Cyber Defense Forensics Analyst [Various Levels] Contingent
Quick Summary
Execute digital forensic collections, host-based memory analysis, disk image acquisition, and reverse engineering during operational security incidents.
Cybersecurity Operations (CSO)
612 - Cyber Defense Forensics Analyst
Intermediate
No
Requirements
~1 min readActive Secret or Top Secret
Personnel assigned to this role must satisfy the foundational qualification requirements for DCWF Work Role 612 at an Intermediate proficiency level prior to commencing work. Qualifying certifications across proficiency tiers include:
The Cyber Defense Forensics Analyst serves within the Cybersecurity Operations (CSO) capability area to support incident response, threat analysis, and digital evidence processing for global C4ISR and distribution operations. Operating in accordance with DoDM 8140.03 standards, this role performs deep-dive technical investigations, host and network-level artifact recovery, and threat timeline reconstruction to ensure operational effectiveness and mission assurance during active security events.
Responsibilities
~1 min read- →Digital Forensics & Artifact Collection: Execute digital forensic collections, host-based memory analysis, disk image acquisition, and reverse engineering during operational security incidents.
- →Evidence Handling & Chain of Custody: Maintain strict evidence handling and legal chain-of-custody protocols for all collected host artifacts, network packet captures, and system memory dumps.
- →Threat Analysis & Reconstruction: Evaluate disk images, volatile memory, system logs, and network traffic captures to reconstruct attack vectors, establish timelines, and determine breach scope and impact.
- →Incident Response Technical Support: Assist in technical measures to isolate, contain, eradicate, and recover from security events upon direction from the COR.
- →Reporting & CDRL Deliverables: Author comprehensive forensic investigation reports and provide technical analysis inputs for formal Security Incident Reports.
- Technical degree in Cybersecurity, Computer Science, Information Technology, or a related field, OR 5+ years of direct operational experience in digital forensics and cyber incident response.
Security+, GCFE, CCFP
SecurityX (CASP+), CISSP, GCFA
- Workforce Qualification Compliance: Contractor personnel must be fully qualified and certified prior to performance. Compliance is tracked and verified via the Personnel Qualification & Certification Report (CDRL A008) and quarterly training rosters (CDRL A050).
- Privileged Access Requirements: Must meet residential qualification requirements for elevated or privileged network access prior to performing technical duties.
- Security Program Adherence: Execute all information handling in strict accordance with AR 380-5 for classified data and DoDI 5200.48 for Controlled Unclassified Information (CUI).
What We Offer
~1 min readEmployment for this role is conditional upon contract award, executed funding, and client approval. Advertised ranges do not constitute a binding promise of specific salary. In compliance with applicable federal, state, and municipal pay transparency requirements—including but not limited to pay disclosure rules in California, Colorado, New York, and Washington—posted salary bands remain flexible. Compensation ranges may be modified prior to an offer to reflect candidate expertise, client budget constraints, and localized geographic pay scales tied to the assigned work site or state of residence.
Location & Eligibility
Listing Details
- First seen
- October 9, 2026
- Last seen
- October 9, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 58%
- Scored at
- October 9, 2026
Signal breakdown
4 other jobs at
View all →Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.