Memory Forensics Analyst - DT #11 - Remote

Compu-Vision - IT
  • Philadelphia, PA
  • Remote
    1 day ago

    Job Description

    Memory Forensics Analyst

    Location: Remote
    Duration: 1–2 Weeks with potential extension

    Position Overview

    We are seeking an experienced Memory Forensics Analyst to investigate volatile memory and identify evidence of sophisticated cyberattacks, malware activity, and advanced persistence mechanisms.

    The role will focus on RAM acquisition and analysis, malicious process identification, code injection detection, memory-resident malware, credential artifacts, and correlation of memory findings with endpoint and network evidence. The ideal candidate will have strong expertise in Windows and Linux memory structures, malware analysis, and incident response.

    Key Responsibilities

    • Acquire and analyze RAM and volatile memory images from compromised systems.
    • Identify suspicious or malicious:
      • Processes
      • Threads
      • DLLs and loaded modules
      • Injected code
      • Network connections
      • Memory-resident artifacts
    • Investigate fileless malware and other memory-resident threats.
    • Identify advanced persistence mechanisms and indicators of compromise.
    • Analyze Windows memory structures and Linux memory artifacts.
    • Investigate credential-related artifacts and suspicious authentication activity within memory.
    • Correlate memory-forensic findings with endpoint and network evidence.
    • Perform malware analysis and support reverse-engineering activities when required.
    • Develop detailed incident timelines based on volatile-memory evidence and other investigative data.
    • Support incident response and threat-hunting activities.
    • Document forensic methodology, evidence, findings, and conclusions.
    • Prepare technical forensic reports and communicate findings to security and incident response teams.

    Key Technical Skills

    Memory Forensics

    • Volatility
    • Rekall
    • Windows memory structures
    • Linux memory analysis
    • RAM acquisition and analysis
    • Process and thread analysis
    • DLL/module analysis
    • Code injection detection
    • Network connection analysis
    • Credential artifact analysis

    Malware & Threat Analysis

    • Malware analysis
    • Fileless malware investigation
    • Reverse engineering
    • Persistence mechanism analysis
    • Indicators of Compromise (IOCs)
    • Advanced attack investigation

    Scripting & Automation

    • Python
    • PowerShell

    Incident Response

    • Incident response
    • Endpoint investigation
    • Network evidence correlation
    • Timeline development
    • Digital evidence analysis and documentation

    Required Qualifications

    • Proven experience in memory forensics, digital forensics, malware analysis, or incident response.
    • Strong hands-on experience analyzing RAM and volatile memory images.
    • Proficiency with Volatility and/or Rekall.
    • Strong understanding of Windows memory structures and processes.
    • Experience with Linux memory analysis.
    • Ability to identify malicious processes, injected code, DLLs, network connections, and other suspicious memory artifacts.
    • Experience investigating fileless malware and advanced persistence techniques.
    • Understanding of malware analysis and reverse-engineering methodologies.
    • Strong Python and/or PowerShell scripting skills.
    • Experience correlating memory evidence with endpoint and network telemetry.
    • Strong analytical, investigative, and technical documentation skills.
    • Ability to work independently in a remote environment.

    Numbers & Facts

    LocationPhiladelphia, PA (
    Remote
    )

    Skills

    • Analysis Skillsunmatched
    • Authenticationunmatched
    • Communication Skillsunmatched
    • Computer Forensicsunmatched
    • Computer Securityunmatched
    • Forensic Scienceunmatched
    • Huntingunmatched
    • Incident Responseunmatched
    • Injectionsunmatched
    • Linux Operating Systemunmatched
    • Malwareunmatched
    • Malware Analysisunmatched
    • Memory Hardwareunmatched
    • Microsoft Windows DLL (Dynamic Link Library)unmatched
    • Microsoft Windows Operating Systemunmatched
    • Network Connectivityunmatched
    • Network Performance/Analysisunmatched
    • Process Analysisunmatched
    • Process Developmentunmatched
    • Python Programming/Scripting Languageunmatched
    • Reverse Engineeringunmatched
    • Scripting (Scripting Languages)unmatched
    • Technical Writingunmatched
    • Telemetryunmatched
    • Volatile Memoryunmatched
    • Windows PowerShellunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder