Minimum Qualifications:The Intermediate Cyber Forensic Examiner independently conducts digital forensic examinations and provides technical analysis of digital evidence across enterprise computing environments. The examiner applies established forensic methodologies to identify, preserve, acquire, examine, and analyze evidence and develops technically defensible findings and reports.
Responsibilities:- Independently conduct forensic examinations of workstations, servers, mobile devices, storage media, virtual machines, cloud environments, and other digital systems.
- Identify and acquire relevant digital evidence while preserving forensic integrity and maintaining complete chain-of-custody documentation.
- Perform forensic imaging and acquisition from physical, logical, virtual, mobile, and cloud-based sources.
- Analyze operating-system artifacts, file systems, application data, browser history, email, communications, registry data, logs, metadata, deleted files, and other forensic artifacts.
- Conduct forensic timeline analysis and correlate evidence across multiple systems and data sources.
- Perform mobile-device forensic examinations, including analysis of application data, communications, location information, media, and device activity.
- Analyze network and security data to identify evidence of unauthorized access, persistence, lateral movement, data staging, exfiltration, or other malicious activity.
- Perform recovery and analysis of deleted, fragmented, concealed, encrypted, or otherwise obfuscated data where technically feasible.
- Utilize forensic suites and specialized tools to acquire, parse, search, correlate, and analyze digital evidence.
- Develop and document forensic examination procedures and analytical methodologies.
- Identify relevant artifacts and develop investigative hypotheses based on available evidence.
- Produce comprehensive forensic examination reports documenting methodology, evidence examined, findings, analytical reasoning, and conclusions.
- Brief technical and government stakeholders regarding forensic findings and investigative conclusions.
- Support incident-response investigations and collaborate with cybersecurity, network, system, and threat-analysis personnel.
- Review junior examiner work products and provide technical guidance and mentoring.
- Maintain knowledge of emerging operating systems, applications, devices, forensic artifacts, and anti-forensic techniques.
Required Qualifications:- 3+ years of relevant experience OR a relevant bachelor's degree with demonstrated/proven practical experience in digital forensics, cyber operations, cyber defense, incident response, computer science, cybersecurity, or a related discipline.
- Demonstrated experience with one or more relevant forensic tools, such as Cellebrite, FTK, EnCase, Magnet AXIOM, Paladin, or comparable forensic platforms.
- Demonstrated knowledge of forensic acquisition, evidence preservation, file-system analysis, artifact analysis, timeline analysis, and digital evidence handling.
- Experience conducting forensic examinations across one or more enterprise technology domains, including endpoints, servers, mobile devices, networks, cloud environments, or virtualized systems.
- Strong analytical, investigative, technical writing, and documentation skills.
- DoD 8570 IAT Level II certification required.
- Must hold Top Secret security clearance. Counterintelligence polygraph desired.