Senior Computer Forensics Analyst
About the Role
Provide senior-level expertise in digital forensics principles, including the acquisition, collection, preservation, and processing of data. Independently conduct forensic data acquisition and perform full forensic examinations/analyses of Windows and Mac-based desktop/laptop systems, servers (including Exchange and file shares), mobile devices, and related digital storage media. Experience with incident response (triaging, collection, and analysis) is required. Document and report findings, and provide expert witness testimony for investigations and litigations. Manage and mentor a team of examiners while utilizing industry-accepted forensic tools such as EnCase®, FTK, and X-Ways.
Responsibilities
- Manage multiple projects and maintain a computer forensics lab.
- Serve on forensic projects and participate in project meetings.
- Proactively assist in client management and train/mentor staff.
- Establish effective working relationships directly with clients.
- Generate high-quality forensic reports presenting complex technical processes and findings clearly and concisely to technical and non-technical clients while meeting expected timelines.
- Compose affidavits, depositions, and participate in court testimony as needed.
- Conduct or assist with forensic acquisition and preservation of electronic data from a wide range of IT environments and platforms, including social media and mobile devices.
- Perform on-site and remote imaging and data captures.
- Coordinate and track all electronic collection activities, maintain chain of custody, and ensure computer forensic protocols are met.
- Research and analyze new technologies and recommend leading-edge solutions for organizational use.
Requirements
- Competence in digital computer forensics, electronic discovery, and information security.
- Knowledge and experience with Windows, Macintosh, and Linux operating systems.
- Firm understanding of information systems security, network architecture, physical server and desktop architecture, virtual infrastructure architecture, general database concepts, and document management concepts.
- Firm understanding of electronic mail systems such as Exchange, GroupWise, Lotus Notes, and cloud-hosted services.
- Experience with forensic tools such as EnCase®, FTK, Oxygen, Cellebrite, and IEF.
- Ability to establish, maintain, and execute all components of an incident response plan, from incident intake through root cause analysis, technical remediation, and reporting.
- Detail-oriented with strong interpersonal skills for client and team interactions.
- Critical thinker and problem solver.
Qualifications
- Hold 2 or more industry-recognized digital forensic certifications (e.g., A+, CFCE, CCE, GCFA, GCFE, EnCE, ACE, CCME).
- Cyber/network-related certifications (one or more): Network+, Server+, GREM, GNFA, CISSP, CCNA, CCNP, or similar.
- Excellent written and oral communication skills.
- Ability to create exceptional, detail-oriented client deliverables.
- Experience with scripting and programming languages (e.g., C#, Java, Python, Perl, Bash, PHP) is a plus.
- Law enforcement or government background is a plus but not required.
- 7+ years of professional work experience in computer forensics investigations, post-incident response, and network forensics.
- Experience testifying in court, Grand Jury, or other legal proceedings through testimony, sworn affidavits, declarations, or other legal instruments.
Capsicum Group, LLC is a technology and consulting company dedicated to helping organizations achieve success with complex legal, regulatory, and technology projects. Founded in 2000, Capsicum focuses on digital forensics, data recovery, regulatory compliance, privacy, cybersecurity, and electronic discovery.