Digital Forensics Incident Response Lead
sprymethods · Linthicum, MD ·
- Work mode
- Onsite
- Seniority
- Lead
- Employment
- Full time
- Category
- Security
- Salary
- USD 200,000 – 225,000 / year
Lead all digital forensics and incident response (DFIR) activities at a government digital forensics laboratory: manage intrusion analysis and incident response staff, direct network intrusion, malware, and memory forensics investigations, analyze APT activity, and brief findings to government leadership. Requires TS/SCI eligibility, a forensics certification, and 7+ years of DFIR experience.
What Your Day-To-Day Looks Like (Position Responsibilities):
-
Lead CFL Digital Forensics and Incident Response activities.
-
Manage intrusion analysis and incident response personnel.
-
Direct network intrusion analysis, malware forensics, and memory analysis.
-
Lead intrusion investigations and monitor investigative quality and efficiency.
-
Analyze advanced persistent threat activity.
-
Correlate findings from host forensics, network logs, and threat intelligence.
-
Brief technical findings to Government leadership.
-
Ensure all intrusion and incident response activities comply with the PWS.
-
Serve as the primary Government technical point of contact for intrusion analysis and incident response.
-
Proactively identify and communicate technical, programmatic, and resource limitations.
What You Need to Succeed (Minimum Requirements):
-
TS/SCI clearance eligible.
-
Active DFE, GCFA, GIAC Certified Incident Handler (GCIH), or equivalent certification approved by the COR.
-
At least seven years of hands-on Digital Forensics and Incident Response experience, including at least five years focused on network intrusion analysis, malware forensics, and memory analysis.
-
At least three years of leadership or supervisory experience within the last five years leading intrusion investigations, managing incident responders, and briefing technical findings to leadership.
-
Demonstrated experience within the last three years analyzing advanced persistent threat activity and correlating findings across host forensics, network logs, and threat intelligence.