Digital Forensics Lead Science Applications International CorpDigital Forensics LeadBethesda, MD$200,001–$240,000 / yearRequired Certifications (at least one): DC3 Cyber Training Academy Digital Forensic Examiner (DFE), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Forensic Examiner (GCFE), GIAC Certified Incident Handler (GCIH), EnCase Certified Examiner (EnCE), or equivalent certification approved by the COR. This position provides oversight of forensic examination personnel, manages laboratory workflows, and ensures the timely, technically defensible extraction and analysis of data from digital devices and media in support of the customer's intelligence mission.
Digital Forensics Examiner PeratonDigital Forensics ExaminerBethesda, Maryland$135,000–$216,000 / yearFull timeA degree in one of the following fields is highly desired: Cybersecurity, Computer Science, Information Systems, Information Technology, Mathematics, Data Science, or Software Engineering. Perform comprehensive analysis, including timeline generation, file signature and hash analysis, email and communication analysis, and examination of large, complex datasets.
Cyber Defense Forensics Lead ManTechCyber Defense Forensics LeadAshburn, VAThe ultimate purpose of this role is to provide the disciplined leadership and structural organization necessary to rapidly implement critical, high-impact security solutions that directly protect the Nation's digital borders while ensuring continuous, compliant contract delivery for 24x7x365 network, cyber, and cloud services. + Certified Information System Security Professional (CISSP) and at least one of the following: SANS GIAC Certified Intrusion Analyst (GCIA), SANS GIAC Certified Incident Handler (GCIH), SANS GIAC Certified Forensic Analyst (GCFA), SANS GIAC Certified Enterprise Defender (GCED), or other IAT Level III certification.
Senior Director, Digital Forensics & Incident Response AstraZeneca PlcSenior Director, Digital Forensics & Incident ResponseGaithersburg, MD$190,957–$286,435 / yearThis role commands the enterprise response to material incidents across cloud, on-premises and OT/ICS environments; owns incident governance, readiness and the forensic defensibility of all collected evidence; and is accountable for executive reporting, lessons learned and the control hardening that follows. Automation and AI in Operations: Experience operationalising modern security tooling, including SIEM, SOAR and XDR, together with artificial intelligence, large language model and agentic capabilities to enable triage, analysis and eradication at scale, with clear human accountability for consequential decisions.
Digital Forensics Examiner Peraton IncDigital Forensics Examinerlinthicum, MD$112,000–$179,000 / yearCertifications: One or more of the following active forensic certifications - Digital Media Collector (DMC), Digital Forensic Examiner (DFE), Cyber Crime Investigator (CCI), Computer Hacking Forensic Investigator (CHFI), International Association of Computer Investigative Specialists (IACIS) certifications: Certified Computer Examiner (CCE) Certified Forensic Computer Examiner (CFCE), GIAC Certified Forensic Examiner (GCFE), GIAC Certified Forensic Analyst (GCFA), Certifications related to mobile device forensic tools (e.g. Cellebrite Certified Mobile Examiner (CCME), XRY, Oxygen Forensic Certified Examiner (OFCE)), Certifications related to computer forensic tools (e.g., EnCase Certified Examiner (EnCE), X- Ways Professional in Evidence Recovery Techniques (X-PERT), Magnet Certified Forensic Examiner (MCFE)), Data recovery or advanced data acquisition related certifications.
AI/ML Automation Engineer Argo Cyber SystemsAI/ML Automation EngineerArlington, VAFull timeCitizenshipActive Secret Security ClearanceAbility to obtain DHS Entry on Duty (EOD) SuitabilityBachelor's degree in Computer Science, Artificial Intelligence, Data Science, Software Engineering, Computer Engineering, or related STEM fieldFive (5) or more years of professional experience developing AI, ML, automation, or data engineering solutionsStrong Python development experienceExperience with Databricks AI PlatformExperience implementing machine learning pipelinesExperience integrating Large Language Models (LLMs)Experience with Amazon Bedrock and AWS AI servicesExperience building REST APIs and cloud-native applicationsExperience with Git, CI/CD pipelines, and software development best practicesStrong analytical, problem-solving, and communication skillsPreferred QualificationsActive TS/SCI ClearanceExperience supporting DHS, CISA, NSA, FBI, DoD, or Intelligence Community programsExperience implementing Generative AI solutionsExperience developing autonomous AI agentsExperience building RAG architecturesExperience with LangChain, LangGraph, CrewAI, AutoGen, Semantic Kernel, or similar AI orchestration frameworksExperience with vector databases (Pinecone, FAISS, ChromaDB, OpenSearch Vector Engine)Experience supporting malware analysis, digital forensics, or threat intelligenceExperience implementing MLOps pipelinesExperience deploying AI into production cloud environmentsDesired Technical SkillsArtificial IntelligenceLarge Language Models (LLMs)Generative AIRetrieval-Augmented Generation (RAG)Prompt EngineeringAI AgentsAgentic AIModel Fine-TuningReinforcement LearningNatural Language Processing (NLP)Embedding ModelsMachine LearningTensorFlowPyTorchScikit-learnXGBoostML PipelinesFeature EngineeringModel EvaluationModel DeploymentCloudAWSAmazon BedrockSageMakerLambdaECSEKSS3IAMCloudWatchDatabricksData EngineeringSparkKafkaKinesisAirflowPrefectSQLNoSQLData LakesETL/ELTVector DatabasesSoftware EngineeringPythonFastAPIREST APIsDockerKubernetesGitGitHub ActionsJenkinsTerraformCybersecurityMalware AnalysisThreat IntelligenceIncident ResponseDigital ForensicsMITRE ATT&CKDetection EngineeringSIEM IntegrationSecurity AutomationDesired CertificationsOne or more of the following certifications are highly desirable:AWS Certified Machine Learning – SpecialtyAWS Certified AI PractitionerAWS Solutions Architect – ProfessionalDatabricks Certified Machine Learning ProfessionalMicrosoft Azure AI Engineer AssociateGoogle Professional Machine Learning EngineerCSSLPDoD 8140 IAT Level IIICISSP (Preferred)GIAC Certified Forensic Analyst (GCFA) (Preferred)What Success Looks LikeWithin your first year you will:Deploy secure AI capabilities supporting DHS cyber operations. AI/ML Automation Engineer Location: Government Facility (Hybrid/Onsite)Security Clearance: Active Secret Clearance Required (TS/SCI Preferred)Customer: U.S. Department of Homeland Security (DHS)Employment Type: Full-TimeAbout Argo CyberArgo Cyber Systems is a Service-Disabled Veteran-Owned Small Business (SDVOSB) delivering advanced cybersecurity engineering, artificial intelligence, cloud security, digital forensics, threat intelligence, and cyber modernization services to Federal agencies and critical infrastructure organizations.
NewCyber Systems Engineering, Advisor PeratonCyber Systems Engineering, AdvisorUndisclosed, Maryland$146,000–$234,000 / yearFull timeAdditionally, the Digital Forensic Analyst will: Perform network traffic analysis of organizational systems to analyze raw packet data and identify anomalous behavior; Conduct computer forensics and security vulnerability analysis using commercial-off-the-shelf (COTS) and/or customer-provided tools; Evaluate cloud services, web applications, and COTS software and hardware; Identify gaps in cybersecurity systems and processes to reduce organizational risks; Offer innovative cyber defense solutions to protect systems; Participate in the penetration test lifecycle to understand threats and recommend solutions; Understand and recommend industry best practices for the configuration of networks and Linux and Windows machines; Leverage analytical tools (e.g., Splunk, Wireshark, etc.) to assist in analysis. The successful applicant must understand network protocols to identify attack points that could be exploited by an adversary and work with the team to implement changes to mitigate potential weaknesses/vulnerabilities.
Cyber Systems Engineering, Advisor Peraton IncCyber Systems Engineering, AdvisorChantilly, VA$146,000–$234,000 / yearAdditionally, the Digital Forensic Analyst will: Perform network traffic analysis of organizational systems to analyze raw packet data and identify anomalous behavior; Conduct computer forensics and security vulnerability analysis using commercial-off-the-shelf (COTS) and/or customer-provided tools; Evaluate cloud services, web applications, and COTS software and hardware; Identify gaps in cybersecurity systems and processes to reduce organizational risks; Offer innovative cyber defense solutions to protect systems; Participate in the penetration test lifecycle to understand threats and recommend solutions; Understand and recommend industry best practices for the configuration of networks and Linux and Windows machines; Leverage analytical tools (e.g., Splunk, Wireshark, etc.) to assist in analysis. The successful applicant must understand network protocols to identify attack points that could be exploited by an adversary and work with the team to implement changes to mitigate potential weaknesses/vulnerabilities.
Digital Forensics Lead (#26-091) Strategic Analysis, Inc.Digital Forensics Lead (#26-091)Washington, DCStrategic Analysis, Inc (SA) is seeking a knowledgeableDigital Forensics Leadto support the Advanced Research Projects Agency for Health (ARPA-H) Office of Information Technology and Data Innovation (ITDI). ClearanceHHS, NIH Public Trust (Ability to obtain)Position is Hybrid with anticipated some days remote and some days at client site in Washington D.C. Some ad-hoc travel is also anticipated.
Cyber Incident Manager Level II Argo Cyber SystemsCyber Incident Manager Level IIArlington, VAFull timeCyber Incident Manager IILocation: Arlington, VA (On-Site)Citizenship: US onlyClearance: Active TS/SCI (DHS EOD Suitability required)Company: Argo Cyber Systems, LLC - Service-Disabled Veteran-Owned Small Business (SDVOSB)About Argo Cyber SystemsArgo Cyber Systems provides mission-critical cybersecurity support to U.S. Government agencies and critical infrastructure owners nationwide. Our teams deliver rapid incident response, advanced forensics, and coordinated recovery operations to protect vital systems from evolving cyber threats.
Digital Forensics Lead (CBP) Agile DefenseDigital Forensics Lead (CBP)Reston, Virginia$155,000–$175,000 / yearA minimum of five (5) years of hands-on experience with experience in the last two (2) years that includes bare metal, cloud or virtual system-based and network-based security monitoring, identifying and analyzing anomalous activities with familiarity in insider threat monitoring software, endpoint forensic tools, intrusion detection systems, intrusion analysis functions, security information event management (SIEM) platforms, endpoint detection and response tools, security operations ticket management. You will preserve and analyze evidence from compromised or suspect systems, reconstruct what happened, and produce findings the incident response, threat hunt, and insider threat monitoring leads can act on and that can support disciplinary, legal, or law enforcement action when it comes to that.
Forensics - Crisis and Investigations - Cyber Response - Manager Ernst & Young Global LtdForensics - Crisis and Investigations - Cyber Response - ManagerMcLean, VA$104,800–$192,300 / yearIf you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at ssc.customersupport@ey.com. This role focuses on the post-incident response phase, helping clients assess impacted data, evaluate legal and regulatory obligations, coordinate remediation activities, and manage stakeholder communications.
Forensics - Crisis and Investigations - Cyber Response - Senior Ernst & Young Global LtdForensics - Crisis and Investigations - Cyber Response - SeniorMcLean, VA$84,700–$139,800 / yearIf you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at ssc.customersupport@ey.com. This role focuses on the post-incident response phase, helping clients assess impacted data, evaluate legal and regulatory obligations, coordinate remediation activities, and manage stakeholder communications.
Lead Incident Responder Evolver FederalLead Incident ResponderWashington, DCFull timeResponsibilities include coordinating with SOC teams, ISSOs, and AOs, integrating threat intelligence and forensic analysis into response processes, and driving continuous improvement to strengthen organizational resilience against evolving cyber threats. The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST 800-series, RMF, TIC 3.0), lead investigations into complex threats, and deliver compliance reporting to federal stakeholders.
Incident Response Team Lead Agile DefenseIncident Response Team LeadReston, VirginiaRequisition #: 1435 Job Title: Incident Response Team Lead Location: Reston, VA Clearance Level: TS (SCI Eligible) Active Certified Information System Security Professional (CISSP) SUMMARY Agile Defense is seeking experienced Cyber Incident Response Team Lead to support an enterprise cybersecurity program that delivers 24/7/365 Cybersecurity Operations Center (SOC) services. QUALIFICATIONS Required Certifications Certified Information System Security Professional (CISSP) and One or more of the following certifications: GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH); GIAC Certified Forensic Analyst (GCFA); SANS GIAC Certified Enterprise Defender (GCED) or Other Information Assurance Technician (IAT) Level III certification in accordance with DoD Directive 8570.1.
Incident Response Team Lead (CBP) Agile DefenseIncident Response Team Lead (CBP)Reston, Virginia$155,000–$180,000 / yearQUALIFICATIONS Minimum required experience Five (5) years of progressive professional experience in incident response role, SOC analyst role with emphasis in cyber security issues, incidents, hunts or digital forensics and operations, and computer incident response lifecycle. The IR team conducts security investigations for potential threat activity identified within the organization, conducts deep-dive forensic investigations (host-based, cloud and network), identify and implement countermeasures, as well as track and report on incident activity to USG customers.
Biometrics Watchlist Lead Science Applications International CorpBiometrics Watchlist LeadBethesda, MD$200,001–$240,000 / yearSAIC is seeking a Biometrics Watchlist Lead to serve as the senior technical and operational authority for all biometric watchlisting, identity intelligence processing, and attribution analysis activities performed under an Intelligence Community program. Coordinating with Digital Forensics, Multimedia Intelligence, Reverse Engineering, and Data Science functional areas to identify fusion opportunities and integrate biometric findings into broader multi-disciplinary intelligence products.
Principal, Digital Forensics Control RisksPrincipal, Digital ForensicsWashington, DCThe Principal will support a range of forensic investigations and eDiscovery matters across many different industries, providing assistance with data collections, chain-of-custody documentation, proper evidence handling, forensic analysis, expert reporting, declaration/affidavits, and expert witness testimony. Assist the business development team throughout the sales process by building relationships with current and potential future clients, demonstrating firm technology and expertise to potential clients, and providing supporting documentation, including proposals and cost estimates, regarding our offerings.
Senior Incident Response Consultant PonduranceSenior Incident Response ConsultantMcLean, VA$110,000–$136,000 / yearOne or more of the following technical certifications preferred: GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), MCFE, EnCE, or equivalent certifications. About the role: The Incident Response team is focused on supporting the IR lifecycle and providing indicators to the SOC that will assist in enhanced detection capabilities of network, log, and host data.
NewCybersecurity Incident Manager (Day Shift) Triangle Cyber, LLCCybersecurity Incident Manager (Day Shift)Arlington, VAMust have knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code). Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code).