Leidos is looking for a Cyber Forensics Analyst with strong hands-on knowledge of host based forensics to join our Cybersecurity Intelligence & Response team in Gaithersburg - MD.
In this role, you will focus on corporate forensic investigations and eDiscovery support requests, as well as defending Leidos' global networks through threat hunting, tactical analysis of ongoing attacks by criminal and nation state actors. Furthermore, you will frequently perform in-depth forensic investigations for the Security, Insider Risk, Ethics, and Legal organizations and provide forensic analysis support to the CSIRT Intrusions team. Supporting incidents and investigations will require you to "think like an adversary" as both an external actor and an insider risk. You will be expected to provide oral and well written reports of the analysis performed, methodologies used, and results discovered to coworkers, management, and customers. You will also need to be able to correlate data from numerous sources to reconstruct an event, this can include things like big data analytics, and log analysis.
- Examines and performs comprehensive technical analysis of computer-related evidence and information stored on devices during the course of digital investigations and litigation support requests.
- Conducts offsite forensic collections of digital evidence using best practices and approved software and hardware (travel required).
- Provides skilled technical guidance and assistance to staff personnel involved in the investigation and litigation process to ensure precautions are taken to prevent spoliation of evidence.
- Serves as technical consultant and provide as-needed training in data recovery, forensic examinations, and other related techniques.
- Provides operational and administrative support to the Digital Forensics Laboratory in configuring hardware and software and managing inventories. Ensure evidence is stored and archived in a manner consistent to maintain preservation and protection of data and evidence. Ensure all hardware and software is verified and validated in accordance with established guidelines and the Federal Rules of Evidence.
- Provides oral and written communication to staff personnel concerning findings of fact, results of examination(s), and legal declarations, and testify in court as to the procedures and methodology used to recover and identify relevant evidence.
- Examines and performs comprehensive technical analysis of computer-related evidence and information stored on a device(s) during the course of an investigation or litigation.
- Bachelor's degree and 4-8 years of progressive technical experience that demonstrates relevant skills in digital forensic investigations.
- Must have experience in investigative and litigation support principles and methodologies.
- Must be able to work independently and within a team environment.
- In-depth experience with file system forensics
- In-depth experience with registry analysis
- In-depth experience with Internet history analysis
- In-depth experience with timeline analysis
- Experience with forensic media imaging
- In-depth experience with email analysis
- Demonstrated experience with forensics tools beyond the classroom, to include EnCase, FTK, Axiom, Blacklight, and others
- Strong documentation and written communication skills with technical report writing experience
- US Citizenship is required and able to acquire and maintain a Secret clearance
- Understanding of behavioral based threat models, including ATT&CK, Cyber Kill Chain, Diamond Model, PICERL etc.
- Industry standard certification(s) such as: CFCE, EnCE, ACE, GIAC, DoD, GCFE, GCFA, GCIH
- Understanding of stenography and encryption detection and analysis
- Understanding of managing complex large data set analysis
- In-depth experience with signature and hash analysis
- Forensic tool and script development
- Programming experience
- Law enforcement investigation experience and understanding of search and seizure