Meet our professionals CGI: An employer of choice Position Description: The CGI Federal Cyber Threat Analysis Center(CTAC) is seeking a senior-level Digital Forensic Analyst to support intrusion and insider threat investigations for internal and external customer incidents. The Digital Forensic Analyst will be responsible for using a wide variety of forensic tools and investigative methods to find: specific electronic data, locate malicious code, determine the infection vector, scope of the compromise, malware artifacts, possible data ex-filtration activity, documents, photos and e-mails from computer hard drives and other data storage devices, such as zip and flash drives that have been deleted, damaged or otherwise manipulated. Your future duties and responsibilities: * Conducting data forensic investigations for enterprise computer security incidents including but not limited to internal and external intellectual property theft, attacks/intrusions, computer abuse and insider threat investigations * Perform forensically sound imaging of multiple types of data sources * Demonstrated skill performing operational software/hardware testing on digital equipment and other electronic devices. * Ability to follow through on leads until all possible avenues in investigating a case have been exhausted. * Performing log, memory and RAW analysis. * Maintain full chain of custody and evidence tracking * Demonstrated skill in performing post-incident computer forensics in a forensically sound manner. * Organize all relevant case information in easy-to understand format * Prepare reports and document case details, development and outcome. * Provide expert analysis and interpretation of forensic artifacts, including expert opinions when necessary * Successfully complete initial competency and annual proficiency testing * Serve as a mentor to junior and mid-level forensic analysts * Maintain knowledge and understanding of current trends and new developments in the field of digital forensics, and provide training to other team members * Perform and document technical reviews of other examiners' work * Perform quality audits of laboratory policies, procedures, and work product Required qualifications to be successful in this role: * • Must be a US Citizen. * Ability to work greater than 40 hours per week as needed * Ability to act as full-time on-call for escalation of cyber security incidents * Experience with forensic data acquisition using a variety of imaging types and methods * Experience with Microsoft, Apple, and Linux-based operating systems, including CLIs for each * Extensive experience in Forensic Analysis of compromised systems * Strong knowledge of forensic best practices pertaining to chain of custody and preservation of evidence procedures * Familiarity with forensic artifacts typically found in Windows and Linux operating systems * Knowledge of proper forensic investigation techniques when working with compromised system images or files. * Experience with volatile memory analysis * Experience in team oriented investigative or incident response environments, leveraging other teams' experience and specialties as required * Technical report writing experience * Six plus years of experience with Autopsy, TSK, EnCase, FTK, X-Ways or other computer forensic tools, including vendor specific certifications where applicable * Digital Forensic and Incident Response Certifications such as GCFE, GCFA, CHFI, CCE, CFC, EnCE, CFCE, CART, NCFI BICEL, BCERT, and/or AFT * Experience troubleshooting, maintaining, and repairing computer hardware * Familiarity with identification and post-mortem analysis of malicious software * Experience with forensic acquisition and examination of mobile devices using a variety of hardware and software tools * Experience with implementation, maintenance, and forensic examination of databases including Postgres, MSSQL, MySQL, and others * Experience in Linux systems, Windows systems, Active Directory, and network administration * Experience working in an ISO/IEC 17025 accredited forensic laboratory * Ability to analyze workflow, processes, tools, and procedures to create further efficiency both internal and external to the laboratory * Excellent verbal and written communication and experience presenting technical findings to a wide audience of varying technical expertise DESIRED QUALIFICATIONS * One or More Related Certifications such as the CEH, CISSP, CND * Knowledge of programming and scripting languages (e.g., Python, Perl, EnScript, etc.) * Ability to read and interpret PCAP data * ISO/IEC 17025 Lead Assessor trained #CGIFEDERALJOB Skills: * Incident Response * InsiderThreatVulnerabilityAsse * Malware Engineering What you can expect from us: Build your career with us. It is an extraordinary time to be in business. As digital transformation continues to accelerate, CGI is at the center of this change—supporting our clients' digital journeys and offering our professionals exciting career opportunities. At CGI, our success comes from the talent and commitment of our professionals. As one team, we share the challenges and rewards that come from growing our company, which reinforces our culture of ownership. All of our professionals benefit from the value we collectively create. Be part of building one of the largest independent technology and business services firms in the world. Learn more about CGI at www.cgi.com. No unsolicited agency referrals please. CGI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to their race, ethnicity, ancestry, color, sex, religion, creed, age, national origin, citizenship status, disability, medical condition, military and veteran status, marital status, sexual orientation or perceived sexual orientation, gender, gender identity, and gender expression, familial status, political affiliation, genetic information, or any other legally protected status or characteristics. CGI provides reasonable accommodations to qualified individuals with disabilities. If you need an accommodation to apply for a job in the U.S., please email the CGI U.S. Employment Compliance mailbox at US_Employment_Compliance@cgi.com. You will need to reference the requisition number of the position in which you are interested. Your message will be routed to the appropriate recruiter who will assist you. Please note, this email address is only to be used for those individuals who need an accommodation to apply for a job. Emails for any other reason or those that do not include a requisition number will not be returned. We make it easy to translate military experience and skills! Click here to be directed to our site that is dedicated to veterans and transitioning service members. All CGI offers of employment in the U.S. are contingent upon the ability to successfully complete a background investigation. Background investigation components can vary dependent upon specific assignment and/or level of US government security clearance held. CGI will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with CGI's legal duty to furnish information.