Criminalist State of OklahomaCriminalistCherokee, OKThe functions performed in this job family will vary by level, unit and organization, but may include the following: Strictly adheres to validated and internationally accepted scientific principles, methods, and quality assurance/quality control; follows safety and health procedures; examines and analyzes various types of forensic evidence from criminal cases and/or convicted offender DNA samples and accurately interprets the results; generates complete, accurate documentation and files of all forensic analysis performed; prepares laboratory examination reports for use by law enforcement entities and criminal justice members; enters/searches evidence profiles/patterns in forensic databases such as CODIS, AFIS, PDQ, and NIBIN. Actively reviews and assesses publications and directives being introduced at the federal level to determine impacts on state and local laboratories and practices; seeks membership on federal boards and organizations to influence direction of forensics; researches scientific/technical literature and forensic methods; attends training to maintain current knowledge and skills; develops/validates new or improved techniques/instrumentation for use in the forensic analysis of physical evidence; writes, reviews, and updates technical protocols, quality assurance policy/procedures, safety and health policies, and operational policies/procedures.
Senior Intelligence Analyst, Iran Focus ChainalysisSenior Intelligence Analyst, Iran FocusOwn Iran attribution end to end — the threat-actor entities, their definitions, and the accounts, addresses, and infrastructure they operate: Iranian exchanges and OTC/no-KYC networks, IRGC and IRGC-QF financing, Iranian proxy and Shia militant finance (e.g., Hezbollah, the Houthis, and Iraqi militias), sanctions-evasion infrastructure, Iranian ransomware and state-linked cyber operations, and oil-, commodity-, and procurement-for-crypto flows. Through the IRGC and its Qods Force, a network of proxies and Shia militant groups, state-linked cyber actors, and a sprawling sanctions-evasion apparatus, the Islamic Republic has turned to cryptocurrency to raise, move, and launder value beyond the reach of the traditional financial system — from exchange-based sanctions evasion and crypto mining powered by subsidized energy, to oil- and commodity-for-crypto schemes, dual-use procurement, and the financing of proxies across the region.
Senior Intelligence Analyst, DPRK & China Focus ChainalysisSenior Intelligence Analyst, DPRK & China FocusOwn DPRK & China attribution end to end — the threat-actor entities, their definitions, and the accounts, addresses, and infrastructure they operate: Lazarus Group and DPRK state-sponsored theft and laundering, DPRK IT-worker networks, Chinese-language OTC and underground-banking networks, guarantee marketplaces (e.g., Huione-style platforms), scam-compound and pig-butchering laundering infrastructure, fentanyl and precursor vendors, and Chinese money-laundering organizations. Lead the attribution response to DPRK- and China-related sanctions events — when OFAC or allied authorities designate DPRK actors, exchange-hacking units, or Chinese laundering networks, drive the rapid, high-visibility on-chain attribution that turns those designations into coverage in our data, often against the clock.
Director, DFIR (Remote) Surefire CyberDirector, DFIR (Remote)RemoteWork closely with the Chief Delivery Officer, the broader Engagement Lead team, and the Forensic Consulting team to lead and oversee active client-facing incident response engagements, to guide clients through the entire incident response lifecycle from detection to recovery. Former professional experience in leading and managing active cybersecurity engagements, including incident response, digital forensics investigations, and interaction with clients, legal counsel, and cyber insurers.
Cyber Threat Hunter FiservCyber Threat HunterAlpharetta, New JerseyRelevant certifications such as GIAC Reverse Engineering Malware (GREM), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), GIAC Reverse Engineering Malware (GREM), CompTIA CySA+, Certified Information Systems Security Professional (CISSP), Certified Threat Hunting Professional (CTHP), Certified Threat Intelligence Analyst (CTIA), Certified Cloud Security Professional (CCSP), or equivalent cybersecurity certification. 8+ years of experience in detection engineering, proactive threat hunting, digital forensics and incident response, malware analysis, reverse engineering, threat research, red teaming, purple teaming, advanced security operations, or a combination of these domains.
Senior Security Engineer – Cyber Hunting & Incident Response – 3rd Shift Truist BankSenior Security Engineer – Cyber Hunting & Incident Response – 3rd ShiftZebulon, North CarolinaGeneral Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Experience in Cyber Incident Response, Threat Hunting, Security Operations Centers (SOC), Network Operations Centers (NOC), Cybersecurity Engineering, or Intelligence Community environments.
Physician (Radiology-Diagnostic) GP-0602-14 Defense Health Agency Civilian Corps, Falls Church, VAPhysician (Radiology-Diagnostic) GP-0602-14Dover, DelawareLeading-Edge DNA Science: It hosts the Armed Forces DNA Identification Laboratory (AFDIL) , which is responsible for the massive, ongoing national mission of identifying the remains of fallen service members from past conflicts (dating back to WWII, the Korean War, and Vietnam) as well as current operations. Dignified Returns: The medical staff, in coordination with Air Force Mortuary Affairs Operations (AFMAO) and the Joint Personal Effects Depot (JPED), ensure the dignified transfer, forensic identification, and honorable return of every fallen American service member who dies overseas.
Consultant Palo Alto NetworksConsultantArlington, VirginiaYour Experience 2+ years of incident response or digital forensics experience with a passion for cybersecurity Proficient with host-based forensics and data breach response Experienced with EnCase, FTK, X-Ways, SIFT, Splunk, Volatility, WireShark, TCPDump, and open-source forensic tools Ability to grow into a valuable contributor to practice and, specifically have an external presence via public speaking, conferences, and/or publications have credibility, executive presence, and gravitas be able to have a meaningful and rapid delivery contribution have the potential and capacity to understand all aspects of the business and an excellent understanding of PANW products be collaborative and build relationships internally, externally, and across all PANW functions, including the sales team Incident Response Consulting is highly preferred Bachelor’s Degree in Information Security, Digital Forensics, Cyber Security, Computer Science, related field, or equivalent experience required Compensation Disclosure . For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below.
Threat Hunter UnitedHealth Group Inc.Threat HunterRaleigh, NC$91,700–$163,700 / year3 years of experience with application protocols (HTTP, DNS, FTP, etc.) and networking protocols (TCP, UDP, ARP, ICMP, etc.), and be comfortable analyzing packet capture (pcap) files in tools such as Wireshark. Primary Responsibilities: Analysis of network data (packets, logs) and endpoint data (logs, malicious artifacts) in both structured and unstructured methods.
Contract Bench, Incident Responder (DFIR) MoxfiveContract Bench, Incident Responder (DFIR)Finding actual evil and seeing the latest threat activity is more exciting than your day job, and you’d love to get your fix on some live response data without committing all your waking hours. Account takeovers are the new malware after all, and investigating the latest threats across Azure, GCP, AWS, and SaaS Apps is the growing frontier you’ve been looking to sink your teeth into.
2027 Intern - Technology FTI Consulting2027 Intern - TechnologyWashington, District of ColumbiaOur advanced analytics researcher interns work closely with corporate clients and law firms to play a critical role within our Find Facts Fast (FFF) service, conducting investigative fact-finding with advanced analytics to mine large datasets and perform substantive research and analysis to quickly identify case-critical documents and prepare comprehensive summaries and documentation of the material facts, key issues and themes for strategic decision-making. Our technology interns work with corporations, governments and law firms to meet critical legal and regulatory needs, including investigations, e-discovery, information governance, digital forensics, data privacy, document review consulting as well as project management.
2027 Entry Level Consultant - Technology FTI Consulting2027 Entry Level Consultant - TechnologyWashington, District of ColumbiaOur advanced analytics researchers work closely with corporate clients and law firms to play a critical role within our Find Facts Fast (FFF) service, conducting investigative fact-finding with advanced analytics to mine large datasets and perform substantive research and analysis to quickly identify case-critical documents and prepare comprehensive summaries and documentation of the material facts, key issues and themes for strategic decision-making. Our technology consultants work with corporations, governments and law firms to meet critical legal and regulatory needs, including investigations, e-discovery, information governance, digital forensics, data privacy, document review consulting as well as project management.
Aver Careers - Data Scientist AVER LLCAver Careers - Data ScientistWashington, DCAVER is seeking a Data Scientist with strong experience in advanced analytics, automation, and Artificial Intelligence/Machine Learning (AI/ML) to develop innovative solutions that enhance data-driven insights, pattern discovery, and operational efficiency. The Data Scientist will collaborate with technical teams, data engineers, leadership, and other stakeholders to modernize data handling, automate analytical processes, improve data quality, and develop scalable analytical solutions.
Senior Policy Analyst Spry MethodsSenior Policy AnalystLinthicum, MDDemonstrated experience developing, analyzing, and managing policy within federal or DoD environments, particularly within cybersecurity, digital forensics, cyber operations, or related mission domains. Spry Methods is a proven provider of mission-focused technology, cybersecurity, and program management solutions supporting critical Federal and DoD missions.
Senior Software Developer – HYBRID! AnaVationSenior Software Developer – HYBRID!Chantilly, VAYou’ll apply systematic and disciplined software‑engineering practices to create reliable, audit‑compliant systems that support case management, investigative analytics, digital‑evidence processing, and other core operational workflows. You’ll work closely with investigators, analysts, and cyber specialists to translate mission needs into robust software solutions, while supporting modern cloud deployments and DevSecOps pipelines aligned with government requirements.
Certified Industrial Hygienist EFI GlobalCertified Industrial HygienistLos Angeles, CaliforniaRemote$130,000–$150,000 / yearOver the last four decades, we have grown from a boutique firm specializing in handling insurance fraud and arson cases and providing expert witness testimony, into a recognized global leader in engineering failure analysis, origin-and-cause investigations, environmental consulting, laboratory testing and specialty consulting. Mental: Clear and conceptual thinking ability; excellent judgment, troubleshooting, problem solving, analysis, and discretion; ability to handle work-related stress; ability to handle multiple priorities simultaneously; and ability to meet deadlines.
Consultant, DFIR, Reactive Services (Unit 42) Palo Alto NetworksConsultant, DFIR, Reactive Services (Unit 42)IllinoisIn this role, you will work alongside Senior Consultants, Principal Consultants, and Consulting Directors to investigate cybersecurity incidents, perform forensic analysis, and help organizations respond to and recover from security events. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below.
Senior Security Engineer - Cyber Hunting & Incident Response - 3Rd Shift Truist Financial CorporationSenior Security Engineer - Cyber Hunting & Incident Response - 3Rd ShiftZebulon, NCGeneral Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Experience in Cyber Incident Response, Threat Hunting, Security Operations Centers (SOC), Network Operations Centers (NOC), Cybersecurity Engineering, or Intelligence Community environments.
Cyber Incident Response Analyst II AmTrust Financial Services, Inc.Cyber Incident Response Analyst IICleveland, OhioFull timeThis role partners with third-party service providers, vendors, infrastructure teams, and security engineering and architecture teams to strengthen the organization's security posture and improve incident response capabilities. Perform digital forensics, log analysis, artifact collection and preservation, and host and network investigations using enterprise security monitoring and endpoint detection tools.
Technical Manager (Cloud, DevSecOps & Enterprise Architecture PeratonTechnical Manager (Cloud, DevSecOps & Enterprise ArchitectureLinthicum, Maryland$146,000–$234,000 / yearFull timeSecurity & compliance: Familiarity with federal enterprise frameworks (e.g., DoDAF) and security compliance frameworks (RMF, NIST SP 800-53, Zero Trust) within a cybersecurity or digital forensics context. Silo Reduction: Identify overlapping technical requirements across different cyber and forensic projects to design shared enterprise-level network and cloud services, reducing duplicate work and manual labor.