Full-Time

Cyber Defense Forensics Analyst

Confirmed live in the last 24 hours

Leidos

Leidos

10,001+ employees

Provides technology solutions for defense and healthcare

Compensation Overview

$85.2k - $153.9k/yr

Mid, Senior

No H1B Sponsorship

Ashburn, VA, USA

US Citizenship Required

Category
Cybersecurity
IT & Security
Required Skills
Linux/Unix
Requirements
  • Requires BS degree and 4-8 or more years of direct relevant experience.
  • Degree in computer science, IT, Information/Cyber Security field from an accredited college or university.
  • Effective communication skills with emphasis on attention to detail, ability to accurately capture and document technical remediation details, and ability to brief stakeholders on incident statuses, recovery and root causes.
  • Demonstrable experience performing forensic analysis, digital media analysis, and in-depth system & network log analysis in support of forensic investigations.
  • Ability to generate forensically sound cyber analysis reports detailing forensically sound analysis procedures, findings, and recommendations from incident investigations.
  • Strong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.
  • Ability to independently prioritize and complete multiple tasks with little to no supervision.
  • Must be a US Citizen.
Responsibilities
  • Provide support to CBP OIT’s Cyber Defense Forensics (CDF) team in support of insider threat and security operations according to established policies, handbooks, and CBP CDF Standard Operating Procedures (SOPs).
  • Monitor activities, conduct threat analysis, investigate policy violations, identify mitigation and/or remediation courses of action, and assess risk posed by trusted insiders.
  • Work with the OIT Data Loss Prevention (DLP) tools to process incidents, investigate spillages of multiple types of classified and/or controlled data, conduct root cause analyses into suspicious or malicious activity, and assist with SOC Incidents / OPR investigations as needed.
  • Provide recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.
  • Conduct enterprise and system(s) endpoint analysis (e.g., Windows, Linux, Mac, Cloud, and mobile systems) and network based digital forensic analysis.
  • Conduct formal digital forensic investigations and document findings in formal, forensically sound investigation reports.
  • Perform Email hygiene activities in support of CBP investigations.
  • Support enterprise recovery efforts as necessary to ensure that security events and incidents are properly remediated prior to restitution.
  • Utilize state of the art forensic tools (FTK/Encase, etc) to perform computer, mobile phone forensics and memory analysis (volatility, rekall) in support of incident response.
  • Conduct reverse engineering of suspicious files utilizing dynamic, automated and static analysis.
  • Properly preserve evidence, maintain chain of custody and write malware analysis or forensic reports.
  • Recognize attacker and APT activity, tactics, and procedures as indicators of compromise (IOCs) that can be used to improve monitoring, analysis, and incident response.
  • Install, secure, maintain and recommend forensic software and hardware within a Forensic Lab environment while following established configuration management processes.
  • Develop and build security content, scripts, tools, or methods to enhance forensic processes.
  • Effectively investigate and identify root cause findings then communicate findings to stakeholders including technical staff, and leadership.
  • Develop and maintain Standard Operating Procedures (SOPs) and playbooks as deemed necessary.
Desired Qualifications
  • Experience performing computer forensics in Federal Government, DOD or Law Enforcement environments.
  • Ability to script in one more of the following computer languages Python, Bash, Visual Basic or PowerShell.
  • Knowledge of the Cyber Kill Chain and MITRE ATT&CK framework.
  • Advanced understanding of multiple Operating Systems, monitoring and detection techniques and methods, and Incident Response Lifecycle.
  • Prior experience with CBP/DHS.
  • Between 2-3 years of experience in two or more of these specialized areas: Insider Threat, Digital media forensic, Monitoring and detection.
  • Incident Response Required certifications: The candidate should have at minimum ONE of the following certifications: CompTIA Cyber Security Analyst (CySA+), CompTIA Linux Network Professional (CLNP), CompTIA Pentest+.

Leidos operates in the technology, science, and engineering sectors, focusing on enhancing safety, health, and efficiency. The company provides specialized solutions in defense, aviation, information technology, and biomedical research, catering to government agencies, private companies, and healthcare organizations. Leidos offers services such as cybersecurity, data analytics, systems integration, and software development, which are tailored to meet the unique needs of its clients. This approach helps clients tackle complex challenges and improve their operational efficiency. Revenue is generated through long-term contracts and service agreements, ensuring a stable income stream. Leidos is recognized for its commitment to sustainability, corporate responsibility, and workplace diversity, making it a respected employer and a leader in promoting inclusion. The company's goal is to deliver advanced solutions while positively impacting communities and the environment.

Company Size

10,001+

Company Stage

IPO

Headquarters

Reston, Virginia

Founded

1969

Simplify Jobs

Simplify's Take

What believers are saying

  • Growing demand for UUVs boosts Leidos' market in military and commercial sectors.
  • Strategic leadership appointments indicate potential for growth in European markets.
  • Strong investor confidence is reflected in significant financial investments in Leidos.

What critics are saying

  • Increased competition in UUV market may impact Leidos' market share.
  • Recent layoffs could signal financial or operational challenges affecting morale.
  • Federal budget cuts may reduce government contracts, impacting Leidos' revenue.

What makes Leidos unique

  • Leidos excels in cybersecurity, data analytics, and systems integration solutions.
  • The company is recognized for its commitment to sustainability and corporate responsibility.
  • Leidos' long-term contracts ensure a steady revenue stream.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical, dental, & vision insurance

Health Savings account

Income protection

PTO

Paid parental leave

Jury duty pay

Bereavement leave

401(k) Retirement Plan

Employee Stock Purchase Plan

Family Benefits

Company News

Annandale Today
Apr 10th, 2025
Federal job cuts will devastate the Fairfax County economy

Leidos laid off 29 employees at its Springfield location.

ExecutiveBiz
Apr 8th, 2025
Leidos Launches Sea Dart UUV for Navy and Commercial Use

Leidos launches Sea Dart UUV for navy and commercial use.

ASD News
Apr 7th, 2025
Leidos Unveils Newest Unmanned Undersea Vessel

Leidos unveils newest unmanned undersea vessel.

Quantis
Mar 31st, 2025
Leidos hires Daryle Lademan to lead corporate strategy activities

Leidos hires Daryle Lademan to lead corporate strategy activities.

Valley Times-News
Mar 26th, 2025
Leidos appoints Adam Clarke chief executive for Leidos UK & Europe

Leidos appoints Adam Clarke chief executive for Leidos UK & Europe.