Location: DFW Department: DEPADM
The Opportunity The Cybersecurity Digital Forensics Investigator is responsible for conducting cybersecurity investigations involving company-owned cellphones, computers, tablets, electronic devices, cloud services, applications, and digital records. This position collects, preserves, analyzes, documents, and tracks digital evidence while maintaining strict chain-of-custody and confidentiality requirements.
The role works closely with internal Cybersecurity, Information Technology, Human Resources, Legal, Compliance, Corporate Security, and executive leadership teams. The investigator may also coordinate with federal law enforcement agencies, government investigators, outside legal counsel, and approved third-party forensic specialists.
This position requires strong technical expertise, sound professional judgment, exceptional attention to detail, and the ability to handle sensitive investigations in a confidential, legally defensible, and impartial manner.
What you will do? Digital Forensics and Cybersecurity Investigations - Conduct cybersecurity and digital forensic investigations involving cellphones, laptops, desktops, tablets, removable media, servers, email systems, cloud platforms, and other electronic devices.
- Investigate suspected data theft, unauthorized access, insider threats, cybersecurity incidents, policy violations, fraud, intellectual property theft, and misuse of company technology.
- Acquire and preserve forensic images and other digital evidence using approved forensic tools and legally defensible procedures.
- Analyze mobile-device data, including call records, text messages, application data, device logs, photographs, files, location-related artifacts, and system activity, when authorized.
- Examine Windows, macOS, iOS, Android, cloud, email, network, and application artifacts relevant to investigations.
- Recover, correlate, and analyze deleted, hidden, encrypted, or otherwise protected information when legally authorized and technically feasible.
- Develop investigation timelines by correlating information from devices, security systems, access records, network logs, email, cloud services, and other authorized sources.
- Identify indicators of compromise, suspicious behavior, unauthorized data transfers, and potential violations of company policies or applicable laws.
- Support incident-response activities, including evidence collection, containment analysis, root-cause investigation, and post-incident reporting.
Evidence Management and Chain of Custody - Collect, label, preserve, store, transfer, and track digital evidence according to established chain-of-custody procedures.
- Maintain complete and accurate evidence logs, forensic notes, investigation records, device inventories, and custody documentation.
- Protect the integrity, authenticity, confidentiality, and availability of all evidence throughout the investigation lifecycle.
- Verify forensic images and collected data using industry-standard hashing and validation techniques.
- Ensure evidence is stored securely and accessed only by authorized personnel.
- Maintain investigation case files in accordance with company retention requirements, legal-hold instructions, contractual obligations, and applicable regulations.
- Document every investigative action sufficiently to support internal reviews, legal proceedings, regulatory inquiries, or law-enforcement requests.
Federal Agency and Legal Coordination - Serve as a technical liaison between the company and authorized federal law enforcement or government investigation teams.
- Coordinate the secure exchange of approved digital evidence, forensic reports, technical findings, and supporting documentation.
- Respond to authorized subpoenas, warrants, preservation requests, legal holds, and government information requests in coordination with Legal and executive leadership.
- Support interviews, technical briefings, case reviews, and evidence presentations involving internal stakeholders, outside counsel, or government investigators.
- Explain technical findings clearly to investigators, attorneys, executives, and other nontechnical audiences.
- Provide factual testimony, declarations, affidavits, or expert technical support when authorized and required.
- Maintain professional independence and ensure that investigative conclusions are based on documented evidence.
Investigation Data Tracking and Reporting - Maintain a centralized system for tracking investigation cases, devices, evidence, activities, findings, deadlines, and case status.
- Create detailed forensic reports that clearly describe the scope, methodology, tools used, evidence examined, findings, limitations, and conclusions.
- Working knowledge of forensic imaging, evidence validation, file systems, operating-system artifacts, network logs, and security-event data.
- Experience coordinating sensitive investigations with Legal, Human Resources, Compliance, Corporate Security, or government agencies.
- Ability to handle highly confidential, privileged, personal, and legally sensitive information.
- Strong written, verbal, analytical, interviewing, and presentation skills.
- Ability to obtain and maintain any security clearance, background investigation, or federal eligibility requirement applicable to the position.
Required Qualifications - Bachelor's degree in Cybersecurity, Digital Forensics, Computer Science, Information Technology, Criminal Justice, or a related field.
- A minimum of 7 years of experience in cybersecurity, digital forensics, incident response, law enforcement investigations, corporate investigations, or a related discipline.
- At least 3 years of hands-on experience conducting digital forensic examinations or cybersecurity investigations.
- Demonstrated experience investigating mobile devices, computers, email systems, cloud environments, and electronic records.
- Experience maintaining chain-of-custody documentation and producing legally defensible investigation reports.
Preferred Qualifications One or more of the following certifications is preferred:
- Certified Information Systems Security Professional • CISSP
- GIAC Certified Forensic Examiner • GCFE
- GIAC Certified Forensic Analyst • GCFA
- GIAC Advanced Smartphone Forensics • GASF
- Certified Computer Examiner • CCE
- EnCase Certified Examiner • EnCE
- Certified Cyber Forensics Professional • CCFP or equivalent
- Cellebrite Certified Mobile Examiner • CCME
How we support you We believe your best work happens when you feel supported - professionally, personally, and financially. That's why we offer a range of benefits designed to help you thrive, stay healthy, and plan for the future.
- Performance-driven rewards • Competitive pay with incentive opportunities that recognize your results and contributions.
- Comprehensive healthcare • Medical, dental, and vision coverage that supports you and your family's total well-being.
- Security and peace of mind • Life and disability insurance programs that provide protection when it matters most.
- Flexible benefits options • A variety of voluntary benefits so you can personalize coverage to fit your needs.
- Time to recharge • Generous paid time off to relax, travel, and maintain a healthy work-life balance.
- Investing in your growth • Education assistance and tuition support to help you build skills and advance your career.
- Planning for the future • Retirement and savings programs that help you achieve long-term financial confidence.