ResponsibilitiesPeraton is seeking an experienced and highly skilled Senior Digital Forensics Examiner to join our specialized team in Bethesda, MD in support of our Department of War (DoW) customer. The ideal candidate will conduct comprehensive forensic examinations on a diverse range of digital media, including hard drives, mobile devices, and removable media. You will serve as a subject matter expert, responsible for the entire lifecycle of digital evidence from acquisition to reporting. This role requires a meticulous and analytical mindset, coupled with the ability to convey complex technical findings to both technical and non-technical audiences.
Core Responsibilities
- Conduct forensically sound examinations of digital and mobile devices (including computers, smartphones, and tablets) to support investigative requirements.
- Utilize industry-standard forensic tools and advanced techniques to perform data extraction, recovery, and in-depth analysis of file systems, operating systems (Windows, macOS, Linux, iOS, Android), and application data.
- Perform comprehensive analysis, including timeline generation, file signature and hash analysis, email and communication analysis, and examination of large, complex datasets.
- Identify and analyze malware and evidence of intrusion or unauthorized activity.
- Prepare detailed, clear, and concise technical reports documenting examination procedures, findings, and expert opinions for a variety of audiences.
- Perform peer reviews of forensic reports to ensure technical accuracy, completeness, and adherence to established standards.
- Maintain strict chain of custody for all digital evidence and associated documentation.
- Provide expert consultation to stakeholders on Tactics, Techniques, and Procedures (TTPs) for digital evidence handling and forensic examinations.
- Stay abreast of the latest developments in digital forensics technology, trends, and methodologies to ensure the use of current best practices.
Qualifications
Required Skills & Experience
- Proven proficiency with industry-standard forensic tool suites (e.g., EnCase, FTK, Magnet AXIOM, X-Ways Forensics, Autopsy).
- Demonstrated mobile forensics experience extracting and parsing iOS and Android devices using tools such as Cellebrite UFED/Physical Analyzer or GrayKey.
- Working knowledge of file systems and structures (NTFS, FAT32, exFAT, EXT3/4, APFS, HFS+).
- Demonstrated ability to identify full-disk, volume, and file-level encryption and evaluate appropriate key extraction or decryption workflows.
- In-depth knowledge of cryptographic hashing algorithms (MD5, SHA-1, SHA-256) and their practical forensic application for data integrity verification and identifying known threat artifacts.
- Experience conducting static and behavioral triage of malicious files (e.g., string analysis, header analysis, sandbox execution) to support forensic attribution.
- Strong technical writing and briefing capabilities, with experience authoring formal forensic reports.
- Must possess an active Top Secret/SCI security clearance with a Polygraph.
- Current DoD 8570/8140 IAT Level II certification (e.g., CompTIA Security+, CySA+, GICSP).
- Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA; Minimum of 3 years with PhD. A degree in one of the following fields is highly desired: Cybersecurity, Computer Science, Information Systems, Information Technology, Mathematics, Data Science, or Software Engineering. However, an additional four years of experience may be considered in lieu of a bachelor6s degree.
Preferred Skills & Experience
- Advanced industry certifications, such as:
- GIAC Certified Forensic Examiner (GCFE) or Analyst (GCFA)
- GIAC Advanced Smartphone Forensics (GASF)
- Cellebrite Certified Mobile Examiner (CCME)
- EnCase Certified Examiner (EnCE)
- AccessData Certified Examiner (ACE)
- Certified Forensic Computer Examiner (CFCE)
- Proficiency in programming or scripting languages (e.g., Python, PowerShell) to automate forensic workflows, parse novel artifacts, and process bulk data.
- Prior experience working within the Intelligence Community (IC).
- Demonstrated experience authoring finished intelligence reports and assessments.
Target Salary Range$135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual6s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.