Leidos is looking for a Sr. Cyber Forensics Analyst with strong hands-on knowledge of host based forensics to join our Cybersecurity Intelligence & Response team. As a Cyber Forensics Analyst with this team, you will be focused on defending Leidos' global networks through threat hunting, and tactical analysis of ongoing attacks by criminal and nation state actors. In this role you will frequently perform in-depth forensic analysis of compromised hosts in support of incident response efforts. You will be expected to provide oral and well written reports of the analysis performed, methodologies used, and results discovered to coworkers, management, and customers. You will also need to be able to correlate data from numerous sources to reconstruct an event, this can include things like big data analytics, and log analysis.
- Examine and perform comprehensive technical analysis of computer-related evidence and information stored on devices during the course of digital investigations of intrusion activity.
- Conduct offsite forensic collections of digital evidence using best practices and approved software and hardware.
- Mentor and provide skilled technical guidance to staff personnel involved in the investigation process.
- Serve as technical consultant and provide as-needed training in data recovery, forensic examinations, and other related techniques.
- Provide operational and administrative support to the Digital Forensics Laboratory in configuring hardware and software and managing inventories. Ensure evidence is stored and archived in a manner consistent to maintain preservation and protection of data and evidence.
- Provide oral and written communication to staff personnel concerning findings of fact, results of examination(s), and legal declarations, and testify in court as to the procedures and methodology used to recover and identify relevant evidence.
- Examine and perform comprehensive technical analysis of computer-related evidence and information stored on a device(s) during the course of an investigation.
- Bachelor's degree and minimum 8 years of progressive technical experience that demonstrates relevant skills in digital forensic investigations. Additional years of relevant experience will be considered in lieu of Bachelor's degree.
- Must be able to work independently and within a team environment.
- In-depth experience with file system forensics
- In-depth experience with registry analysis
- In-depth experience with Internet history analysis
- In-depth experience with timeline analysis
- Experience with forensic media imaging
- In-depth experience with email analysis
- Demonstrated experience with forensics tools beyond the classroom, to include EnCase, FTK, Axiom, Blacklight, and others
- Strong documentation and written communication skills with technical report writing experience
- Must be US Citizen and able to acquire and maintain a Secret, or higher, clearance
- Understanding of behavioral based threat models, including ATT&CK, Cyber Kill Chain, Diamond Model, PICERL etc.
- Industry standard certification(s) such as: CFCE, EnCE, ACE, GIAC, DoD, GCFE, GCFA, GCIH
- Understanding of stenography and encryption detection and analysis
- Understanding of managing complex large data set analysis
- In-depth experience with signature and hash analysis
- Forensic tool and script development
- Programming experience
- Law enforcement investigation experience and understanding of search and seizure
External Referral Bonus:
Potential for Telework:
Clearance Level Required:
Yes, 10% of the time
Scheduled Weekly Hours: