ResponsibilitiesThe Cyber Threat Analysis Division (DS/CTI/CTAD) conducts advanced digital technical forensic analysis and application assessments to support Department of State information, systems, and personnel. Within this division, the Mobile Threat Analysis (MTA) section serves as the primary capability for identifying and mitigating security anomalies within the mobile ecosystem.
The team leverages a wide variety of advanced technologies to perform comprehensive forensic examinations and deep-dive mobile app assessments, ensuring the detection of malicious behaviors, unauthorized data exfiltration, and emerging attack vectors. By synthesizing complex mobile telemetry and forensic artifacts, the team provides actionable intelligence and mitigation strategies to stakeholders worldwide, ensuring the integrity of the Department’s mobile environment against sophisticated global threats.
In this role, you will:
- Conduct forensic examinations of mobile devices (e.g., Android and iOS phones), including full physical, logical, and file-system acquisitions.
- Perform mobile application assessments to analyze behavior, identifying malicious code, unauthorized data exfiltration, privacy risks, and communication patterns within installed applications.
- Perform consolidated and comprehensive information and intelligence analysis of mobile threat data obtained from classified, proprietary, and open-source resources to provide awareness to relevant stakeholders.
- Analyze and report on unique attack vectors, emerging cyber threats, and current trends used by malicious actors targeting mobile ecosystems.
- Assess the cyber threat environment for U.S. missions worldwide.
- Ensure that forensic community accepted principles and practices are applied throughout the entire lifecycle of the analysis.
- Utilize industry-accepted forensic tools to perform analysis, including but not limited to Cellebrite, Magnet, and other commercial and open-source forensic and app-analysis software.
- Collaborate with other forensic analysts, law enforcement officers, and legal experts to identify and recommend methods and procedures for recovery, preservation, analysis, and presentation of digital evidence.
- Travel to domestic and overseas locations to provide operational briefings and threat awareness.
Qualifications
Minimum Qualifications
- A Bachelor’s degree and 9 years of experience; 7 years with Masters. An additional 4 years of experience may be substituted in lieu of the bachelor's degree requirement.
- Must either possess and maintain, or obtain prior to start date, one of the following professional certifications:
- CASP+ CE
- CCNP Security
- CEH
- CFR
- CHFI
- CISA
- CISSP (or Associate)
- Cloud+
- CND
- CySA+
- GCED
- GCIH
- GICSP
- SSCP
- Demonstrated experience performing mobile device forensic acquisitions.
- Experience analyzing forensic images and data for indicators of compromise (IOCs), root cause and other relevant artifacts pertaining to network intrusion activity.
- Strong critical, creative, and analytical thinking skills.
- Experience developing technically detailed reports that translate complex technical information to non-technical audiences.
- U.S. citizenship and an active Secret security clearance to start.
- Ability to obtain final TS/SCI.
Desired:
Target Salary Range$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.