Digital Forensics Analyst- mid-level
- Log in
Find similar career opportunities
Digital Forensics Analyst- mid-level
Category: Cyber Security Consulting
City: Huntsville, Alabama, United States
Position ID: J0919-1402
Employment Type: Full Time
Meet our professionals
CGI: An employer of choice
The CGI Federal Cyber Threat Analysis Center(CTAC) is seeking a senior-level Digital Forensic Analyst to support intrusion and insider threat investigations for internal and external customer incidents. The Digital Forensic Analyst will be responsible for using a wide variety of forensic tools and investigative methods to find: specific electronic data, locate malicious code, determine the infection vector, scope of the compromise, malware artifacts, possible data ex-filtration activity, documents, photos and e-mails from computer hard drives and other data storage devices, such as zip and flash drives that have been deleted, damaged or otherwise manipulated.
Your future duties and responsibilities:
Conducting data forensic investigations for enterprise computer security incidents including but not limited to internal and external intellectual property theft, attacks/intrusions, computer abuse and insider threat investigations
Perform forensically sound imaging of multiple types of data sources
Demonstrated skill performing operational software/hardware testing on digital equipment and other electronic devices.
Ability to follow through on leads until all possible avenues in investigating a case have been exhausted.
Performing log, memory and RAW analysis.
Maintain full chain of custody and evidence tracking
Demonstrated skill in performing post-incident computer forensics in a forensically sound manner.
Organize all relevant case information in easy-to understand format
Prepare reports and document case details, development and outcome.
Provide expert analysis and interpretation of forensic artifacts, including expert opinions when necessary
Successfully complete initial competency and annual proficiency testing
Serve as a mentor to junior and mid-level forensic analysts
Maintain knowledge and understanding of current trends and new developments in the field of digital forensics, and provide training to other team members
Perform and document technical reviews of other examiners work
Perform quality audits of laboratory policies, procedures, and work product
Required qualifications to be successful in this role:
Must be a US Citizen.
Ability to work greater than 40 hours per week as needed
Ability to act as full-time on-call for escalation of cyber security incidents
Experience with forensic data acquisition using a variety of imaging types and methods
Experience with Microsoft, Apple, and Linux-based operating systems, including CLIs for each
Extensive experience in Forensic Analysis of compromised systems
Strong knowledge of forensic best practices pertaining to chain of custody and preservation of evidence procedures
Familiarity with forensic artifacts typically found in Windows and Linux operating systems
Knowledge of proper forensic investigation techniques when working with compromised system images or files.
Experience with volatile memory analysis
Experience in team oriented investigative or incident response environments, leveraging other teams experience and specialties as required
Technical report writing experience
Six plus years of experience with Autopsy, TSK, EnCase, FTK, X-Ways or other computer forensic tools, including vendor specific certifications where applicable
Digital Forensic and Incident Response Certifications such as GCFE, GCFA, CHFI, CCE, CFC, EnCE, CFCE, CART, NCFI BICEL, BCERT, and/or AFT
Experience troubleshooting, maintaining, and repairing computer hardware
Familiarity with identification and post-mortem analysis of malicious software
Experience with forensic acquisition and examination of mobile devices using a variety of hardware and software tools
Experience with implementation, maintenance, and forensic examination of databases including Postgres, MSSQL, MySQL, and others
Experience in Linux systems, Windows systems, Active Directory, and network administration
Experience working in an ISO/IEC 17025 accredited forensic laboratory
Ability to analyze workflow, processes, tools, and procedures to create further efficiency both internal and external to the laboratory
Excellent verbal and written communication and experience presenting technical findings to a wide audience of varying technical expertise
One or More Related Certifications such as the CEH, CISSP, CND
Knowledge of programming and scripting languages (e.g., Python, Perl, EnScript, etc.)
Ability to read and interpret PCAP data
ISO/IEC 17025 Lead Assessor trained
What you can expect from us:
Build your career with us.
It is an extraordinary time to be in business. As digital transformation continues to accelerate, CGI is at the center of this changesupporting our clients digital journeys and offering our professionals exciting career opportunities.
At CGI, our success comes from the talent and commitment of our professionals. As one team, we share the challenges and rewards that come from growing our company, which reinforces our culture of ownership. All of our professionals benefit from the value we collectively create.
Be part of building one of the largest independent technology and business services firms in the world.
Learn more about CGI at www.cgi.com .
No unsolicited agency referrals please.
CGI is an equal opportunity employer.
Qualified applicants will receive consideration for employment without regard to their race, ethnicity, ancestry, color, sex, religion, creed, age, national origin, citizenship status, disability, medical condition, military and veteran status, marital status, sexual orientation or perceived sexual orientation, gender, gender identity, and gender expression, familial status, political affiliation, genetic information, or any other legally protected status or characteristics.
CGI provides reasonable accommodations to qualified individuals with disabilities. If you need an accommodation to apply for a job in the U.S., please email the CGI U.S. Employment Compliance mailbox at USEmploymentCompliance@cgi.com . You will need to reference the requisition number of the position in which you are interested. Your message will be routed to the appropriate recruiter who will assist you. Please note, this email address is only to be used for those individuals who need an accommodation to apply for a job. Emails for any other reason or those that do not include a requisition number will not be returned .
We make it easy to translate military experience and skills! Click here at https://cgi-veterans.jobs/ to be directed to our site that is dedicated to veterans and transitioning service members.
All CGI offers of employment in the U.S. are contingent upon the ability to successfully complete a background investigation. Background investigation components can vary dependent upon specific assignment and/or level of US government security clearance held.
CGI will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with CGIs legal duty to furnish information.