Cyber Forensics Analyst

3 weeks ago


Arlington, Virginia, United States Gray Tier Technologies LLC Full time

Gray Tier Technologies LLC is seeking a Cyber Forensics Analyst to support the DHS Hunt and Incident Response Team (HIRT).

This team secures the Nation's cyber and communications infrastructure while providing front line response for cyber incidents and hunting for malicious cyber activity.

Our team performs HIRT investigations to develop a diagnosis of the severity of breaches.

Contract personnel provide front line response for digital forensics/incident response and proactively hunting for malicious cyber activity for this critical customer mission.


Responsibilities:

  • Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack.
  • Assess network topology and device configurations identifying critical security concerns and providing security best practice recommendations.
  • Collect network intrusion artifacts (e.g., PCAP, domains, URI's, certificates, etc.) and use discovered data to enable mitigation of potential incidents.
  • Collect network device integrity data and analyze for signs of tampering or compromise.
  • Analyze identified malicious network and system log activity to determine weaknesses exploited, exploitation methods, effects on system and information.
  • Track and document onsite incident response activities and provide updates to leadership through executive summaries and in-depth technical reports.
  • Plan, coordinate, and direct the inventory, examination, and comprehensive technical analysis of computer-related evidence.
  • Serve as technical forensics liaison to stakeholders and explain investigation details.

Required Skills:

  • U.S. Citizenship.
  • Active DoD Secret clearance. Must be able to obtain a TS/SCI clearance.
  • Must be able to obtain DHS Suitability.
  • 8+ years of directly relevant experience in cyber forensic and network investigations using leading edge technologies and industry standard forensic tools.
  • Experience leading cross-functional teams conducting cyber threat hunting activities.
  • Experience with reconstructing a malicious attack or activity.
  • Ability to characterize and analyze network traffic, identify anomalous activity/potential threats, analyze anomalies in network traffic using metadata.
  • Ability to create forensically sound duplicates of evidence (forensic images).
  • Able to write cyber investigative reports documenting forensics findings.
  • In-depth knowledge and experience of:
  • Utilizing COTS and custom-developed tools to detect APT activity.
  • Reviewing threat reports and searching the network for applicable IOC (Indicators of Compromise).
  • Identifying different classes and characterization of attacks and attack stages.
  • CND policies, procedures, and regulations.
  • Of network topologies, Wi-Fi Networking, and TCP/IP protocols.
  • Splunk (or other SIEMs).
  • Vulnerability scanning, assessment, and monitoring tools such as Security Center, Nessus, and Endgame.
  • Mitre Adversary Tactics, Techniques, and Common Knowledge (ATT&CK).
  • Must be able to work collaboratively across physical locations.

Desired Skills:

  • Experience and proficiency with the following tools and techniques:
  • EnCase, FTK, SIFT, X-Ways, Volatility, WireShark, Sleuth Kit/Autopsy, and Snort.

EDR Tools:
Crowdstrike, Carbon Black, etc

  • Carving and extracting information from PCAP data.
  • Non-traditional network traffic: Command and Control.
  • Preserving evidence integrity according to national standards.
  • Designing cyber security systems and environments in a Linux environment.
  • Virtualized environments.
  • Conducting all-source research.

Required Education:


BS Computer Science, Cybersecurity, Computer Engineering, or related degree; or HS Diploma and 10+ years of host or digital forensics or network forensic experience.


Desired Certifications:

  • GCFA, GCFE, EnCE, CCE, CFCE, CEH, CCNA, CCSP, CCIE, OSCP, GNFA
On-Site work 2-3 days per week

  • Arlington, Virginia, United States Argo Cyber Systems Full time

    Job Title: Host Based Cyber Systems Analyst IVJob Summary:Argo Cyber Systems is seeking a highly skilled Host Based Cyber Systems Analyst IV to join our team. As a key partner to the Department of Homeland Security (DHS), we provide critical support to the Hunt and Incident Response Team (HIRT) in securing the Nation's cyber and communications...


  • Arlington, Virginia, United States Nightwing Full time

    Job SummaryNightwing is seeking a skilled Cyber Host Forensic Analyst to support a critical customer mission. The ideal candidate will have 2+ years of experience in cyber forensic investigations using leading edge technologies and industry standard forensic tools.Key ResponsibilitiesAcquiring and collecting computer artifacts, correlating forensic findings...


  • Arlington, Virginia, United States Nightwing Full time

    Job Summary:At Nightwing, we are seeking a highly skilled Cyber Forensic Analyst IV to join our team. As a Cyber Forensic Analyst IV, you will be responsible for leading forensic teams at onsite engagements, providing technical assistance on digital evidence matters, and writing in-depth reports. You will also be responsible for supporting forensic analysis,...


  • Arlington, Virginia, United States Raytheon Technologies Full time

    Job Title: Cyber Host Forensic Analyst IVAt Nightwing, we are seeking a highly skilled Cyber Host Forensic Analyst IV to join our team. As a key member of our cybersecurity team, you will be responsible for conducting forensic investigations and analyzing digital evidence to support our customers' most critical missions.Responsibilities:Assist federal leads...


  • Arlington, Virginia, United States Raytheon Technologies Full time

    Job Title: Cyber Host Forensic Analyst IIJob Summary:We are seeking a highly skilled Cyber Host Forensic Analyst II to join our team. As a Cyber Host Forensic Analyst II, you will be responsible for conducting forensic investigations of cyber attacks, analyzing digital evidence, and providing expert testimony in court.Responsibilities:Conduct forensic...


  • Arlington, Virginia, United States Raytheon Technologies Full time

    Job Summary:RTX is seeking a highly skilled Cyber Forensic Analyst III to support our critical customer mission. As a member of our team, you will assist Federal leads with overseeing and leading forensic teams at onsite engagements, providing technical assistance on digital evidence matters, and writing in-depth reports. Responsibilities:Assist with leading...


  • Arlington, Virginia, United States Raytheon Technologies Full time

    Cyber Host Forensic Analyst RoleThis role is part of a team that provides technically advanced full-spectrum cyber, data operations, systems integration and intelligence mission support services to meet our customers' most demanding challenges. We are seeking a Cyber Host Forensic Analyst to support our critical customer mission. The selected candidate will...


  • Arlington, Virginia, United States Nightwing Full time

    Job Summary:Nightwing is seeking a highly skilled Cyber Forensic Analyst IV to support our critical customer mission. As a key member of our team, you will be responsible for leading forensic teams at onsite engagements, providing technical assistance on digital evidence matters, and writing in-depth reports.Responsibilities:Assisting Federal leads with...


  • Arlington, Virginia, United States Raytheon Technologies Full time

    Job SummaryWe are seeking a highly skilled Cyber Host Forensic Analyst to support our critical customer mission. As a Cyber Host Forensic Analyst, you will be responsible for acquiring and collecting computer artifacts, assessing evidentiary value, and correlating forensic findings with network events. You will also be responsible for performing incident...


  • Arlington, Virginia, United States Raytheon Technologies Full time

    Job SummaryWe are seeking a highly skilled Cyber Host Forensic Analyst III to support our critical customer mission. As a key member of our team, you will be responsible for assisting federal leads with overseeing and leading forensic teams at onsite engagements, providing technical assistance on digital evidence matters, and writing in-depth...


  • Arlington, Virginia, United States Nightwing Full time

    About the Role:Nightwing is seeking a highly skilled Cyber Host Forensic Analyst to join our team. As a Cyber Host Forensic Analyst, you will be responsible for conducting forensic investigations to identify and analyze cyber threats. You will work closely with our team to identify and characterize cyber attacks, develop mitigation plans, and assist with the...


  • Arlington, Virginia, United States Raytheon Technologies Full time

    Job Summary:Raytheon Technologies is seeking a highly skilled Cyber Host Forensic Analyst IV to support our critical customer mission. As a member of our team, you will assist federal leads with overseeing and leading forensic teams at onsite engagements, providing technical assistance on digital evidence matters, and writing in-depth...


  • Arlington, Virginia, United States Nightwing Full time

    Job Title: Cyber Host Forensics Analyst IIIAbout the Role:Nightwing is seeking a highly skilled Cyber Host Forensics Analyst III to support our critical customer mission. As a key member of our team, you will be responsible for leading forensic teams at onsite engagements, providing technical assistance on digital evidence matters, and writing in-depth...


  • Arlington, Virginia, United States Nightwing Full time

    About the Role:Nightwing is seeking a skilled Cyber Host Forensic Analyst to support our critical customer mission. As a member of our team, you will be responsible for acquiring and collecting computer artifacts, assessing evidentiary value, and correlating forensic findings with network events.Responsibilities:Acquiring and collecting computer artifacts...


  • Arlington, Virginia, United States Solutions3 Full time

    Job Title: Host Based Systems Analyst IVSolutions3 LLC is seeking an experienced Host Based Systems Analyst IV to provide front-line response for digital forensics/incident response (DFIR) and proactively hunt for malicious cyber activity.Responsibilities:Assist Federal leads with overseeing and leading forensic teams at onsite engagements by coordinating...


  • Arlington, Virginia, United States Nightwing Full time

    Job SummaryAt Nightwing, we are seeking a highly skilled Cyber Network Forensic Analyst II to join our team. As a Cyber Network Forensic Analyst II, you will be responsible for conducting thorough investigations of network security incidents, analyzing network traffic, and identifying potential threats to our customers' networks.Responsibilities* Assist the...


  • Arlington, Virginia, United States BCMC Full time

    Job OverviewThe Hunt and Incident Response Team (HIRT) at DHS secures the Nation's cyber and communications infrastructure. As a Host Forensics Analyst, you will be part of a team that provides front-line response for cyber incidents and proactively hunts for malicious cyber activity. Your expertise will be crucial in developing a preliminary diagnosis of...


  • Arlington, Virginia, United States Argo Cyber Systems Full time

    Job SummaryWe are seeking a highly skilled Deputy Cyber Incident Response Team Manager to join our team at Argo Cyber Systems. As a key member of our Cyber Defense Mission, you will play a critical role in ensuring exceptional service for our managed services customers and driving employee engagement for our CIRT staff members.Key ResponsibilitiesSupport the...


  • Arlington, Virginia, United States BCMC Full time

    Job DescriptionThe DHS's Hunt and Incident Response Team (HIRT) secures the Nation's cyber and communications infrastructure. HIRT provides DHS's front-line response for cyber incidents and proactively hunting for malicious cyber activity. BCMC, as a contractor to DHS, performs HIRT investigations to develop a preliminary diagnosis of the severity of...


  • Arlington, Virginia, United States Raytheon Technologies Full time

    Job Summary:RTX is seeking a highly skilled Cyber Network Forensic Analyst III to join our team. As a Cyber Network Forensic Analyst III, you will be responsible for assisting the Government lead in coordinating teams in preliminary incident response investigations, determining appropriate courses of actions in response to identified and analyzed anomalous...