Digital Investigations Engineer

The MITRE Corporation

$129K — $193K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in digital investigations or related fields; 3+ years with a master's degree or PhD with relevant experience.
  • Experience in investigating endpoints, OS, user activity, malware, or network threats.
  • Familiarity with forensic tools, SIEM platforms, and log analysis.
  • Knowledge of incident response and evidence handling best practices.
  • Understanding of Windows, Linux, and macOS concerning investigation artifacts.
  • Strong analytical, problem-solving, and documentation skills.
  • Ability to effectively communicate findings to both technical and non-technical audiences.

Responsibilities

  • Conduct digital investigations on cybersecurity incidents and suspicious activities.
  • Collect and document digital evidence from various sources including endpoints and networks.
  • Support cybersecurity operations through alert triage and incident response.
  • Perform forensic analysis to identify attack vectors and impact scope.
  • Maintain evidence handling procedures for investigations and potential legal matters.
  • Analyze logs for indicators of compromise or anomalous behaviors.
  • Collaborate with multiple teams during investigations to optimize outcomes.
  • Prepare detailed investigative reports for diverse audiences.
  • Help improve digital investigation methodologies and evidence collection standards.
  • Recommend remediation based on investigative outcomes.

Benefits

  • Hybrid work model with at least 50% on-site requirements.
  • Professional development opportunities in cybersecurity.
  • Access to innovative technologies and forensic tools.
  • Collaboration with leading experts in digital investigations.
  • Engagement in high-impact law enforcement and cybersecurity projects.
Full Job Description
MITRE's Digital Investigations Department (L515) delivers innovative technical solutions and capabilities primarily focused on support to law enforcement and investigative cyber operations conducted by sponsors, most notably within DOJ, DHS, and DoW. The department's core technology areas are:
  • Digital Investigations and Cases
  • Digital/Media/Mobile Device Access and Forensics
  • Digital Artifact Discovery
  • Digital Evidence Processing
  • Cryptocurrency Analysis and Seizure
  • Cyber Attribution
  • Darkweb Research
  • Financial Cybercrime Analysis
  • Social Media Exploitation


Roles & Responsibilities:
  • Conduct digital investigations related to cybersecurity incidents, insider threat concerns, policy violations, and suspicious activity.
  • Collect, preserve, analyze, and document digital evidence from endpoints, servers, mobile devices, cloud environments, logs, and network sources.
  • Support cybersecurity operations by triaging alerts, correlating threat activity, and assisting with incident response and containment efforts.
  • Perform forensic analysis using industry-standard tools and methodologies to determine attack vectors, timeline of events, impacted systems, and scope of compromise.
  • Maintain chain of custody and proper evidence handling procedures in support of internal investigations and potential legal or regulatory matters.
  • Analyze system, application, security, and network logs to identify indicators of compromise and anomalous behavior.
  • Collaborate with Security Operations Center, Threat Intelligence, IT, HR, Legal, and Compliance teams during investigations.
  • Prepare clear, concise, and defensible investigative reports, briefings, and technical documentation for both technical and non-technical audiences.
  • Assist in developing and improving digital investigation procedures, playbooks, and evidence collection standards.
  • Recommend remediation and mitigation actions based on investigative findings.
  • Stay current on emerging cyber threats, attacker tactics, forensic techniques, and relevant technologies.


Basic Qualifications:
  • Typically requires a minimum of 5 years of related experience with a bachelor's degree; or 3 years and a master's degree; or a PhD with relevant experience who can immediately contribute at this job step; or equivalent combination of related education and work experience.
  • Experience supporting investigations involving endpoints, operating systems, user activity, malware, or network-based threats.
  • Familiarity with common forensic and investigative tools, SIEM platforms, endpoint detection and response tools, and log analysis solutions.
  • Knowledge of incident response processes, digital evidence handling, and forensic best practices.
  • Understanding of Windows, Linux, and/or macOS operating systems and associated artifacts relevant to investigations.
  • Strong analytical, problem-solving, and documentation skills.
  • Ability to communicate investigative findings clearly to technical and non-technical stakeholders.
  • This position requires a minimum of 50% hybrid on-site


Preferred Qualifications:
  • Experience in a Security Operations Center, Computer Security Incident Response Team, or digital forensics function.
  • Familiarity with cloud investigation techniques in environments such as Azure, AWS, or Google Cloud.
  • Experience with eDiscovery, insider threat investigations, or fraud-related digital analysis.
  • Exposure to malware analysis, threat hunting, or network forensics.
  • Relevant certifications such as Security+, CySA+, GCFA, GCIH, GCFE, EnCE, CHFI, or similar.
  • Knowledge of regulatory, compliance, and privacy considerations related to investigations.


This requisition requires the candidate to have a minimum of the following clearance(s):
None

This requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s):
None

Salary compensation range and midpoint:
$129,200 - $161,500 - $193,800 Annual

Work Location Type:
Hybrid

Similar Jobs

More Jobs at The MITRE Corporation

More Information Technology Jobs

Find similar Digital Investigations Engineer jobs: