C

cFocus Software

Federal cybersecurity, cross-domain, geospatial IT services

Forensic and Malware Lead

Full-TimeUpdated on 9/30/2026
No salary listed
Senior
Bachelor's
Washington, DC, USA
In Person

About the job

Requirements
  • Ability to obtain a Public Trust clearance.
  • Bachelor of Science in Computer Science, Information Technology, or a related field.
  • Five years of incident response experience in a large security operations center with over 5,000 endpoints, including at least three years focused on digital forensics for operating systems or file systems.
  • Three years of demonstrated expertise in disk, memory, and registry analysis using industry-standard tools such as EnCase, FTK, X-Ways, and Volatility.
  • Demonstrated understanding of file systems and operating system artifacts, including SRUM, Shellbags, and Prefetch.
  • Familiarity with federal evidence guidelines and chain-of-custody requirements.
  • Active GCFA, GREM, CFCE, or OSED certification.
Responsibilities
  • Lead digital forensics and malware analysis activities in support of AOUSC Security Operations Division operations.
  • Provide advanced subject matter expertise for forensic investigations involving Windows, Linux, macOS, cloud, and enterprise environments.
  • Perform static and dynamic malware analysis to identify indicators of compromise, attacker tactics, techniques and procedures, and root cause.
  • Analyze forensic artifacts, memory images, endpoint telemetry, SIEM data, and file system timelines to identify malicious activity and intrusion vectors.
  • Coordinate with Cybersecurity Triage and Incident Response teams to support investigation, escalation, containment, remediation, and recovery activities.
  • Conduct live forensic analysis using Splunk Enterprise Security, Microsoft Sentinel, EDR tools, and AO-provided investigative tooling.
  • Collect, preserve, duplicate, and maintain digital evidence in accordance with forensic evidence-handling and chain-of-custody procedures.
  • Develop forensic reports, malware analysis reports, incident artifacts, and technical documentation in accordance with Judiciary SOC Forensics SOPs and JSOCIRP requirements.
  • Provide real-time investigative support for Priority 1 and Priority 2 cybersecurity incidents.
  • Support analysis of advanced persistent threats, ransomware, phishing campaigns, malicious scripts, and suspicious binaries.
  • Perform memory analysis using approved forensic tools such as Volatility and other Judiciary-approved forensic platforms.
  • Extract deleted or hidden data using forensic data carving and recovery techniques.
  • Analyze endpoint, network, identity, and cloud telemetry to support incident investigations and threat-hunting operations.
  • Coordinate escalation and communication of investigative findings to AO leadership, incident responders, SOC management, and federal staff.
  • Review and validate forensic and malware analysis deliverables for technical accuracy, completeness, and compliance with SLA requirements.
  • Develop and maintain forensic analysis procedures, malware analysis SOPs, investigative work instructions, and operational playbooks.
  • Support enterprise security awareness reporting by contributing forensic findings, threat trends, and investigative recommendations.
  • Participate in weekly technical meetings, operational briefings, and cybersecurity reporting activities.
  • Support continuous process improvement initiatives related to digital forensics, malware analysis, investigative workflows, and incident response operations.
  • Assist in transition-in and transition-out activities, including knowledge transfer, operational readiness, training, and documentation support.

About the company

cFocus Software provides cybersecurity, cross-domain, geospatial, and IT services to federal government agencies. It helps agencies design, implement, and manage security architectures, cross-domain data workflows, and geospatial solutions through consulting, implementation, and ongoing support. It differentiates itself with 18+ years of federal-focused experience and deep domain knowledge in government cybersecurity and geospatial work. Its goal is to help federal agencies protect operations, comply with regulations, and optimize IT and geospatial capabilities for secure, efficient government services.

Company Size

11-50

Company Stage

N/A

Total Funding

N/A

Headquarters

Largo, Florida

Founded

2006

Get referred to cFocus Software

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • DHS won its geospatial protest on July 29, 2026, validating cFocus's award.
  • GAO denied the NIH emergency call center protest, confirming competitive strength.
  • CMMC Level 2 and renewed ISO certifications on July 11 and July 16, 2025 strengthen bids.

What critics are saying

  • HUD OCIO POG 4 task order expires September 29, 2026, risking $3.7 million.
  • DFC cyber BPA ends September 23, 2026, shrinking recurring revenue visibility.
  • Dependence on federal recompetes invites displacement by larger integrators and cloud specialists.

What makes cFocus Software unique

  • Microsoft Gold Certified Partner with FedRAMP automation and Azure Government focus.
  • Exclusive ATO as a Service branding distinguishes cFocus in federal cloud compliance.
  • Small-business SDB status helps win set-aside federal IT work.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options