About the role

Lead Cyber Defense Forensics Analyst This position serves as the senior forensic practitioner on a federal enterprise cybersecurity program operating within government-controlled secure facilities. The forensics function supports the full cyber defense mission — conducting complex digital forensic investigations, driving incident response analysis, and contributing to threat hunt operations at the classified level. This is a hands-on technical lead role, not an organizational management position. The core challenge: leading forensic investigations of the highest technical complexity within a classified environment — setting the analytic standard, producing legally defensible findings, and ensuring that forensic work directly informs and accelerates the program's incident response and threat hunt capabilities. As Lead Cyber Defense Forensics Analyst at Revolutional, you are the program's most senior forensic practitioner. You own the most complex investigations, set the technical standard for forensic methodology, and serve as the subject matter authority on computer forensics, network analysis, and evidentiary handling across the cyber defense mission. You work alongside — not above — the SOC Chief, contributing deep technical expertise where it matters most: inside the investigation. You bring 5 to 7 years of hands-on experience across digital forensics, incident response, and threat hunting, and you operate in full alignment with the NICE Cybersecurity Workforce Framework Cyber Defense Forensics Analyst role (IN-FOR-002). Your core competencies span Computer Forensics, Computer Network Defense, Software Testing and Evaluation, System Administration, and Threat Analysis — and you apply all of them under classified conditions, within government-controlled secure facilities, every day.
Responsibilities: Lead digital forensic investigations of the highest technical complexity; conduct end-to-end analysis from evidence acquisition through findings documentation within classified, government-controlled secure facilities Perform host-based forensic analysis: disk and memory acquisition, file system examination, artifact recovery, malware triage, and attack timeline reconstruction across Windows and Linux environments Conduct network forensic analysis: packet capture review, Net Flow correlation, log analysis, and identification of lateral movement, exfiltration, and command-and-control activity Maintain strict chain of custody for all evidence collected and handled; ensure all forensic work meets applicable federal legal and evidentiary standards Provide direct analytical support to incident response operations; contribute forensic findings that drive containment, eradication, and recovery decisions in real time Support threat hunt activities with forensic analysis: investigate hunt leads, validate hypotheses, and extract IOCs that feed detection improvements Apply Software Testing and Evaluation methodology to validate forensic tools and assess new capabilities before operational deployment Apply system administration knowledge across Windows and Linux environments to scope investigations, interpret artifacts, and assess attacker activity accurately Apply Threat Analysis tradecraft to map forensic findings to adversary TTPs using MITRE ATT&CK and other structured frameworks Produce thorough, legally defensible forensic reports documenting methodology, findings, evidence handling, and recommended response actions Maintain current awareness of adversary tradecraft, malware families, forensic evasion techniques, and emerging investigation methodologies Ensure compliance with NICE Cybersecurity Workforce Framework IN-FOR-002 role definition and associated role-based training requirements What You Bring (Requirements)
Baseline Requirements: Bachelor's degree in Computer Science, Digital Forensics, Information Security, or related field (or equivalent experience)5 to 7 years of hands-on experience in digital forensics, incident response, and threat hunting, with demonstrated lead-level technical proficiency Active Top Secret/SCI clearance (Final) required Must work onsite within a government-controlled secure facility Technical & Domain Capabilities Expert-level Computer Forensics: disk and memory acquisition, file system and artifact analysis, malware triage, timeline reconstruction, and chain of custody management to legal and evidentiary standards Core competency in Computer Network Defense: intrusion detection, alert triage, network traffic analysis, and defensive posture assessment applied to forensic investigation scoping and findings Experience with Software Testing and Evaluation applied to forensic tool validation, capability testing, and pre-deployment assessment of new investigation technologies Working knowledge of System Administration across Windows and Linux environments sufficient to accurately scope investigations, interpret system artifacts, and reconstruct attacker activity Core competency in Threat Analysis: MITRE ATT&CK-based TTP mapping, threat actor profiling, and structured analytic frameworks applied to forensic findings Proficiency with industry-standard forensic tools: EnCase, FTK, Autopsy, Volatility, Wireshark, or equivalent Experience operating within the NICE Cybersecurity Workforce Framework IN-FOR-002 role definition; current on applicable role-based training requirements Core Strengths Technically elite forensic practitioner — your investigations are thorough, your methodology is sound, and your findings hold up under legal and operational scrutiny Analytically independent: you take complex, ambiguous investigations and drive them to conclusion without needing the situation pre-defined Rigorous in classified environments — chain of custody, access controls, and handling requirements are instinctive, not procedural Effective technical contributor to incident response and threat hunt teams; your forensic findings accelerate the broader mission, not just your own workstream
Certifications: One or more of the following is required or strongly preferred: GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner), EnCE (EnCase Certified Examiner), CFCE (Certified Forensic Computer Examiner), or GCIH (GIAC Certified Incident Handler)Role-based training required per NICE Cybersecurity Workforce Framework IN-FOR-002 — must be current or completed within required timeframes Nice to Have (Differentiators)GREM (GIAC Reverse Engineering Malware) or equivalent advanced malware analysis credentialGNFA (GIAC Network Forensic Analyst) for candidates with deep network forensics depth Experience conducting forensic investigations at TS/SCI level within SCIFs or other government-controlled secure facilities Background in mobile device forensics, cloud forensics, or memory forensics at advanced levels Experience supporting legal proceedings or law enforcement actions with forensic evidence and findings documentation Familiarity with emerging forensic evasion techniques and anti-forensics tradecraft used by advanced threat actors

Matching similar jobs

JOB OVERVIEW

Experience level

Lead

Location

Suitland, MD

Occupation

Digital Forensics Analysts

Industry

Computer Systems Design Services

Posted

today

Tired of running searches?

Rank the roles you'd take once, and matches like these arrive on their own.

CREATE PROFILE