Sr. Forensic Malware Analyst

2 weeks ago


San Antonio, TX, United States Bristol Bay Native Corporation Full time

STS Systems Support, LLC (SSS) is seeking a Sr. Forensic Malware Analyst to support our mission at Lackland AFB in San Antonio, TX.

What You'll Do:

  • Document all findings in the investigation/incident log. (CDRL A008)
  • Track evidence inventory for intake and releasing to the forensics laboratory. This includes insuring proper handling and maintenance of evidence and chain of custody records with no more than 5% error rate.
  • Utilize forensic tools such as, but not limited to; EnCase, FTK, FireEye, etc. and other systems as required.
  • Conduct analysis of metadata and forensic examinations of digital media from a variety of sources including preservation, acquisition, and analysis of digital evidence with the goal of developing forensically sound evidence.
  • Confirm malicious activity when new information is identified through forensic analysis.
  • Investigate network and computer intrusions to identify root cause and generate indicators of compromise and document all findings in the investigation/incident log for each file.
  • Perform memory forensics and malware reverse engineering of suspected malicious files to verify if system compromise occurred document all findings Indicators of Compromise (IOCs) in the investigation/incident log for each file.
  • Perform Hard Drive Analysis of suspected/confirmed infected or exploited systems and document all findings in the investigation/incident log for each hard drive with no more than a 5% error rate.
  • Develop methods to identify, contain, log, and analyze malware-based activities on AF AIS and networks. (A008)
  • Provide support to AF network administrators on the installation and analysis of packet sniffers on their network topology by reporting the functionality status upon request.
  • Generate forensic reports and synopses presenting complex technical processes and findings clearly and concisely to technical and non-technical. (CDRL A008)
  • Collaborate with leadership and external agencies, including Counter-Intelligence activities/agencies, OSI, FBI, and other security agencies, to include Incident Responders, as well as other forensic analysts.
  • Provide AF OSI DCO technical support to law enforcement and counter- intelligence activities.
  • Turn any investigation over to AF OSI if it is determined during the course of an investigation a law was broken.
  • Support and/or augment Incident Response deployment with same day notice. This travel will allow responders to retrieve hard drives or miscellaneous storage media, isolate system(s) for additional investigation, and perform other on-site Incident Response actions.
  • Set up a monitor or "cage" at the on-site location as needed.
  • Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.
  • Provide requested forensic information to operational flight commander as it relates to the Host Detection processes and procedures.
What You Bring

Requirements:
  • DoDD 8570.01-M/8140.01 I AT Level III CND
  • Active TS/SCI
  • More than five (5) years of experience as a Forensic Malware Technician.
  • Experience performing forensic acquisition and examination of Windows, Unix/Linux, and Macintosh-based computers and servers.
  • Strong skill in and a strong understanding of: the use of a variety of forensic tools (Access Data, FTK, Guidance EnCase; including mobility (Axiom/BlackBag , Mobilyze/Cellebrite/Paraben and in, FTK, X-Ways Forensics, FireEye, Volatility, Sleuthkit, BlackBag tools) and various Open Source forensic tools.
  • Shell Scripting is a plus.
  • Experience writing intelligence and technical articles for production and dissemination.
  • Very proficient w/ malware analysis, sandboxing, and software reverse engineering.
  • Proficient Experience with scripting languages such as Python and PowerShell.
  • Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects). Required: SANS GCFA (or equivalent).
Desired:
  • GREM, GCTI and/or ACE


What We Offer:

STS Systems Support, LLC (SSS) offers a competitive benefits package to include paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.

SSS is an Equal Opportunity Employer. Employment decisions are made without regard to any protected category. Hiring preference will be given to BBNC shareholders, their spouses and descendants and Alaska Natives in accordance with Public Law 93-638

  • San Antonio, TX, United States Booz Allen Hamilton Full time

    Job Number: R0229227Cyber Defense Forensics Analyst The Opportunity: As a security operations center analyst, you're in the middle of the action, responding to and mitigating threats in real time. You're the first line of cyber defense for your organization, and they look to you for guidance on best practices and security measures. We need a Tier 2 SOC...

  • Exploitation Analyst

    2 weeks ago


    San Antonio, TX, United States iNovex Information Systems Full time

    RealmOne is FOCUSED on you! RealmOne was built on the principle that people matter first and foremost. We believe in providing a strong work/life balance by investing in our employees and encouraging professional and personal growth. We do this by offering exceptional benefits, flexible schedules, and the tools necessary to achieve success through paid...


  • San Antonio, TX, United States Cymertek Full time

    Digital Network Exploitation Analyst (DNEA)LOCATION San Antonio, TX 78208 CLEARANCE TS/SCI CI Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a highly skilled and analytical Digital Network Exploitation Analyst (DNEA) to join our innovative team. In this role, you will leverage advanced tools and methodologies to...


  • San Antonio, TX, United States Cymertek Full time

    Digital Network Exploitation Analyst (DNEA)LOCATION San Antonio, TX 78208 CLEARANCE TS/SCI CI Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a highly skilled and analytical Digital Network Exploitation Analyst (DNEA) to join our innovative team. In this role, you will leverage advanced tools and methodologies to...


  • San Antonio, TX, United States Cymertek Full time

    Digital Network Exploitation Analyst (DNEA)LOCATION San Antonio, TX 78208 CLEARANCE TS/SCI CI Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a highly skilled and analytical Digital Network Exploitation Analyst (DNEA) to join our innovative team. In this role, you will leverage advanced tools and methodologies to...


  • San Antonio, TX, United States Amyx Full time

    Sr. Contract AnalystJob Locations US-TX-San AntonioID 2025-4268Category DefenseType Full TimeOverviewAmyx, Inc. is seeking a Senior Contract Analyst to be located in San Antonio, TX, to support the Defense Health Agency (DHA). The DHA is responsible for the effective execution and operation of the Department of Defense's (DoD) medical mission, which is...


  • San Antonio, TX, United States Evotech Full time

    Company Description EvoTech, LLC is an Economically Disadvantaged Woman-Owned Small Business (EDWOSB) delivering program management, application development, cybersecurity, and IT solutions to federal government agencies and commercial clients. We are committed to advancing innovative technologies and fostering a culture of creativity. Guided by our vision...

  • Sr. Analyst

    2 days ago


    San Antonio, TX, United States Purple Drive Full time

    Location: San Antonio, TX / Plano, TXRole: Sr. AnalystExperience Required: Relevant experience in Insights Delivery, Reporting, Dashboarding, and Data AnalysisSummary This role focuses on insights delivery, reporting, dashboard development, and data analysis using SAS, SQL, Tableau, and Python. The candidate will perform data discovery, exploratory analysis,...


  • San Antonio, TX, United States Cymertek Full time

    Android Mobile Reverse EngineerLOCATION San Antonio, TX 78208 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a skilled Android Mobile Reverse Engineer to join our team and tackle complex challenges in analyzing, deconstructing, and understanding Android applications and systems. In this role,...


  • San Antonio, TX, United States Cymertek Full time

    Android Mobile Reverse EngineerLOCATION San Antonio, TX 78208 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a skilled Android Mobile Reverse Engineer to join our team and tackle complex challenges in analyzing, deconstructing, and understanding Android applications and systems. In this role,...