Forensics / Incident Response SME
$145k - $155kValiant Solutions
Position Description
Valiant Solutions is seeking a Forensics / Incident Response SME to join our rapidly growing and innovative cybersecurity team!
Do you have experience in IT security and a strong background in Incident Response and Forensics? If so, you may be interested in this dual-focused position that requires active participation in all Incident Response activities, complemented by deep, specialized expertise in Forensic Analysis.
This is your opportunity to join a busy Security Engineering team delivering cutting-edge solutions to a fantastic Government client. Specialized experience in incident response, managing APTs, forensic analysis, and handling evidentiary data is key for this challenging and rewarding role. This role will be responsible for all incident response and management activities, forensic analysis, and other emerging enterprise-wide IT challenges.
We are seeking a motivated individual to join this team, which is constantly evolving and currently developing cloud security solutions in AWS. You’ll be passionate about what you do and will be able to work autonomously to engineer your way out of problems. The IR/Forensics SME shall be responsible for all incident response and management activities, forensic analysis, and other emerging enterprise-wide IT challenges.
Named one of the Best Places to Work in the Washington DC area for 12 consecutive years , Valiant is proud of our employee-centric culture and commitment to excellence. If you are interested in learning more about Valiant and this opportunity, we invite you to apply now!
This position allows for 100% remote work. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.
Required Experience
- 8+ years of specialized experience in incident response, management of the APT, forensic analysis, and handling of evidentiary data, with the most recent experience in the past 4 years.
- Experience with Mobile Device Forensics
- Experience performing IR, Forensics, and post-mortem reports in cloud environments (AWS preferred).
- Ability to identify malware characteristics and conduct reverse engineering in x86 and x64 assembly
- Ability to demonstrate and conduct Windows memory forensics techniques to analyze malware threats.
- Strong knowledge of malware code and behavioral analysis.
- Working knowledge in SIFT, REMnux, or other similar frameworks.
- Experience in Presentation and Reporting of Evidence and Analysis
- Experience in File System Timeline Analysis
- Experience in Live Incident Response and Volatile Evidence Collection
- Experience in Advanced Windows Registry Analysis
- Experience in Forensic Imaging and Filesystem Media Analysis
- Experience performing Advanced Network Event and Protocol analysis and timeline reconstruction
- Experience and ability to develop, use, and follow Standard Operating Procedures (SOPs)
- In-depth experience with processing and triage of Security Alerts from multiple sources, but not limited to Endpoint security tools, SIEM, email security solutions, CISA, Threat Intel Sources
- Demonstrated ability to evaluate events (through a triage process) and identify appropriate prioritization for response
- Expert understanding of security incident response processes
- Support and participate in Threat Hunt and Threat Intel operations
Responsibilities
-
Participate in a rotating on-call; rotation is based on the number of team members
- Serve as a hybrid Incident Response (IR) and Digital Forensics (DFIR) function, requiring both real-time incident handling and deep forensic investigative expertise across enterprise and cloud environments.
- Provide Incident Management and Forensic Support as required for incidents/investigations, including off-hours
- Provide Incident Management support, including guidance and expertise to the Incident Response Team and SOC components
- Development of policies, instructions, standards, and procedures around security functions
- Develops, maintains, and optimizes the malware and forensic analysis laboratory environment
- Maintains digital evidence Chain of Custody for forensic activity in accordance with policy, industry standards, and law
- Perform forensic analysis on a variety of networks, hosts, digital media, and operating systems/environments as but not limited to: Windows, Mac, iOS, Android, Windows Mobile, Linux/Unix, Mainframe, and cloud computing platforms (SaaS, PaaS, IaaS)
- Prepare detailed written technical reports covering the methodology applied to forensic investigation, findings, and recommendations for further action
- Provide SME technical analysis for Incident Response and Forensics for Incident / Breach / and Compromise Activities. Including but not limited to malware detection, lateral movement, data collection, and exfiltration detection
- Provide a complete response to all DFIR tasks
- Produce and review aggregated performance metrics
- Work directly with Security and SOC leadership to convert intelligence and results from forensic analysis into useful detection in enterprise security tools
- Collaborate with the incident response team to rapidly build detection rules as needed
- Perform customer security assessments
- Supporting incident response or remediation as needed
- Participate and develop, and run tabletop exercises
- Perform lessons learned activities
- Supporting ad-hoc data and investigation requests
- Support the enrichment and enhancement of security monitoring tools, including but not limited to evaluation and recommendations on rule tuning and development of new rules/detections
- Participate in a rotating on-call schedule
Strongly Preferred Certifications:
- GIAC Certified Forensics Examiner (GCFE)
- Certified Forensic Analyst (GCFA)
- Certified Computer Examiner (CCE)
- AccessData Certified Examiner (ACE) EnCase Certified Examiner (EnCE)
- Magent Certified Forensic Examiner (MCFE)
- Magent Certified GRAYKEY Examiner (MCGE)
- AWS Solution Architect (AWS)
- SANS GIAC Certified Incident Handler (GCIH)
- SANS GIAC Certified Intrusion Analyst (GCIA)
- SANS GIAC Network Forensics Analyst (GNFA)
- SANS GIAC Certified Enterprise Defender (GCED)
- SANS GIAC Reverse Engineering Malware (GREM)
- Carnegie Mellon Certified Computer Incident Handler (CSIH)
- IACIS Certified Forensic Computer Examiner (CFCE)
- ISFCE Certified Computer Examiner (CCE)
About Valiant Solutions
Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies by Inc. 5000, Washington Technology’s Fast 50, and Washington Business Journal’s Best Places to Work in the D.C. area, Valiant Solutions prides itself on providing its employees with great benefits and career development opportunities. As a company, we are just as committed to growing careers as we are to building world-class IT solutions, all while enjoying an unparalleled work-life balance. We are in a phase of tremendous growth and building the team that will take us to the next level. We seek people whose talents and accomplishments will contribute to a thriving company, who have the character to support their capacity, and can make a positive impact on our culture. Alongside our talented team, you’ll learn to think quickly on your feet and expand your own personal and professional skill set. Our management team will inspire you to consider new perspectives and challenge you to become a better practitioner in the fast-paced industry of IT security. We hire people we respect – and we trust them to deliver results leveraging their expertise. If you would enjoy working in a dynamic environment as part of a stellar team of professionals, then we invite you to apply online today.
Benefits Snapshot (includes, but not limited to) Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time EmployeesValiant contributes 25% towards Health Coverage for Family and Dependents100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees100% Paid Certifications401K Matching up to 4%Paid Time OffPaid Federal HolidaysWellness & Fitness ProgramValiant University – Online Education and Training PortalFSA programs for: Medical Costs, Dependent Care, Transit, and ParkingReferral Bonuses
The salary range for this position is a general guideline and not a guarantee of compensation or salary. It has been benchmarked in relation to the scope of the role, market rate, and internal equity. The salary for this role is expected to be in the $145,000 - $155,000 salary range. Where a candidate falls within the band can be determined based on one or more of the following: skillset, experience level, achievements, education, geographic location, security clearance, involvement in corporate tasks, and other non-discriminatory factors. In addition to the base salary, this role will include benefits as described above. Valiant reserves the right to adjust the salary range, experience requirements, and position responsibilities at any time without prior notice.
Remote Work Policy
Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General’s effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients.
Equal Employment Opportunity
Valiant Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, marital status, or veteran status, in accordance with applicable law.
Physical Demands
Sitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job.
Authorization to Share Resume and Personal Information
By submitting your resume for this position, you authorize Valiant Solutions to share your resume, as well as, personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should Valiant Solutions or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents.
#LI-LH1
$100k - $125k
Incident Response Expert III (Cyber Eviction Analysts) Location: Washington DC Metro Area (On-Site... ...rapid incident response, advanced forensics, and coordinated recovery operations to... ...incident response subject matter expert (SME), applying in-depth knowledge on threat...SuggestedLocal areaImmediate start$142.9k - $266k
Digital Forensics and Incident Response, Senior ManagerThe Opportunity:Serve as a member of the Digital Forensics and Incident Response leadership team, responsible for the strategic direction, operational performance, client delivery, and continued growth of multiple incident...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$138k - $200k
...customer teams to investigate and contain incidents.Recognize and codify attacker Tools,... ...current and future investigations.Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations.Lead client-facing...Suggested- Edgewater Federal Solutions is seeking a Threat Hunter to provide threat hunting, incident response, forensics, and malware analysis to strengthen the Client’s SOC. You will develop hunt hypotheses, analyze SIEM alerts, and coordinate detection logic and incident reports...Suggested
$150k - $180k
...expertise and support to maximize cyber fusion across the Client’s SOC. The role requires 8+ years in cybersecurity threat hunting or incident response, with strong SIEM, EDR, and malware analysis skills, and eligibility for US citizenship. On-site in Frederick, MD, with...Suggested- Charles River Associates seeks a Senior Associate in Forensic Services to lead end-to-end incident response, recovery, and investigations for complex breaches. You will manage scope, budgets, and teams, directing technical work across containment, forensics, and remediation...
- Charles River Associates is seeking a Consulting Associate in its Forensic Services to execute core incident response and digital forensics tasks within a dynamic team. You will lead forensic collection and analysis across Windows, Linux, VMware, and cloud environments,...
$59.81k - $94.44k
## Incident Response Analyst IApplylocations: Austin, TXtime type: Full timeposted on: Posted Todayjob requisition id: R0016477* **Scope**... ...handling, coordinates cross-functional responses, and performs forensic analysis. + Oversees incident response strategy, threat...Full timeTemporary workWork experience placementFlexible hoursNight shift$207k - $301k
Conduct analysis and manage consulting engagements with a focus on incident response and forensics, serving as the subject matter expert and point person from kickoff through full remediation.Recommend and document specific countermeasures and mitigating controls while...Local area- ...Jobtailor is seeking a Forensic Investigator to join our San Diego team. The role requires 1–3 years in forensics and incident response, a BS in CS or MIS, and experience with EnCase, FTK, and DLP technologies. You will collect data across platforms, perform analysis,...
$151k - $208k
...Palo Alto Networks, Inc. is looking for a Principal Consultant in Burbank, California, responsible for leading incident response and digital forensics services. This role involves serving as a technical leader on investigations and guiding clients through security incidents...Remote job$175k - $250k
...launchyour career.Position OverviewCRA’s Forensic Services practice supports companies’... ...forensic & cyber investigations space, your responsibilities as a Principal may include (but are not... ...breach detection, threat analysis, incident response and malware analysis;...Work at officeLocal areaWork from home3 days per week$130k - $152.5k
...launchyour career.Position OverviewCRA’s Forensic Services practice supports companies’... ...CRA clients, in preparation of, and in response to, data security matters, which may include... ...breach detection, threat analysis, incident response and malware analysis;Performing...Work at officeLocal areaWork from home3 days per week- About the Role:The Senior Director, Digital Forensics & Incident Response owns AstraZeneca’s global capability to respond to and investigate cyber incidents. This role commands the enterprise response to material incidents across cloud, on-premises and OT/ICS environments...Hourly payPermanent employmentFull timeTemporary workWork at officeFlexible hours3 days per week
- ...economic and financial analysis for litigation, strategy, and policy impact. The Senior Associate in our Forensic Services practice leads end-to-end incident response and recovery engagements, guiding scoping, directing teams, and presenting findings to executives and...
- Zurich North America is seeking a Senior Incident Response Consultant to deliver expert incident response services. The role involves leading... ...a Bachelor’s degree or equivalent experience in IT, digital forensics skills, and proficiency in client communication. The...Remote job
- ...River Associates seeks a hands-on Consulting Associate to drive forensic collection and analysis in hybrid Microsoft environments.... ...teams under tight deadlines. The role requires 3-5 years in incident response or forensics, strong scripting in PowerShell, and experience...Flexible hours
- Jobtailor in Washington state seeks a Senior Digital Forensics & Incident Response professional with an active Top Secret clearance to lead investigations and coordinate across the SOC. You will apply EnCase, FTK, Autopsy, Wireshark, Ghidra and IDA Pro to analyze evidence...
- Google is seeking experienced Security Engineers to drive incident response and forensics. The ideal candidate will have extensive experience in managing incident response operations and will collaborate to enhance security for Google's services. This role requires a Bachelor...
- Accenture Federal Services seeks a seasoned Incident Response & Digital Forensics Lead in Germantown, MD. You will lead the IR & Forensics team and coordinate briefings with clients and senior leadership on incident responses. Requirements: 7+ years in IR/forensics, GCFE...1 day per week
- ...(CRA) is seeking an Associate for the Forensic Services practice in the United States.... ...cybercrime investigations, data security incidents, and forensic reporting. The candidate... ...evidence-driven insights for clients. Responsibilities include conducting investigations, drafting...
- ...provide threat hunting expertise across the Client’s SOC, leveraging hypothesis-driven hunts to detect threats and support incident response, forensics, and malware analysis. The role emphasizes collaborating with IT and security teams to keep environments secure....
- Fairweather, LLC seeks an experienced Cyber Incident Response Analyst to lead investigations and respond to security incidents in an onsite... ...Austin and San Antonio. The position requires hands-on forensic analysis, malware assessment, and strong communication of findings...
- Charles River Associates (CRA) is seeking a Consulting Associate for its Forensic Services practice in the Washington, DC area to lead incident response and digital forensics engagements. You will work across Windows, Linux, VMware, Azure, and cloud environments, building...
- Accenture Federal Services in Germantown, MD is seeking a seasoned leader to head the Incident Response and Digital Forensics team. You will guide DFIR operations, mentor analysts, and coordinate with clients and senior leadership on incident responses. The ideal candidate...1 day per week
- ...message the job poster from V Group Inc. Recruiting for NY - MTA, VITA, State of NC, SC, MI, MS, TN at V Group Job Title: Incident Response & Forensics Analyst Duration: 6+ Months Location: Remote with Occasional visit to NYC Position Type: Contract Interview Type: In-...Contract workWork at officeLocal areaRemote work
$250k - $400k
...market penetration. To lead on the delivery of complex cyber incident response cases in the Americas, and elsewhere as appropriate. To... ...develop, and manage high quality crisis management, technical forensics and client-facing resources. To work seamlessly with our global...Work at officeRemote workFlexible hours- Charles River Associates seeks a Consulting Associate for its Forensic Services to execute incident response and digital forensics across Windows, Linux, VMware, and cloud environments. You will lead containment actions, perform credential resets, and guide recovery workflows...Night shiftWeekend work
- ...and work remotely one day. A member of our recruitment team will provide more details.The Global Director of Autonomous Incident Response and Forensic Analysis leads the strategy, execution, and continuous improvement of a 24/7 global incident response (IR) and digital...Full timeWork at officeLocal areaRemote work1 day per week
- ...Description Insight Global is looking for a Forensics Analysts to act as the primary liaison... ...obfuscate content related to a security incident. We are a company committed to... ...Anti-Malware technologies o Incident Response • Experience in analyzing security alerts...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Forensics / Incident Response SME. Be the first to apply!
- forensic chemistry United States
- forensic therapist United States
- forensic psychiatrist United States
- entry level forensic science United States
- forensic biology United States
- forensic United States
- forensic science United States
- cyber forensics United States
- forensic lab United States
- forensic accounting United States

