ShorePoint Inc.

Senior Cyber Forensic Analyst

ShorePoint Inc.$110K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a relevant field; a postgraduate degree can substitute for 6 years of experience.
  • 10+ years of experience in digital forensics and incident response.
  • Expertise in complex federal and national security environments.
  • Strong analytical skills for translating complex requirements into actionable tasks.
  • U.S. citizenship with eligibility for security clearance.

Responsibilities

  • Lead advanced digital forensic examinations across various data sources.
  • Collect and document digital evidence while maintaining chain of custody.
  • Reconstruct incident timelines and identify attacker activity and impacts.
  • Lead complex incident response, including triage and recovery validation.
  • Conduct proactive threat-hunting activities based on intelligence and observed behaviors.
  • Analyze security alerts and logs to identify indicators of compromise.
  • Produce clear technical reports and executive summaries for multiple stakeholders.

Benefits

  • Mentorship opportunities for cyber analysts.
  • Opportunity to shape company culture in a growing cybersecurity market.
  • Involvement in a unique, fast-paced project with federal stakeholders.
Full Job Description
We are seeking an experienced Senior Cyber Forensic Analyst to lead advanced digital forensics analysis and incident response support across complex enterprise environments. This role will support threat hunting, incident triage, forensic analysis, continuous monitoring, vulnerability analysis, defensive exercises and cyber performance metrics while producing defensible findings that inform containment, eradication, recovery, risk decisions and corrective actions. The ideal Sr. Cyber Forensic Analyst candidate will bring deep experience collecting, preserving, analyzing and reporting digital evidence, reconstructing cyber events and translating technical findings into timely, actionable information for government stakeholders, incident response personnel, Information System Security Officers (ISSOs) and Federal technical leads. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market. Employment for this position is dependent on the successful award of the contract. for a potential opportunity What you'll be doing: • Lead and perform advanced digital forensic examinations involving endpoint, server, network, cloud, application, removable-media and log-data sources in support of suspected or confirmed cybersecurity incidents. • Collect, preserve, validate, analyze and document digital evidence using sound forensic practices while maintaining evidentiary integrity, chain-of-custody records and reproducible analysis methods. • Reconstruct incident timelines and identify initial access, attacker activity, persistence, lateral movement, data access or exfiltration indicators, affected assets and potential mission or system impacts. • Lead forensic support for complex incident response activities, including scoping, triage, containment recommendations, eradication and recovery validation, post-incident reporting and lessons learned. • Conduct proactive threat-hunting activities using endpoint, network, identity and security-event data and develop and refine hypotheses based on threat intelligence, observed behaviors and environmental risk. • Analyze security alerts, logs, malware artifacts, suspicious files, authentication events and network activity to identify indicators of compromise, tactics, techniques and procedures and detection or monitoring gaps. • Produce clear technical reports, executive-ready summaries, evidence packages, incident timelines, hunt reports and recommended corrective actions for cybersecurity leadership, government stakeholders, ISSOs, Federal Information Systems Security Engineers (ISSEs) and other authorized personnel. • Coordinate with ISSOs to ensure relevant incident, forensic, vulnerability and monitoring findings are reflected in risk assessments, security documentation, continuous-monitoring artifacts, authorization evidence and Plans of Action and Milestones (POA&M) records. • Support vulnerability assessment and defensive-exercise activities by analyzing results, validating operational impact, identifying detection and response gaps and documenting corrective-action recommendations. • Contribute to continuous-monitoring, incident, hunting, detection-effectiveness and capability-gap metrics, identify recurring trends and recommend process or detection improvements. • Develop and maintain forensic playbooks, standard operating procedures, evidence-handling processes and analytical work instructions consistent with customer, program and legal requirements. • Mentor cyber analysts and contribute to an integrated, repeatable and measurable cyber-defense operating model. What you need to know: • Digital forensic investigations and incident response within complex federal, national-security or other highly regulated environments. • Host-, network- and log-based forensic analysis, attack-timeline reconstruction, evidence preservation, chain of custody, forensic imaging and collection, artifact analysis, log correlation, malware triage and incident documentation practices. • Security information and event management (SIEM), endpoint detection and response (EDR), network-security monitoring, forensic-analysis tools and threat-intelligence sources. • Incident-response lifecycle practices, threat hunting, vulnerability analysis, continuous monitoring and control-effectiveness validation. • Cybersecurity risk management, federal security controls, continuous monitoring and the relationship between operational findings and authorization or POA&M activities. • Development of concise, defensible reports, evidence packages and corrective-action recommendations under time-sensitive conditions, including communicating findings to technical and nontechnical stakeholders and coordinating with government stakeholders, ISSOs, security operations personnel and Federal technical authorities. Must have's: • Bachelor's degree from an accredited university; a postgraduate degree from an accredited university may substitute for 6 years of experience. • 10+ years of relevant work experience. • Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking. • Applicants must currently be a U.S. citizen and eligible to obtain and maintain a security clearance, in compliance with federal contract requirements. Beneficial to have: • Active DOE Q or equivalent DoD Top Secret clearance. Where it's done: • Onsite (Albuquerque, NM).

About ShorePoint Inc.

ShorePoint Inc. is a cybersecurity and IT consulting firm that provides services to the federal government and commercial clients. The company's services include cybersecurity, cloud computing, data analytics, and software development. ShorePoint was founded in 2015 and is headquartered in Reston, Virginia. The company has additional offices in Washington, D.C. and Colorado Springs, Colorado.
Learn more about ShorePoint Inc.
Size
300 employees
Industry
Founded
2015

Similar Jobs

More Jobs at ShorePoint Inc.

More Information Technology Jobs

Find similar Senior Cyber Forensic Analyst jobs: