and AI-...  ...experience with Department of Defense (DoD), Intelligence Community,... 
    Cyber
    Full time
    Temporary work
    Work experience placement
    Work at office
    Remote work

    Lumen

    Adelphi, MD
    3 days ago
  •  ...the fastest growing areas of our business, and our global Cyber Investigation and Forensic Response (CIFR) practice is at the heart of how we help clients...  ...maturing the offering, and growing the practice.The Work:Lead enterprise recovery engagements during active cyber... 
    Cyber
    Full time
    Live in
    Work at office
    Local area
    Shift work

    Accenture

    Arlington, VA
    3 days ago
  • Nightwing in Arlington, VA is seeking a Cyber Network Forensic Analyst to support on-site incident response for a U.S. Government customer. You will assist investigations, coordinate with government teams, and help develop mitigation strategies. Ideal candidates have 8... 
    Cyber

    Nightwing

    Arlington, VA
    16 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Cyber Defense Forensics Analyst. Be the first to apply!