Full-Time

Digital Forensics & Incident Response Analyst - Mid-Level

Multiple Teams

Posted on 9/24/2025

True Zero Technologies

True Zero Technologies

11-50 employees

Splunk-based security and tech-management solutions

No salary listed

Huntsville, AL, USA

In Person

US Top Secret Clearance Required

Category
IT & Security (1)
Required Skills
Word/Pages/Docs
Splunk
Excel/Numbers/Sheets
PowerPoint/Keynote/Slides
Requirements
  • Bachelor's degree (or equivalent experience) in Cybersecurity, Information Technology, or a related field.
  • Minimum of 3 years of relevant experience in direct digital forensics or incident response within a federal agency context.
  • Active Top-Secret Clearance with SCI Eligibility.
  • Must be able to pass a background check and CI Polygraph. May require additional background checks as required by projects and/or clients at any time during employment.
  • Skilled in the use of Incident Response tools such as Splunk Enterprise Security, Microsoft Defender for Endpoint, for conducting sophisticated cyber incident monitoring and analysis.
  • Well-versed in employing forensic tools and suites such as Magnet Axiom, FTK, Cellebrite Physical Analyzer, Kape, Eric Zimmerman Tools to support investigative processes.
  • Adept at conducting open-source research to identify and understand active or potential threats.
  • Must possess problem-solving skills.
  • Exceptional communication skills, both oral and written.
  • Must be able to work effectively in a high-stress environment during critical incidents and be adaptable to a dynamic operational speed.
  • Ability to respond effectively to customers with a sense of urgency.
  • Proficient in Microsoft and Adobe toolsets, including Excel, Word, PowerPoint, Acrobat, etc.
  • Highly motivated with the ability to handle and manage multiple tasks at any one time.
  • Ability to forge new relationships with both individuals and teams.
  • Must be a self-starter, that can work independently and as part of a team.
Responsibilities
  • Provide real-time analysis and triage of security events to support the initial response efforts.
  • Analyze log files from endpoints, EDR systems, firewalls, and servers to identify, contain, and remediate suspicious activity.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Engage in Threat Hunting operations to proactively identify and mitigate threats.
  • Conduct predictive or reactive analyses on security measures to support cyber security initiatives.
  • Create system images or capture network settings from information technology environments to preserve as evidence.
  • Forensically duplicate digital evidence to use for data recovery and analysis procedures.
  • Perform web service network traffic analysis or waveform analysis to detect anomalies, such as unusual events or trends.
  • Contribute to the analysis of cyber threat intelligence and apply findings to bolster ESOC's defensive and responsive actions.
  • Post-incident analysis, assisting in identifying root causes, mining lessons learned, and reinforcing security measures.
  • Contribute to training and skill development opportunities for self and other team members.
  • Develop or refine policies and requirements for data collection, processing, and reporting.
  • Recommend cyber defense software or hardware to support responses to cyber incidents.
  • Adhere to legal policies and procedures related to handling digital media.
  • Stay current on emerging threats, attack techniques, and vulnerabilities.
  • Write and execute scripts to automate tasks, such as parsing large data files.
  • Write cyber defense recommendations, reports, or white papers using research or experience.
  • Write technical summaries to report findings.
Desired Qualifications
  • Relevant cybersecurity certifications such as GIAC.
  • Solid foundation in the principles and practices of digital forensics methodologies and incident handling.
  • Familiarity with cybersecurity frameworks, standards, and best practices.
  • Experience with malware analysis and reverse engineering.
  • Scripting, coding, and query language experience (Bash, PowerShell, KQL, SPL, Python, etc).
  • Experience conducting Incident Response in AWS Cloud environments.
True Zero Technologies

True Zero Technologies

View

True Zero Technologies provides security and technology management services by implementing Splunk-based data analytics for organizations in sectors like healthcare, finance, and government. These solutions work by collecting and analyzing large amounts of machine data to help clients monitor their IT systems and detect cybersecurity threats in real-time. As a veteran-owned business, the company differentiates itself by using a team of seasoned industry experts to deliver repeatable, standardized service models rather than one-off custom fixes. Their goal is to ensure long-term customer success through managed services while actively supporting the veteran community through educational scholarships.

Company Size

11-50

Company Stage

N/A

Total Funding

N/A

Headquarters

Fair Oaks, Virginia

Founded

2016

Simplify Jobs

Simplify's Take

What believers are saying

  • ServiceNow partnership unites AI-driven platforms for enhanced cybersecurity operations.
  • Wiz integration strengthens client cloud security postures via managed services.
  • September 26, 2025 federal award expands government cybersecurity contracts.

What critics are saying

  • Splunk's Q2 2026 agentless pivot obsoletes agent-heavy professional services.
  • Tanium commoditization by Splunk's Terminus acquisition erodes hybrid demand.
  • Booz Allen's January 2026 DoD contract captures public sector Tanium deals.

What makes True Zero Technologies unique

  • True Zero delivers Splunk-based solutions for mission-critical security across sectors.
  • Veteran-owned status secures federal MAS contract worth $571,354 through 2030.
  • Partners with ServiceNow, Wiz, and Tanium for AI-driven cybersecurity services.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Paid Vacation

Paid Holidays

401(k) Retirement Plan

401(k) Company Match

Phone/Internet Stipend

Parental Leave

INACTIVE