7+ years of experience for Senior role; 5+ years for Mid; 3+ years for Junior
Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field (may reduce experience requirement)
DOD Level III certification for Senior; Level II for Mid; Level I for Junior
Strong understanding of digital forensics and cybersecurity principles
Experience with incident response and threat analysis
Responsibilities
Provide support to Cyber Investigations in insider threat and security operations
Monitor DLP solutions and conduct near real-time analysis
Recommend best practices for Information Spillage Incident Response
Design and deploy custom digital forensic builds for analysis
Conduct endpoint and network-based digital forensic analysis
Utilize forensic tools for advanced research and development
Document findings in formal investigation reports
Benefits
Remote support options available
Opportunity to work with government agencies
Engagement in high-stakes cybersecurity investigations
Access to advanced forensic tools and technologies
Professional development opportunities in a specialized field
Full Job Description
We are seeking a Forensic Analyst for an opportunity in Washington, DC. This opportunity may allow some remote support.
Forensics Specialist Senior-7+ years of experience-Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field may reduce required experience to 5 years. Must have a DOD Level III certification.
Forensics Specialist Mid-5+ years of experience-Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field may reduce required experience to 5 years. Must have DOD level II certification.
Forensics Specialist Junior-3+ years of experience. Must have DOD level I certification.
Cyber Forensics Analysis Support
The Contractor shall provide support to Cyber Investigations (CI) in conjunction with OIT's CDF team in support of insider threat and security operations according to established policies, handbooks, and CBP CDF SOPs. This support includes monitoring activities, conducting threat analysis, investigating policy violations, identifying mitigation and/or remediation courses of action, and assessing risk posed by trusted insiders. The focus of this task is to process CBP email misuse 'egress' cases assigned to OPR in the CBP OPR Joint Intake Case Management System (JICMS), work with the OIT DLP tools to process incidents and assist with SOC Incidents / OPR investigations as needed.
Support the Cyber Investigations through near real-time (when possible, based on tools) monitoring of the DLP solutions and other applicable tools.
Provide recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.
Support the design, development, and deployment of OPR's custom digital forensic builds for triaging, imaging, and advanced analysis.
Support OIT, OI, OIG and Other Government Agencies in the investigation of CBP personnel operating with potentially malicious or alleged criminal intent.
Support the Government in conducting enterprise and individual system(s) endpoint (e.g., Windows, Linux, Mac, and Cloud systems) and network based digital forensic analysis and cloud network designs for new forensic tools in support of CI or CDF and for deployment into production networks.
Leverage commercially available and open-source forensic tools to efficiently perform forensic analysis, assess technical gaps and conduct advanced research and development on forensic technologies and enterprise solutions.
Support the Government in conducting formal digital forensic investigations and document findings in formal investigation reports.
Perform Email hygiene activities in support of CBP investigations.
Support enterprise recovery efforts as necessary to ensure that security events and incidents are properly remediated prior to reconstitution.
Serve as Subject Matter Experts (SMEs) by supporting the preservation of evidence, which includes a deep understanding of proper chain of custody and proper storage, handling, and transmission procedures for various data sets including but not limited to SBU, FOUO, LES, CONFIDENTIAL, SECRET and TOP SECRET information.
Create and escalate cases via ticket management system to proper law enforcement entities in compliance with CBP policy and SOPs.
Assist with authoring, updating, and modernizing OPR's IOD SOPs.
Support the Government with managing the lifecycle of Cyber investigations from creation to closure in accordance with OPR's Policy and Procedures.
Assist in static and dynamic file analysis to identify malware characteristics, intent, and origin.