We are seeking a skilled Digital Forensics Investigator to conduct forensic investigations involving potentially compromised computers, servers, and storage devices. The role will focus on identifying security incidents, unauthorized access, fraudulent activity, and other digital evidence while following established forensic and chain-of-custody procedures.
The ideal candidate will have strong hands-on experience with industry-standard forensic tools and be capable of performing both disk and memory analysis across Windows and Linux environments.
Key Responsibilities
Conduct digital forensic investigations related to:
Security incidents
Unauthorized access
Fraud
Potential system compromise
Acquire, preserve, and analyze forensic images and digital evidence.
Perform disk and filesystem analysis.
Analyze Windows artifacts, including:
Registry
Event logs
Browser activity
User activity
Perform email and communication artifact analysis where applicable.
Conduct memory forensics and analyze volatile system data.
Perform forensic investigations across Windows and Linux environments.
Establish detailed timelines of attacker and/or user activity.
Identify indicators of compromise and relevant forensic artifacts.
Document investigative procedures, evidence, findings, and conclusions.
Prepare detailed and defensible forensic investigation reports.
Maintain proper chain-of-custody and evidence-handling procedures.
Support legal, compliance, security, and internal investigative activities.
Communicate technical findings clearly to both technical and non-technical stakeholders.
Required Technical Skills
EnCase
FTK (Forensic Toolkit)
Autopsy
Magnet AXIOM
Cellebrite
Volatility
Windows forensics
Linux forensics
Disk and filesystem analysis
Memory analysis
Incident response
Digital evidence acquisition and preservation
Required Qualifications
Demonstrated experience conducting digital forensic investigations.
Strong understanding of forensic evidence acquisition, preservation, and analysis.
Hands-on experience with disk, filesystem, registry, browser, email, and memory artifacts.
Experience investigating compromised systems and determining the scope and timeline of activity.
Strong understanding of incident response and forensic investigation methodologies.
Ability to maintain accurate chain-of-custody documentation.
Strong technical writing and forensic reporting skills.
Ability to work independently in a remote environment.
Numbers & Facts
Location
Philadelphia, PA (Remote)
Skills
Analysis Skillsunmatched
Autopsyunmatched
Communication Skillsunmatched
Computer Forensicsunmatched
Computer Securityunmatched
Computer Serversunmatched
Data Analysisunmatched
Documentationunmatched
EnCaseunmatched
File Systemsunmatched
Forensic Scienceunmatched
Forensic Toolkit (FTK)unmatched
Incident Responseunmatched
Industry Standardsunmatched
Investigative Reportsunmatched
Legalunmatched
Linux Operating Systemunmatched
Memory Hardwareunmatched
Microsoft Windows Operating Systemunmatched
Reporting Skillsunmatched
Systems Analysisunmatched
Technical Writingunmatched
Web Browsersunmatched
Writing Skillsunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.