Senior Associate/Digital Forensics (Forensic Services practice)
Charles River Associates · Oakland, CA · 1 mo ago
OTHR$130k–$153k/yrFull-time
Responsibilities
- Performing onsite data collection and/or triage of MacOS, iOS, Android, Windows, and Linux devices;
- Executing chain of custody documentation and performing other data intake procedures;
- Performing forensic analysis MacOS related artifacts such as plists, unified logs, FS Events, spotlight metadata, etc.
- Conducting misappropriation of trade secret investigations across operating systems, but particularly with regards to MacOS system, by investigating the retention or exfiltration of data through iCloud (and other cloud-based storage), AirDrop, USB devices, or other means.
- Remediating data by securely removing it from multiple file systems and data platforms;
- Conducting mobile device extractions (including full file system extractions) and associated forensic examinations to identify user actions including the deletion of text messages;
- Using open-source and commercial tools to examine APFS, HFS+, FAT, and other file systems;
- Serving as primary point of contact for clients on data collection activities;
- Supervising project team execution by leading quality assurance efforts and overseeing work product;
- Improving the ability of the team to conduct investigations by writing code, evaluating commercial software, and implementing new processes;
- Creating, leading, and maintaining leveraged team environment that is positioned for continued success and expansion by actively recruiting and retaining employees, and managing team morale;
- Participating in and leading business development efforts by building relationships with current and potential clients, drafting and presenting proposals, participating in pitches, and demonstrating firm capabilities to potential clients;
- Aid with team recruiting and training efforts as needed.
Qualifications
- 5-7+ years of experience in digital forensics, cyber intrusion investigation, or incident response analysis;
- Bachelor’s or Master’s degree in a related field;
- Training, certifications, or working experience investigating MacOS forensic artifacts such as plists, unified logs, FS Events, spotlight metadata, etc.
- Deep knowledge of Mac OS, Windows, and Linux operating systems, and APFS, HFS+, FAT, and NTFS file systems;
- Working knowledge of open-source and commercial forensic software products, particularly those focused on MacOS and iOS analysis;
- Ability to effectively lead teams, prioritize multiple projects and meet timely deadlines;
- Experience leading data analytics engagements and managing the execution of technology-based best practices;
- Working knowledge of computer hardware components, operating systems, file systems, computer networks, e-mail systems, mobile devices, IT security or incident response;
- Deep knowledge of networking (TCP/IP, design, traffic flow, protocols, sessions), operating systems (Windows / *nix) and web technologies;
- Willing and able to travel for client projects.