Cyber Forensics Analyst
ECS · Portland, OR · 1 mo ago
Information TechnologyFull-time
Key Responsibilities
- Perform forensic analysis using industry-standard forensic tools and open-source DFIR utilities.
- Aid in forensic investigations involving endpoints, servers, malware, and cyber incidents.
- Analyze Windows Registry, Windows System Calls, Linux artifacts, file system data, logs, and memory artifacts.
- Create findings and technical notes that support investigative conclusions and remediation actions.
- Analyze malware in a lab environment using standard malware analysis techniques.
- Create IOCs based on forensic and malware findings for sharing with SOC and security teams.
- Support Java code de-obfuscation and technical analysis activities within the analyst skill level.
- Assist the SOC with security investigations and incident response activities.
- Conduct routine memory checks on Linux and Windows servers as directed.
- Support proactive malware analysis, incident response, and advanced threat hunting activities.
- Communicate with different teams and data centers during investigations.
Required Skills
- U.S. Citizenship with ability to obtain and maintain a DOE “L” clearance after start.
- 5 to 8 years of experience in cybersecurity, digital forensics, incident response, or related cyber investigation work.
- Experience performing forensic analysis using industry-standard forensic tools and open-source tools.
- Familiarity with Windows Registry, Windows System Calls, Linux operating systems, and Java code de-obfuscation.
- Hands-on experience with Volatility or other memory forensics tools, FTK, and Wireshark.
- Experience creating IOCs based on forensic analysis and sharing them with other security teams.
- Experience analyzing malware in a lab environment using standard malware analysis techniques.
- Experience performing or supporting forensic investigations and incident response activities.
- Excellent written communication, resourcefulness, investigative ability, research skills, and problem-solving skills.
Desired Skills
- Experience with EnCase (OpenText), Autopsy, Axiom, Zimmerman tools, and other DFIR tools.
- Experience supporting a U.S. Government civilian agency, enterprise SOC, or regulated environment.
- Experience with OllyDbg, IdaPro, or comparable reverse-engineering tools.
- Knowledge of X86 Intel Assembly Language.
Tools and Technologies
- Forensic Toolkit (FTK)
- EnCase (OpenText)
- Autopsy
- Axiom
- DFIR tools
- Zimmerman tools
- Volatility or equivalent memory forensics tools
- Wireshark
- Linux
- OllyDbg
- IdaPro
Key Competencies
- Hands-on forensic analysis
- Malware triage and IOC creation
- Memory analysis
- Research and technical problem solving
- Clear reporting and cross-team communication