Leidos is looking for a Senior Cyber Forensics Analyst with strong hands-on knowledge of host based forensics to join our Cybersecurity Intelligence & Response team. As a Cyber Forensics Analyst with this team, you will be focused on defending Leidos' global networks through threat hunting, and tactical analysis of ongoing attacks by criminal and nation state actors. In this role you will frequently perform in-depth forensic analysis of compromised hosts in support of incident response efforts. You will be expected to provide oral and well written reports of the analysis performed, methodologies used, and results discovered to coworkers, management, and customers. You will also need to be able to correlate data from numerous sources to reconstruct an event, this can include things like big data analytics, and log analysis.
- Examines and performs comprehensive technical analysis of computer-related evidence and information stored on devices during the course of digital investigations of intrusion activity.
- Conducts offsite forensic collections of digital evidence using best practices and approved software and hardware.
- Mentor and provide skilled technical guidance to staff personnel involved in the investigation process.
- Serves as technical consultant and provide as-needed training in data recovery, forensic examinations, and other related techniques.
- Provides operational and administrative support to the Digital Forensics Laboratory in configuring hardware and software and managing inventories. Ensure evidence is stored and archived in a manner consistent to maintain preservation and protection of data and evidence.
- Provides oral and written communication to staff personnel concerning findings of fact, results of examination(s), and legal declarations, and testify in court as to the procedures and methodology used to recover and identify relevant evidence.
- Examines and performs comprehensive technical analysis of computer-related evidence and information stored on a device(s) during the course of an investigation.
- Bachelor's degree and minimum 8 years of progressive technical experience that demonstrates relevant skills in digital forensic investigations. Additional years of relevant experience will be considered in lieu of Bachelor's degree.
- Must be able to work independently and within a team environment.
- In-depth experience with file system forensics, registry analysis, Internet history analysis, and timeline analysis.
- Experience with forensic media imaging.
- In-depth experience with email analysis.
- Demonstrated experience with forensics tools beyond the classroom, to include EnCase, FTK, Axiom, Blacklight, and others.
- Strong documentation and written communication skills with technical report writing experience.
- Ability to acquire and maintain a Secret, or higher, clearance.
- US Citizenship is required and able to obtain Secret clearance.
- Understanding of behavioral based threat models, including ATT&CK, Cyber Kill Chain, Diamond Model, PICERL etc.
- Industry standard certification(s) such as: CFCE, EnCE, ACE, GIAC, DoD, GCFE, GCFA, GCIH
- Understanding of stenography and encryption detection and analysis
- Understanding of managing complex large data set analysis
- In-depth experience with signature and hash analysis
- Forensic tool and script development
- Programming experience
- Law enforcement investigation experience and understanding of search and seizure