Digital Forensics & eDiscovery

This mid-level role within a global financial group involves performing digital forensic examinations and eDiscovery in support of Information Security, Legal, Compliance and HR investigations. Day to day, the analyst conducts artifact analysis across Windows, Mac and Linux systems, performs

Incident Response Principal Consultant

This principal-level consulting role centres on leading high-priority incident response engagements for organisations facing sophisticated cyber threats. Day to day, the practitioner conducts intrusion investigations, performs host and network-based forensic analysis across Windows, macOS, and Linux, and supports cloud IR

Digital Forensic Examiner

This full-time role requires an active TS/SCI clearance and at least eight years of digital forensics experience. Day to day, the examiner conducts forensic examinations of digital devices and media, analyses large and complex datasets, and identifies artefacts, steganography and

Senior Consultant, DFIR, Reactive Services (Unit 42)

The Role This position sits within a specialist incident response practice, where consultants investigate active cybersecurity incidents, conduct forensic analysis, and support client recovery efforts. Day to day, work involves collaborating with senior practitioners across varied client environments, contributing technical

Senior Incident Response Consultant, DFIR

The Role Consultants lead end-to-end incident response engagements for external clients, conducting digital forensics investigations, malware analysis, and threat actor attribution. The position requires 24/7 on-call availability, remote and on-site deployment, executive briefings, and maintaining a 75% billable utilisation target

Forensic Computer Analyst SR

The Role This position involves conducting complex forensic examinations of digital and multimedia evidence in support of criminal and administrative investigations. Responsibilities include analyzing evidence, producing detailed reports and exhibits, providing expert witness testimony in judicial proceedings, performing quality control

VP, Digital Forensics Expert Witness – SME (Testifying)

The Role This position centres on conducting digital forensic investigations across endpoints, cloud platforms, and enterprise environments, then presenting those findings in legal proceedings. Day to day, the work spans authoring expert reports, supporting litigation counsel on technical strategy, and

Senior DFIR Consultant – Remote (Anywhere in the U.S.)

The Role This fully remote position involves leading and executing complex digital forensics and incident response investigations, including host forensics, network traffic analysis, log review, malware triage, and business email compromise analysis. The consultant communicates findings to both technical and

Senior Incident Response Consultant | USA, Remote | $120,000 – $155,000

The Role This position leads complex digital forensic investigations from initial triage through containment and recovery, covering host, network, cloud, and application environments. Consultants direct client teams during live incidents, scope engagements, develop detection logic from attacker behaviour, and deliver

Forensic Data Analyst with Security Clearance

The Role This on-site position supports a federal law enforcement client across Fairfax and Arlington, VA. Day-to-day work includes consulting with field users on forensic needs, extracting data from mobile devices, managing forensic intake, conducting examinations in line with established

Principal DFIR Consultant

The Role This senior consulting position leads digital forensics and incident response engagements, with a focus on business email compromise and ransomware cases. Day to day, the work spans forensic investigation, log and artifact analysis, containment support, client communication, team

Principal Consultant, DFIR

The Role This position involves leading end-to-end incident response engagements, from initial identification and containment through to forensic investigation, log analysis, and report writing. The practitioner also conducts threat actor communications and ransomware negotiations when required, operating independently under pressure

Associate Director, Incident Response and Forensics

The Role This senior leadership position oversees a global team of digital forensics, incident response, and eDiscovery analysts. Day to day, the role involves directing forensic investigations, guiding incident handling across the full response lifecycle, driving tool adoption, and collaborating

Sr. Cyber Analyst, Digital Forensics Incident Response

The Role This position involves conducting end-to-end incident investigations for insured clients, including evidence collection, forensic analysis, timeline development, and root cause identification. The analyst also participates in threat actor negotiations, supports recovery efforts, produces detailed incident reports, and delivers

Digital Forensics Analyst

The Role This hybrid position involves conducting network and media forensic investigations, supporting cybersecurity incident response, and performing advanced threat hunting across enterprise infrastructure. Day-to-day work includes malware analysis, IOC sweeps, evidence preservation, insider threat investigations, and preparing detailed technical

Senior Director, Digital Forensics & Incident Response

The Role This senior leadership position owns and commands the enterprise response to cyber incidents across cloud, on-premises and OT/ICS environments globally. Day to day, the role drives incident scoping, containment, eradication and recovery, oversees forensic evidence integrity, delivers executive

Digital Forensic Technician

The Role This position involves supporting a forensic laboratory through the full evidence lifecycle, from seizure and imaging at search locations to documentation, reporting, and court testimony. Day-to-day duties include maintaining chain of custody, performing tool validation, assisting with accreditation,

CTN – Digital Forensics/Law Enforcement Integration SME

The Role This remote position supports a DoD counter-narcotics programme by providing senior technical expertise to a partner-nation defence force. Day-to-day work involves designing and delivering training curricula, integrating digital forensics with law-enforcement workflows, mentoring local personnel, and improving interagency

Digital Forensics Investigator

The Role This position supports law enforcement by collecting, preserving, processing, and presenting digital evidence across a range of criminal investigations, with a focus on violent crimes and internet crimes against children. Day-to-day work includes writing detailed reports, assisting prosecutors

Mid-Level Digital Forensic Analyst

The Role This position involves conducting forensic examinations of digital devices and data sources, including mobile phones, computers, removable media, and cloud platforms. Day to day, analysts perform targeted evidence extraction, produce detailed reports for investigators and prosecutors, and provide

DFIR Consultant

The Role This fully remote position involves supporting clients through the full lifecycle of cyber incidents, from initial triage and evidence preservation through forensic analysis and final reporting. Day-to-day work centres on investigating Business Email Compromise and ransomware cases, delivering

Incident Response Senior Consultant (Remote)

The Role This position involves leading incident response engagements for major organisations, investigating breaches, analysing attacker behaviour, and delivering technical findings. Consultants work remotely across a varied caseload, responding to complex, high-profile incidents and helping clients understand and contain advanced

Cyber Crime Investigator

The Role This on-site position at Quantico supports a federal counterintelligence programme, combining traditional investigative methods with advanced cyber expertise. Day-to-day responsibilities span digital forensic examinations, evidence acquisition, incident response, malware analysis, operational security assessments, and designing and delivering training

Senior Cyber Crypto & Blockchain Forensic Investigator

The Role This position supports a federal law enforcement agency, conducting complex cryptocurrency tracing across multiple blockchains and obfuscation techniques, performing advanced on-chain analysis, leading OSINT collection, carrying out financial forensic analysis across large datasets, and contributing to cyber-enabled investigations

Associate/Cybersecurity & Incident Response (Forensic Services practice)

The Role This position involves executing security and privacy investigations, supporting data breach detection, threat analysis, incident response, and malware analysis. Associates assist counsel and clients with digital forensic support, contribute to drafting forensic reports and affidavits, and may provide

Computer Forensic Examiner, Computer Crimes

The Role This position involves conducting computer forensic examinations and supporting criminal investigations into offences including child exploitation, identity theft, computer fraud, and computer trespass. The examiner collaborates with federal, state, and local law enforcement, engages with technology professionals, and

Principal Incident Response Security Consultant, Mandiant

The Role This senior consulting position involves leading end-to-end incident response engagements for clients facing complex, high-profile security incidents. Day-to-day responsibilities include conducting forensic investigations, performing threat hunting, triaging malware, supporting containment and remediation efforts, and communicating findings to both

Incident Response Principal Consultant (Remote)

The Role This position involves leading complex incident response engagements for major global organisations, investigating breaches, analysing threat actor activity, and delivering expert guidance throughout the full incident lifecycle. Consultants work across a varied caseload, handling high-profile investigations that demand

Digital Forensic Analyst I

The Role This position centres on the forensic preservation and collection of data from mobile devices and cloud environments, with both on-site travel and in-office lab work. Day-to-day responsibilities include liaising with legal and IT teams, maintaining chain of custody,

IT Incident Response and Forensics Specialist III

Lead complex security investigations and digital forensics across endpoints, networks, and cloud environments. Responsibilities include threat hunting, evidence preservation, root cause analysis, playbook development, and post-incident reporting to strengthen security posture.

Incident Response Principal Consultant (Remote)

The Role This remote position involves leading complex incident response investigations for major global organisations, responding to advanced cyber threats and breaches. Day to day, consultants conduct forensic analysis, manage high-stakes engagements, and advise clients on containment and remediation strategies

Host Based Cyber Systems Analyst III

Experienced analyst needed to lead host-based forensic investigations for DHS HIRT, conducting evidence acquisition, malware triage, memory analysis, and intrusion reporting across federal civilian networks and critical government systems.

Criminalist I, Digital Forensics (8259) – San Francisco Police Department

The Role This position involves conducting digital forensic examinations on electronic devices and digital media in support of criminal investigations. Working within a law enforcement laboratory setting, the specialist processes, analyzes, and documents digital evidence, producing detailed reports and providing

Principal Incident Response Analyst

The Role This senior position sits within a Threat Detection and Response team, covering hands-on security incident analysis, digital forensic investigations, and proactive threat hunting. The analyst leads containment and remediation efforts, coordinates with cross-functional teams during active incidents, and

Digital Forensic Examiner, Mid

The Role This position involves leading and supporting digital forensics and incident response investigations on a day-to-day basis. Responsibilities include scoping new matters, managing case documentation, analysing forensic images, examining malware and log data, identifying indicators of compromise, and delivering

Digital Forensics Lead (CBP)

The Role This position leads digital forensics operations supporting a large federal border protection environment, spanning hundreds of ports of entry and associated facilities. Day to day, the work involves preserving and analyzing evidence from compromised or suspect systems, reconstructing

Principal Incident Response Security Consultant, Mandiant

Senior Mandiant consultant managing complex incident response engagements, performing digital forensics, threat hunting, and malware analysis across cloud and on-premise environments, while communicating findings to executive and legal stakeholders.

Senior Security Engineer, Digital Forensics

Join a global 24/7 detection and response team to investigate security and privacy incidents, conduct digital forensic analysis, develop forensic tooling, and contribute to large-scale incident response across a major technology organisation.

Cyber Defense Forensics Lead

The Role This position leads a team of digital forensics analysts supporting insider threat operations and data loss prevention for a federal law enforcement agency. Day-to-day responsibilities include directing enterprise and endpoint forensic investigations across Windows, Linux, Mac, and cloud

Cryptologist

Supports DoD cyber investigations by decrypting and recovering data from seized mobile devices, computers, and storage media. Produces technical reports for federal court proceedings and collaborates with digital forensic examiners on law enforcement and counterintelligence operations.

Cryptologist (Digital Forensics & Data Recovery)

Supports DoD law enforcement and counterintelligence investigations by decrypting mobile devices and storage media, recovering deleted data, performing chip-level extractions, and producing technical reports suitable for federal court proceedings. Top Secret/SCI clearance required.

Senior Forensic Technician/Analyst

Performs forensic analysis on computer systems, servers, and mobile devices at a naval warfare centre. Collects and preserves digital evidence, investigates cybersecurity incidents, recovers data, and produces forensic examination reports. May supervise junior analysts.

Lead Digital Investigations Engineer

Lead digital investigations role supporting law enforcement sponsors, conducting forensic analysis of endpoints, mobile devices, cloud environments and networks, handling evidence, producing investigative reports, and assisting with incident response and containment efforts.

Digital Forensics Analyst

The Role This hybrid position involves conducting network and media forensic investigations, supporting cybersecurity incident response, and performing advanced threat hunting across enterprise infrastructure. Day-to-day work includes malware analysis, IOC sweeps, evidence preservation, SOP development, and preparing detailed technical reports

Senior Forensic Developer – HYBRID!

Design and build specialised forensic software supporting federal cybercrime and digital evidence investigations. Responsibilities include file-system parsing, memory analysis, binary reverse engineering, mobile device parsing, and producing court-ready, validated investigative tooling.

IT – Cyber Security Specialist IV

Seeking a cryptologist to decrypt data from mobile devices, computers and storage media, recover deleted data, perform chip-level extractions, and produce technical reports supporting federal law enforcement and counterintelligence investigations. TS/SCI clearance required.

Forensic Data Analyst with Security Clearance

The Role This position involves conducting mobile device forensic examinations for a federal law enforcement client, including physical extractions, board-level repair, and lawful access to encrypted devices. Analysts manage evidence intake, maintain chain-of-custody documentation, support active investigations, and provide expert

Digital Forensic Analyst I with Security Clearance

The Role This position centres on the forensic preservation and collection of data from mobile devices and cloud environments, with both on-site travel and in-office lab work involved. Day-to-day responsibilities include liaising with legal and IT teams, maintaining chain of

CFL Intrusions Lead

The Role This position leads a team conducting digital forensic examinations, network forensics, malware analysis, and reverse engineering in support of intrusion investigations. Day-to-day responsibilities include overseeing evidence handling, managing task execution, ensuring regulatory and accreditation compliance, and delivering accurate,

Security Analyst: Forensic Investigations

The Role This position conducts forensic investigations across a large financial institution, covering areas such as employee relations matters, email forensics, and legal holds. Day-to-day work includes reviewing logs, analysing data, creating documentation, supporting data loss prevention efforts, and helping

Senior Incident Response Consultant, DFIR

The Role This position leads digital forensics and incident response engagements for external clients facing active cybersecurity threats. Day-to-day work includes malware analysis, forensic examination of compromised systems, threat actor attribution, and delivering executive briefings, with 24/7 on-call availability and

Consulting Director, DFIR, Reactive Services (Unit 42)

The Role This senior position leads cybersecurity incident response and digital forensics engagements for enterprise clients, combining strategic advisory responsibilities with hands-on technical leadership. Day to day involves guiding organisations through complex breaches, overseeing forensic investigations including memory and disk

Senior Security Consultant, Incident Response, Mandiant

The Role This position involves leading end-to-end incident response engagements, supporting clients through investigation, containment, remediation, and crisis management. Day to day, consultants analyse threats across network, cloud, disk, and memory environments, communicate findings to diverse audiences, and help organisations

Forensic Computer Analyst

The Role This position involves conducting forensic examinations of digital and multimedia evidence in a laboratory environment, supporting criminal and administrative investigations. Day-to-day responsibilities include analysing evidence, producing detailed reports and exhibits, providing expert witness testimony in legal proceedings, and

Digital Forensics SME

The Role This senior position leads advanced digital forensics and incident response work across an enterprise environment, covering forensic imaging, memory analysis, malware reverse engineering, and network intrusion investigations. The analyst also coordinates SOC remediation efforts, supports threat intelligence production,

CERT Lead

The Role This position leads a Computer Emergency Response Team through all phases of the incident response lifecycle, serving as the senior technical escalation point for high-profile cybersecurity incidents across city agencies. Day-to-day responsibilities span malware analysis, digital forensics, threat

Host Based Systems Analyst III

The Role This position supports federal cybersecurity incident response and proactive threat hunting, conducting host-based forensic analysis during both remote and onsite engagements. Day-to-day work includes coordinating data collection, leading forensic teams, analysing digital artefacts, drafting technical reports and executive

Senior Cyber Lead

The Role This position leads digital forensics and incident response operations supporting a major Department of Defense cyber laboratory. Day to day involves directing forensic examinations, overseeing malware and intrusion analysis, managing evidence workflows in an accredited environment, and coordinating

Associate Director, Incident Response and Forensics

The Role This position leads a global team of digital forensics, incident response, and eDiscovery analysts, overseeing the full incident response lifecycle from preparation through recovery. Day-to-day responsibilities include forensic analysis of operating systems, network traffic examination, IOC derivation, malware

Host Based Systems Analyst III

The Role This position involves delivering hands-on digital forensics and incident response support for a federal government client. Day-to-day work includes coordinating data acquisition operations, conducting host-based forensic analysis, leading preliminary investigations, producing technical reports and executive summaries, and serving

Principal Consultant, DFIR

The Role This position involves leading end-to-end incident response engagements, from initial identification and containment through to recovery and reporting. Practitioners conduct digital forensic investigations across servers and endpoints, perform log analysis, and when required, manage threat actor communications and

Cyber Forensics Analyst

The Role This position involves hands-on digital forensics and malware analysis in support of SOC investigations and incident response. Day-to-day work includes examining endpoints, servers, memory artifacts, file systems, and logs, as well as developing indicators of compromise and contributing

Digital Forensic Examiner

The Role This position involves examining digital evidence across criminal, civil, and corporate matters, working with devices ranging from mobile phones and computers to vehicles. Day-to-day responsibilities include evidence management, data analysis, report writing, client consultation, expert witness testimony, and

Digital Forensics Lab Technician

The Role This position involves performing forensic extractions from contraband mobile devices recovered within correctional facilities, with a target output of around 50 devices per week. Technicians prepare summary reports, upload documentation into a state corrections case management system, and

Digital Forensic Specialist (NMDOJ #1116)

The Role This position involves extracting, analysing, and preserving digital evidence from computers, mobile devices, network logs, and cloud storage seized during criminal investigations. The examiner supports law enforcement agencies across the state, helps build prosecutable cases against online child

Associate Principal/Digital Forensics (Forensic Services practice)

The Role This position leads digital forensic investigations, primarily involving trade secret theft matters. Day-to-day work includes onsite data collection, forensic analysis of macOS and mobile device artifacts, data remediation across multiple file systems, and guiding investigation teams. Expert witness

Digital Forensics Analyst

The Role This position involves conducting digital forensic investigations in support of ethics and employee concerns, performing evidence acquisition, preservation, and analysis in line with forensic best practices. Responsibilities include malware analysis, Windows registry examination, data carving, chain of custody

Digital Forensics Technician I (Hourly)

The Role This part-time, entry-level position supports law enforcement investigations by conducting forensic examinations of digital devices, including computers, mobile phones, and storage media. Responsibilities include extracting and preserving digital evidence, determining appropriate forensic methods, logging evidence, and maintaining accurate

Digital Forensic Examiner (Remote 10-99)

The Role The examiner analyses digital evidence from computers, mobile devices, cloud environments, and data return packages obtained via legal process, such as those from Google, iCloud, and Facebook. Work also includes preparing clear forensic reports, collaborating with attorneys and

Principal Incident Response Consultant, Google Public Sector

Lead incident response and forensic consulting engagements for US public sector clients, managing breach containment, threat hunting, and remediation while mentoring staff and developing new business opportunities leveraging Google and Mandiant capabilities.

Consulting Associate/Recovery Services (Forensic Services practice)

Hands-on forensic analyst and incident responder supporting ransomware, BEC, and fraud investigations. Responsibilities include digital forensic collection, endpoint containment, enterprise identity remediation, and producing defensible written findings for clients and counsel.

Digital Forensic Technician

The Role This position centres on collecting, preserving, imaging, and documenting digital evidence within a forensic laboratory environment. Day-to-day work includes supporting field seizures, maintaining chain of custody, writing forensic reports, assisting with audits and accreditation, and occasionally providing expert

Digital Forensics Analyst

The Role This position sits within an ethics and employee concerns function, conducting digital forensic investigations into workplace matters. Day to day, the analyst acquires and preserves digital evidence, performs forensic imaging, conducts malware and registry analysis, supports internal and

Forensic Data Analyst

The Role This position supports a federal law enforcement client on-site in Fairfax, VA, performing mobile device extractions, including physical, filesystem, BFU, and AFU methods, conducting board-level repairs, microsoldering, and vehicle infotainment extractions, while maintaining chain-of-custody standards and providing courtroom

Digital Forensics Lab Technician

The Role This position centres on performing forensic extractions from contraband mobile devices recovered within correctional facilities, processing approximately 50 devices per week. Technicians analyse extracted data, prepare summary reports, upload documentation into authorised case management systems, and maintain strict

IBM CISO – Cybersecurity Forensic Analyst

The Role This position sits within a global cybersecurity incident response team, focusing on the Americas region. Day to day, analysts conduct forensic investigations across endpoint, network, and cloud environments, collect and preserve digital evidence, support incident triage and containment,

Information Technology Manager II

The Role This position leads complex cyber incident investigations across enterprise, cloud, and on-premises environments, covering the full incident response lifecycle from triage to post-incident reporting. Day-to-day work includes digital forensics, malware analysis, proactive threat hunting, and developing SIEM detections

DFIR Consultant

Join a specialist DFIR team responding to BEC and ransomware incidents. Responsibilities include evidence acquisition, forensic analysis, malware triage, timeline development, client communication, and written reporting across endpoint, server, and cloud environments.

DFIR Consultant

The Role This position involves conducting digital forensics and incident response investigations across Windows and Linux environments. Day to day, the consultant collects disk and memory images, analyses forensic artefacts for indicators of compromise, reviews host and appliance logs, builds

Assistant Director -Cyber Crimes Unit

The Role This sworn investigative position leads day-to-day operations within a prosecutor-aligned cyber crimes unit, conducting digital forensics examinations, producing detailed investigative reports, collaborating with law enforcement and legal staff, and serving as an instructor for digital forensics training. The

DFIR Cybersecurity Consultant (Remote)

Conduct forensic analysis and incident response investigations covering ransomware, business email compromise and litigation support. Collect and analyse data, produce technical reports, develop modern forensic techniques, and assist with EDR deployment and triage.

Principal DFIR Consultant – Remote (Anywhere in the U.S.)

The Role This senior individual contributor position leads the most complex and high-visibility incident response engagements, including ransomware, APT, and insider threat cases. Day to day involves conducting advanced host forensics, network analysis, cloud forensics, and malware triage, while also

Director, DFIR (Remote)

The Role This fully remote position involves leading digital forensics and incident response engagements across a range of cyber threats, including ransomware and data theft. The director oversees multiple concurrent incidents, coordinates cross-functional teams, and liaises with external stakeholders such

Principal DFIR Consultant

The job posting is cut off at “Client Management And” but I have enough information to write the description. Let me craft the HTML with the three required sections. Key points from the posting: – Principal DFIR Consultant, remote USA

Principal Consultant, Digital Forensic and Incident Response (DFIR) (Remote)

The Role This fully remote position involves leading digital forensics and incident response engagements across a range of industries, conducting sophisticated forensic analysis, managing investigations of varying complexity, and serving as a senior technical expert for clients navigating active cyber

Engineer, Cybersecurity DFIR

The Role This position sits within a cybersecurity DFIR team defending critical financial infrastructure against global threats. Day to day, the engineer handles security analytics, incident detection and investigation, endpoint forensics, threat hunting, intrusion detection, and the design of preventative

Principal Consultant, DFIR, Reactive Services (Unit 42) – Remote Weekend Shift

The Role This senior individual contributor position involves leading expert-level incident response and digital forensics engagements across diverse industries. Day to day, consultants conduct forensic investigations, analyse attacker activity, assess scope and impact, and guide clients through containment, remediation, and

Senior Associate, Digital Forensics and Incident Response (DFIR)

The Role This position involves leading and supporting cybersecurity investigations, including ransomware, data breaches, and insider threats. Day-to-day responsibilities include forensic imaging, malware examination, log analysis, and reconstructing attack timelines across endpoints, servers, cloud environments, and mobile devices, with findings

Cyber Network Defense Analyst (CNDA) – Cloud Forensics

The Role This position involves leading end-to-end forensic investigations across hybrid and multi-cloud environments, including Azure, AWS, and GCP. Analysts correlate telemetry, reconstruct attacker timelines, develop detection logic and hunting scripts, and produce technical and executive-level reports to support federal

Media Malware Analyst, Senior

The Role This senior position supports United States Cyber Command by leading forensic examination of compromised systems and digital media, conducting static and dynamic malware analysis, reverse engineering malicious files, and producing detailed technical reports and threat briefings that inform

Cyber Network Defense Analyst III

The Role This position supports a federal cyber defence programme, conducting Tier 2 and Tier 3 digital forensics and incident response investigations both remotely and on-site. Day-to-day work involves responding to cyber incidents, performing proactive threat hunting, and analysing host-based,

Cyber Network Defense Analyst II

The Role This position supports front-line cyber defence and incident response operations within a federal programme protecting national communications infrastructure. Day to day, analysts conduct Tier 2 and Tier 3 digital forensics and incident response investigations, perform proactive threat hunting,

Contract Bench, Incident Responder (DFIR)

The Role This contract position involves conducting digital forensic investigations and incident response engagements on a flexible, as-needed basis. Responders analyse live response data, investigate threat actor activity across Windows environments and cloud platforms, and help eradicate adversaries across clients’

Senior Consultant, DFIR (Wed-Sun)

The Role This position involves leading digital forensics and incident response engagements across modern enterprise environments, investigating threat actor activity on endpoints, cloud platforms including AWS, Azure, and GCP, SaaS applications, and identity providers, while supporting clients through active incidents

Senior Consultant, DFIR

The Role This position involves leading incident response and digital forensics engagements across complex, modern enterprise environments, including Windows endpoints, cloud platforms such as AWS, Azure, and GCP, and SaaS applications. Consultants investigate active threats, support clients through high-pressure incidents,

Senior Incident Response Consultant

The Role This position leads forensic investigations across host, network, and application environments while guiding clients through containment, remediation, and recovery. Day to day involves triaging active security incidents, identifying attacker tactics, developing investigative tooling, producing reports, and working directly

Lead Cyber Mission Threat Analyst – Clearance Required

The Role This senior position leads cyber threat hunting, incident investigation, forensic analysis, and enterprise monitoring in support of U.S. Navy cybersecurity operations. The analyst identifies indicators of compromise, examines adversary tactics, conducts complex investigations, and delivers actionable recommendations to

DFIR

The Role This position sits at the front line of cyber defence, handling the full incident response lifecycle for clients worldwide. Day to day, practitioners perform digital forensic investigations across Windows, Linux, and cloud environments, conduct proactive threat hunting, analyse

Senior Cyber Lead

The Role This senior position leads digital forensics and incident response operations in support of a Department of Defense cyber forensics laboratory. Day to day, the role involves directing forensic examinations, overseeing malware and intrusion analysis, managing evidence handling and

Principal Engagement Lead (Remote)

The Role This fully remote position centres on leading multiple concurrent cybersecurity incident response engagements, serving as the primary point of contact for clients, insurance carriers, and legal counsel. Day-to-day responsibilities include scoping engagements, coordinating cross-functional response teams, and driving

Incident Response and Forensics Lead

The Role This senior position leads a digital forensics and incident response team within a federal environment, overseeing day-to-day operations, managing service delivery, briefing clients and senior leadership, analyzing intrusion artifacts such as malware, and monitoring emerging threats from external

Lead Cyber Mission Threat Analyst – Clearance Required

The Role This senior position leads cyber threat hunting, incident investigation, enterprise monitoring, and forensic analysis in support of U.S. Navy cybersecurity operations. Working alongside government professionals, the analyst identifies indicators of compromise, examines adversary tactics, conducts complex investigations, and

Digital Forensics Lead

The Role This position leads digital forensics and insider-threat investigations within a 24/7 cybersecurity operations centre, overseeing evidence handling, chain-of-custody procedures, endpoint and network forensic analysis, and malware triage, while maintaining SIEM dashboards, incident response documentation, and mentoring junior team

Digital Forensic Examiner Trainee / Trainee-Forensic Scientist 1

The Role This entry-level position involves learning digital forensic examination techniques under the supervision of experienced practitioners. Day-to-day work focuses on the analysis of digital and multimedia evidence, with up to 25% travel required. Initial duties are performed at the

Forensic Analyst (VIG-FA-01.080626)

The Role This position involves the examination and analysis of digital evidence, including computers, networks, devices, logs, and files. Day to day, analysts exploit captured media, investigate computer security incidents, and support intelligence derivation and network vulnerability mitigation across cybersecurity,

Digital Forensics Consultant (PST hours Seattle Area preferred)

The Role This position involves conducting forensically sound collections of electronically stored information from computers, mobile devices, servers, cloud repositories, and other digital sources, both onsite and remotely. Practitioners perform forensic analysis supporting investigations and litigation, author detailed reports, and

ICITAP Forensic Digital Evidence Advisor

The Role This advisory position involves delivering specialist training and mentorship to host-country law enforcement professionals on the collection, preservation, examination, and court presentation of digital evidence, including data recovered from mobile devices, computers, and other digital sources, in support

Senior Forensic Analyst

The Role The analyst conducts forensic evaluations of federal enterprise systems suspected of compromise, working with a high degree of independence on non-repetitive, fixed-duration engagements. Each investigation is unique, requiring rigorous host and network forensic analysis performed under strict legal

AOUSC – Forensic and Malware Lead

The Role This position leads digital forensics and malware analysis operations within a large federal security operations environment. Day to day, the work spans static and dynamic malware analysis, forensic examination of disk and memory artifacts, live system investigation, and

Associate/Cybersecurity & Incident Response (Forensic Services practice)

The Role This position sits within a forensic consulting practice, where practitioners conduct security and privacy investigations, support incident response engagements, and perform malware and threat analysis. Work also involves drafting forensic reports and affidavits, and providing expert support to

Criminal Crypto Technical Support Specialist- Expert – 4 Tyler Texas

The Role This position supports a federal law enforcement agency by leading expert-level blockchain and financial forensic investigations. Day-to-day work spans evidence collection and preservation, cryptocurrency tracing, OSINT analysis across open and dark web sources, and producing findings that underpin

Computer Forensics Investigator

The Role This position involves conducting end-to-end digital investigations, from collecting and preserving evidence in line with legal standards to analysing data across computers, mobile devices, and networks. Responsibilities include recovering deleted files, reviewing logs, performing malware analysis, producing detailed

Digital Forensic Examiner II

The Role This position involves the forensic extraction and analysis of digital evidence from mobile devices, computers, tablets, GPS units, and portable storage media. Examiners document their methodology and findings, support prosecutors with technology-related matters, and present expert testimony in

Digital Forensic Analyst I

The Role This position centres on the forensic preservation and collection of data from mobile devices and cloud environments, with a mix of on-site travel and in-office lab work. Day-to-day responsibilities include liaising with legal and IT teams, managing chain

Digital Forensic Examiners 23-E-25

The Role This full-time position involves conducting forensic examinations of digital evidence in support of criminal investigations, working both in a laboratory setting and on-scene during law enforcement operations. The examiner provides technical support to investigators and attorneys and collaborates

Digital Forensic Examiner (DFE) 24-E-10

The Role The examiner conducts forensic analysis of digital evidence in support of criminal investigations, working both in a laboratory setting and on-site during active law enforcement operations. The role also involves providing technical support to investigators and attorneys, and

Senior Digital Forensics Examiner

The Role This position involves conducting forensic examinations of mobile devices, computers, and other digital media across civil and criminal matters. Examiners produce peer-reviewed laboratory reports, draft affidavits, and regularly testify as expert witnesses in depositions and court proceedings for

Digital Forensic Examiner

The Role This position involves the forensic examination of mobile devices, computers, and electronically stored data to support criminal investigations. Day-to-day responsibilities include acquiring and analysing digital evidence, conducting on-scene device previews and triage, collecting data from digital video recording

Minimum qualifications

The Role This position involves protecting network boundaries, hardening systems against attacks, and monitoring infrastructure for intrusions. The engineer owns and drives resolution of complex security incidents, collaborates with software engineers to identify and remediate vulnerabilities, and handles sensitive policy

Digital Forensic Examiner

The Role This position involves conducting forensic examinations of mobile devices, computers, and digital storage media to support criminal investigations. Examiners acquire and analyse electronic evidence, preview devices on-scene, collect data from video recording systems, prepare detailed reports, and provide

Digital Forensics Lead (26-091) with Security Clearance

The Role This hybrid position involves leading and conducting digital forensics investigations into cybersecurity incidents affecting agency systems and devices, developing and maturing a forensics programme, and delivering clear analytical reports to senior leadership, including the CISO, based on investigation

Digital Forensics Analyst (Cyber Analyst III) TS/SCI with Security Clearance

The Role This position supports sensitive military and intelligence missions by conducting forensically sound acquisition, examination, and analysis of digital evidence across computers, mobile devices, servers, and removable media. The analyst produces detailed reports, maintains network intrusion detection systems, and

Digital Forensic Examiner

The Role This position involves conducting forensic examinations of mobile devices, computers, hardware, software, and electronically stored data to support criminal investigations. Day-to-day duties include acquiring and analysing digital evidence, attending crime scenes, triaging devices on-site, collecting data from digital

Mid-Level Digital Forensic Analyst

The Role The analyst conducts forensic examinations of digital data drawn from mobile devices, computers, removable media, and cloud sources, supporting criminal, cyber, and administrative investigations. Work involves recovering, analysing, and interpreting digital evidence and producing clear, court-defensible findings within

Incident Response Expert

The Role This position involves leading and supporting end-to-end forensic investigations across complex cybersecurity incidents, including ransomware and nation-state activity. Day-to-day work includes log analysis, host and network forensics, memory analysis, malware triage, threat hunting, and collaborating with client security

Digital Forensics Consultant (PST hours Seattle Area preferred)

The Role This position centres on conducting forensically sound collections of electronically stored information from computers, mobile devices, servers, cloud repositories, and other digital media, both onsite and remotely. Consultants analyse collected data to support investigations and litigation, produce detailed

Digital Forensics Consultant (Onsite in San Francisco Lab)

The Role This position involves collecting electronically stored information from computers, mobile devices, servers, cloud repositories, and other digital media, both on-site and remotely. Consultants conduct forensic analysis in support of investigations and litigation, prepare detailed written reports, and may

Digital Forensics Analyst (Cyber Analyst III) TS/SCI

The Role This position involves conducting forensically sound acquisition, preservation, and examination of digital media including mobile devices, computers, and servers in support of sensitive military and intelligence missions. Day-to-day work includes analyzing network logs, triaging malware, processing encrypted or

Digital Forensic Examiner 1

The Role This entry-level position involves examining electronic devices, recovering deleted or damaged data, and documenting digital evidence to support criminal investigations. Responsibilities also include assisting investigators at crime scenes, maintaining network systems used in online investigations, and helping prepare

Digital Forensics Analyst

The Role This position centres on conducting complex digital forensics investigations within an enterprise environment, with a focus on insider threat, data exfiltration, and employee misconduct cases. Day-to-day work spans forensic acquisition, endpoint and cloud artifact analysis, EDR log review,

Forensic Analyst (VIG-FA-01.080626)

The Role This position involves the examination and analysis of digital evidence, including computers, networks, devices, logs, and files. The analyst supports cybersecurity, intelligence, and investigative missions by exploiting captured media, investigating security incidents, and deriving actionable intelligence to help

Senior Associate/Digital Forensics (Forensic Services practice)

The Role This position involves conducting digital forensic investigations across a range of operating systems and mobile platforms. Day-to-day work includes onsite data collection, chain of custody documentation, forensic analysis of device artifacts, trade secret misappropriation investigations, mobile device extractions,

Digital Forensics Senior Consultant

The Role This senior-level position involves conducting digital forensics investigations, supporting clients through complex incidents, and delivering high-impact engagements. Day to day, the consultant collaborates across teams, applies emerging technologies including AI-enabled tools, and contributes to account strategy while ensuring

Engineer, Cybersecurity DFIR

The Role This position focuses on defending critical financial infrastructure through hands-on incident response, endpoint forensics, and proactive threat hunting. Day to day involves detecting and investigating security incidents, analysing forensic artefacts to build timelines, tuning intrusion detection controls, and

Senior Computer Forensics Analyst

The Role This senior-level position centres on acquiring, preserving, and forensically examining data from Windows and Mac systems, servers, mobile devices, and digital storage media. The analyst manages lab operations and multiple concurrent projects, produces expert-quality reports, and may provide

Senior Investigator Digital Forensics, Incident Response (DFIR)

The Role This senior position involves leading complex digital forensics and incident response investigations across cloud, OT, and enterprise environments. Day-to-day work includes memory forensics, malware triage, threat hunting, log analysis, and building attack timelines, while mentoring junior investigators and

CSIRT Analyst

The Role This position sits within a CSIRT team, handling escalated security incidents and conducting digital forensics and incident response investigations. Day-to-day responsibilities span threat hunting, compromise assessments, threat intelligence collection, detection engineering in SIEM and XDR platforms, purple teaming

Forensics Lead

The Role This position leads digital forensics operations supporting a federal homeland security environment around the clock. Day-to-day work includes conducting remote imaging, analysing digital media, reverse engineering malicious code, responding to email-based attacks, and applying kill-chain methodologies to detect

Threat Hunt Analyst – High – Digital Forensics

The Role This position centres on designing and leading proactive threat hunting programmes across a federal enterprise IT environment, conducting advanced digital forensics investigations, supporting complex incident response activities, and identifying advanced persistent threats targeting critical government systems and data.

Digital Forensics and Incident Response Advisory – Manager

The Role This manager-level position sits within a cybersecurity and digital trust advisory practice, focusing on digital forensics and incident response engagements. Day to day, the role involves leading client-facing work across diverse industry sectors, helping organisations manage security incidents,

Global Director of Autonomous Incident Response and Forensic Analysis

The Role This senior leadership position oversees a 24/7 global incident response and digital forensics function, driving strategy, execution, and continuous improvement. Day to day, the role involves coordinating rapid containment and recovery efforts, managing forensic investigations, producing executive-level reporting,

Digital Forensics SME

The Role This position involves conducting advanced forensic investigations across endpoints, networks, and digital media, identifying root causes of cybersecurity incidents and supporting remediation efforts. Responsibilities include malware analysis, phishing investigation, chain-of-custody evidence handling, IOC development, threat intelligence reporting, and

Information Security Forensic Analyst

The Role This position centres on host and network forensic analysis in support of a 24/7 security operations environment. Day to day, the analyst leads incident triage, conducts forensic examinations of digital evidence, correlates findings with network events, and produces

Digital Forensics Analyst

The Role This position sits within a Diplomatic Security Cyber Mission Program, where the analyst conducts forensic examinations across mobile devices, computers, removable media, and cloud sources. Responsibilities include collecting and preserving evidence during warrant executions, producing detailed reports, delivering

Digital Forensics SME

The Role This senior position involves leading digital forensics efforts in support of federal law enforcement investigations, cybercrime cases, and national security missions. Day to day, the work spans conducting advanced forensic analysis, designing investigative workflows, preparing technical reports, and

Digital Forensics Consultant (PST hours)

The Role This position involves conducting forensic collections of electronically stored information from computers, mobile devices, servers, cloud repositories, and other digital sources, both onsite and remotely. Consultants analyse data to support investigations and litigation, produce detailed reports and declarations,

Digital Forensic Analyst I with Security Clearance

The Role This full-time position centres on the forensic preservation and collection of mobile device and cloud-stored data, both on-site and remotely. The analyst liaises with legal teams and client IT departments, maintains chain of custody, performs quality checks on

Digital Forensics Consultant (PST hours)

The Role This position involves conducting forensic collections of electronically stored information from computers, mobile devices, servers, cloud platforms, and other digital sources, both on-site and remotely. Day-to-day work includes forensic analysis supporting investigations and litigation, preparing detailed reports and

Digital Forensics Analyst

The Role This position supports criminal investigations within a law enforcement forensics unit, handling the acquisition, preservation, and analysis of digital evidence from computers, mobile devices, and storage media. Responsibilities include preparing technical reports, maintaining chain of custody, attending scenes,

Senior Security Engineer, Digital Forensics

The Role This position involves conducting digital forensic investigations, performing security assessments, and monitoring systems for threats and intrusions. Engineers work hands-on with network infrastructure, collaborate with software engineering teams on proactive security measures, and help maintain hardened, resilient environments

Digital Forensics Analyst

The Role This analyst supports Department of Defense operations through digital forensic investigations, malware analysis, incident response, and vulnerability assessments conducted within secure, classified environments. Day-to-day work involves network analysis, static and dynamic application security testing, and reverse engineering of

Forensic Computer Analyst

The Role This position involves conducting forensic examinations of digital and multimedia evidence using scientific methodologies, producing detailed reports and exhibits, providing expert witness testimony in federal and state proceedings, advising on evidence collection and preservation at crime scenes, and

Digital Forensic Examiner 1

The Role This entry-level position supports law enforcement digital investigations by examining electronic devices, recovering deleted or damaged files, and helping document evidence for criminal cases. Examiners also assist investigators at crime scenes, support network systems used in online investigations,

Digital Forensics / Malware Analyst

The Role This position involves conducting digital forensic investigations and malware analysis in support of a Federal information security programme. Day-to-day work includes acquiring and examining evidence from endpoints, servers, cloud environments, and removable media, reverse engineering malicious software, maintaining

Senior Digital Forensics Automation SME

The Role This position focuses on analysing, designing, and maintaining automated digital forensics workflows for a federal government customer. Day to day, the specialist identifies process bottlenecks, builds scalable solutions to reduce case backlogs, and ensures forensic methodologies are thoroughly

Digital Forensics Consultant (Onsite in San Francisco Lab)

The Role This position centres on conducting forensically sound collections of electronically stored information from computers, mobile devices, servers, cloud repositories, and other digital sources. Day to day, the consultant performs forensic analysis supporting investigations and litigation, prepares detailed written

Digital Forensics Analyst (Cyber Analyst III) TS/SCI

The Role This position supports sensitive military, intelligence, and counterintelligence missions by conducting forensic examinations and digital exploitation. Day-to-day work includes preserving, analysing, and cataloguing digital evidence, documenting forensic artefacts to established standards, and evaluating software tools used in data

Associate Principal/Digital Forensics (Forensic Services practice)

The Role This senior-level position leads digital forensic investigations, primarily focused on trade secret theft matters. Day-to-day work includes directing onsite data collection, performing forensic analysis across multiple operating systems and mobile platforms, remediating data, and occasionally providing expert witness

Tier II-III Incident Response Analyst-Senior

The Role This senior position leads advanced cybersecurity incident investigations, coordinating responses to high-impact security events. Day-to-day responsibilities include conducting in-depth forensic analysis, reviewing suspicious code, performing malware analysis, hunting for threats, and gathering cyber threat intelligence across client environments.

Senior Forensic Analyst

The Role The analyst conducts independent forensic evaluations of federal enterprise systems suspected of compromise, performing both host and network analysis under strict legal chain of custody requirements. Each engagement is unique and fixed-duration, with findings that inform immediate incident

Digital Forensic Analyst I with Security Clearance

The Role This position centres on the forensic preservation and collection of mobile device and cloud-stored data, conducted both on-site and remotely. Day-to-day work includes liaising with legal teams and client IT departments, maintaining chain of custody, contributing to documented

Digital Forensics and Incident Analyst (TS)

The Role This position supports threat analysis and investigations by examining digital evidence and responding to computer security incidents at Tier 2 and Tier 3 levels within an enterprise SOC environment. The analyst collects, preserves, and examines evidence using documented

Forensic Computer Analyst

The Role This position involves conducting forensic examinations of digital and multimedia evidence in support of criminal and administrative investigations. Day-to-day work includes analysing electronic evidence, producing detailed reports, preparing exhibits for court proceedings, and providing expert witness testimony at

Digital Analyst

The Role This position sits within a police department’s Computer Forensics unit and centres on the collection, preservation, analysis, and documentation of digital evidence in support of criminal investigations. The analyst responds to requests from investigators, assists other divisions as

Senior Forensic Developer

The Role This position centres on designing and building specialised forensic software for federal cybercrime and digital evidence investigations. Day to day, you architect low-level capabilities covering file system parsing, memory analysis, binary dissection, and investigative workflow automation, collaborating with

Digital Forensics Analyst

The Role This position supports federal law enforcement by conducting digital forensic examinations in a lab environment. Day-to-day work includes seizing and imaging devices, executing on-scene support during search warrants, analysing evidence, producing detailed reports, and providing expert witness testimony

Digital Forensics and Incident Response, Senior Manager

The Role This senior leadership position oversees multiple incident response teams, directing complex digital forensic investigations and cybersecurity incident response engagements. The role involves advising during high-severity incidents, communicating findings to executives and legal stakeholders, managing team performance, and supporting

Lead Cyber Defense Forensics Analyst

The Role This onsite position within a classified government facility leads complex digital forensic investigations at the senior practitioner level. Day to day, the analyst conducts forensic examinations, supports incident response analysis, contributes to threat hunt operations, and sets the

Digital Forensics SME

The Role This senior position involves delivering advanced digital forensics support to federal law-enforcement and cybercrime investigations. Day to day, the practitioner conducts complex forensic analysis, designs investigative workflows, prepares technical reports, and collaborates with multidisciplinary teams including cryptocurrency analysts

Digital Analyst

The Role This position sits within a law enforcement computer forensics unit and centres on the collection, preservation, analysis, and documentation of digital evidence in support of criminal investigations. The analyst responds to requests from investigators, collaborates with prosecutors on

Digital Forensics Analyst

The Role This position supports a Special Operations Forces logistics programme at Fort Bragg, NC, requiring an active Top Secret/SCI clearance. The analyst applies digital forensics expertise to mission-critical national security work, contributing to the operational readiness of U.S. Special

Police Digital Forensic Analyst

The Role This position centres on the extraction, examination, and forensic preservation of digital evidence across a range of electronic platforms. The analyst supports criminal investigations through technical data analysis, prepares evidentiary materials for court, and regularly delivers expert testimony

Digital Forensics Senior Examiner

The Role This position sits within a police department’s forensic services section, where the examiner conducts digital forensic investigations in support of criminal cases. Day-to-day work includes examining digital devices, processing digital evidence, and responding to on-call callouts, which may

Digital Forensics & eDiscovery Manager

The Role This position leads digital forensic investigations, ESI preservation, eDiscovery processes, and information governance functions within a legal and compliance team. The individual serves as the primary subject-matter expert and escalation point, supporting litigation, internal investigations, and forensic advisory

Digital Forensics Analyst

The Role This position involves conducting digital forensic examinations in a law enforcement laboratory environment, supporting federal investigations. Day-to-day work includes acquiring and imaging digital devices, attending search warrant executions, analysing evidence using specialist tools, producing detailed reports, and occasionally

Digital Forensic Examiner

The Role This position involves conducting forensic examinations of electronic devices such as computers, smartphones, tablets, and digital storage media. The examiner collects, preserves, and documents digital evidence following chain of custody procedures, recovers data from damaged or encrypted devices,

Senior Consultant, Digital Forensic and Incident Response (DFIR) (Remote)

The Role This fully remote position sits within a collaborative incident response team, where the successful candidate leads and supports investigations into cyber incidents including ransomware, business email compromise, malware, and data theft, conducting forensic analysis and delivering clear, high-quality

Digital Forensics & Incident Response Analyst

The Role This position supports Department of Defense cyber operations in the Fayetteville, North Carolina area, requiring hands-on work across digital forensic investigations, malware analysis, incident response, and vulnerability assessments within classified, secure environments on a day-to-day basis. Skills &

Host Forensic Analyst/Host Based Systems Analyst

The Role This position involves leading and coordinating host-based forensic investigations at onsite engagements, collecting and analysing digital evidence, evaluating suspected malicious code, and communicating findings through executive summaries and detailed technical reports to both senior leadership and external stakeholders.

Digital Forensics Consultant

The Role This position supports litigation matters by preserving, collecting, and analysing digital evidence from computers, mobile devices, servers, and cloud accounts. Day-to-day work includes forensic imaging, chain of custody documentation, artifact analysis, deleted data recovery, and contributing to expert

Computer Forensic Examiner

The Role Examiners lead forensic investigations—primarily ransomware and business email compromise cases—identifying points of compromise, potential data exfiltration, and indicators of compromise. Work spans Windows, Linux, VMware, ESXi, and firewall environments, and includes applying data recovery techniques and producing written

Cyber Analyst, Digital Forensics Incident Response

The Role Analysts conduct end-to-end incident response engagements for insured businesses, including forensic evidence collection, compromise analysis, timeline reconstruction, and root cause identification. Responsibilities also extend to threat actor negotiations, recovery support, report writing, and delivering tailored training and simulations

Digital Forensic Examiner

The Role This full-time position involves collecting, processing, and exploiting digital media seized in operational environments, including computers, mobile devices, removable storage, GPS units, DVRs, and UAVs. The examiner conducts forensically sound data acquisition, produces detailed exploitation reports, and coordinates

AOUSC – Digital Forensics Analyst

The Role This hybrid position, based in Washington, DC, supports a federal judiciary programme. Analysts conduct digital forensic examinations, performing disk, memory and registry analysis, applying industry-standard tools to investigate and preserve digital evidence in accordance with federal guidelines and

Digital Forensics Analyst

The Role This position sits within a law enforcement forensics unit, supporting criminal investigations through the acquisition, preservation, and analysis of digital evidence from computers, mobile devices, and storage media. Responsibilities include maintaining chain of custody, preparing technical reports, assisting

Digital Forensic Technician

The Role This position involves identifying, extracting, and recovering digital evidence from a wide range of electronic devices to support criminal investigations within a Sheriff’s Office. The technician maintains chain of custody procedures and may be called upon to testify

Forensic Computer Analyst SR

The Role This senior-level position involves conducting forensic examinations of digital and multimedia evidence in support of criminal and administrative investigations. Day-to-day responsibilities include analysing electronic evidence, producing detailed reports, providing expert witness testimony in federal and state proceedings, and

Digital Forensic Analyst

The Role Analysts conduct forensic examinations of digital devices and data sources — including mobile devices, computers, cloud services, and removable media — producing detailed reports, supporting search warrant executions, providing expert witness testimony, and mentoring colleagues while maintaining rigorous

Computer Forensic Examiner

The Role This position involves conducting end-to-end digital forensic examinations, from collection and imaging through analysis and reporting, across computers, mobile devices, and digital media. The examiner manages complex caseloads independently, maintains rigorous chain of custody, and presents defensible findings

Digital Forensics Investigator – Vice President

The Role This position leads end-to-end digital forensic investigations and eDiscovery activities within an Insider Risk Management function, supporting incident response, litigation, regulatory matters, and employee investigations. The investigator engages daily with senior stakeholders across Legal, HR, Compliance, and Cyber

Cyber Crime Analyst 1/2

The Role This position sits within a state law enforcement crime laboratory, where analysts conduct digital forensic examinations, support cyber threat investigations, assist with incident response, and perform technical analysis to help identify and combat cybercrime alongside experienced investigators on

Cyber Crime Investigator

The Role This on-site position supports sensitive counterintelligence and counterterrorism investigations by conducting digital forensic examinations, acquiring and analysing digital evidence, and performing operational security assessments. The work includes research, technology evaluation, training activities, and maintaining rigorous chain-of-custody and evidentiary

Digital Forensics Investigator/Sheriff

The Role This position serves as the primary digital evidence specialist for a county sheriff’s office, conducting forensic examinations of computers, mobile devices, storage media, and cloud data. The investigator prepares expert reports, maintains chain of custody, assists with warrants,

Senior Forensic Examiner

The Role This on-site position involves conducting advanced forensic examinations across mobile devices, computers, cloud accounts, and multimedia files. Day to day, the examiner plans and executes forensic strategies, maintains chain of custody, prepares technical reports for legal teams, mentors

Digital Forensic Analyst

The Role This position sits within a police department’s detective unit, where the analyst processes and examines digital evidence, produces detailed forensic reports, correlates data from multiple sources, liaises with investigators and prosecutors, and provides court testimony when required. Skills

Senior Digital Forensics Incident Response Analyst (DoD TS/SCI Clearance)

The Role This position involves leading real-time and historical investigations into security incidents, conducting forensic imaging, host and network analysis, and memory analysis. Analysts triage incidents, reconstruct attacker activity including lateral movement and exfiltration, and perform both static and dynamic

Digital Forensics and Incident Response Analyst Mid-Level

The Role This mid-level position involves conducting digital forensic investigations, responding to security incidents, and performing proactive threat hunting across endpoints, firewalls, and servers. Day-to-day work includes malware analysis, network traffic examination, evidence preservation, forensic duplication, and contributing to post-incident

Digital Forensic Examiner

The Role This position involves the forensic preservation, collection, and analysis of digital evidence from computers, mobile devices, email platforms, and cloud-based systems. The examiner manages cases independently from scoping through completion, maintains detailed documentation, coordinates with internal teams, and

Senior Digital Forensics Engineer

The Role This position supports a Pentagon-based Security Operations Centre, conducting forensic examinations of digital devices and analysing potentially malicious code during active investigations. Findings are documented in clear, professional reports that inform defensive measures and feed into the broader

Digital Forensic Specialist

The Role This civilian position within a law enforcement Evidence Division supports investigative operations through digital evidence processing, retention, and crime analysis. Day-to-day work includes operating and maintaining the digital forensics laboratory, attending crime scenes to collect or triage digital

Senior Director of Digital Forensics & Incident Response

The Role This senior leadership position oversees a 24x7x365 global security operations centre, directing enterprise-wide incident response and digital forensic investigations. The role involves shaping multi-year strategy, managing global teams across DFIR and related functions, and advising executive leadership during

Digital Forensic Examiner

The Role The examiner conducts forensically sound acquisition and exploitation of a wide range of digital media, including computers, mobile devices, removable storage, GPS units, DVRs, and UAVs. Responsibilities include triaging Collected Exploitable Material, generating detailed forensic reports, and coordinating

Senior Digital Forensics Analyst

The Role This senior position involves conducting in-depth forensic examinations of digital evidence across mobile devices, computers, servers, cloud environments, and storage media. The analyst applies recognised scientific best practices to collect, analyse, and interpret digital evidence in support of

E-Discovery & Digital Forensics Lead (Legal Operations)

The Role This position supports legal, HR, and corporate investigations teams by conducting end-to-end forensic examinations, including data acquisition, analysis, and presentation of findings through written reports, visual aids, affidavits, and sworn testimony, while coordinating with outside counsel and technology

Senior Director, Digital Forensics and Incident Response

The Role This senior leadership position involves commanding complex cyber investigations end-to-end, from initial response through containment and recovery. Day to day, the role spans ransomware, business email compromise, cloud and identity compromise, and insider threat investigations, alongside executive briefings,

Senior Digital Media Forensic Analyst (Contingent)

The Role This on-site position supports U.S. Army Counterintelligence and Counterterrorism operations through the full forensic examination lifecycle, encompassing evidence acquisition, deep-dive analysis, and pre-trial reporting. Responsibilities extend to incident response, mobile device extraction, memory forensics, anti-forensic detection, and delivering

Digital Forensics and Incident Response (DFIR) Consultant

The Role This position involves responding to active cyber incidents, conducting forensic acquisition and analysis of physical and virtual systems, reviewing host and appliance logs, correlating events into timelines, and applying mitigation strategies to contain and remediate threats such as

Digital Media Forensics Analyst Expert

The Role This onsite position at Fort Meade, Maryland involves providing digital forensic and cyber analytical support to counterintelligence and counterterrorism investigations. Day-to-day work includes recovering and analysing electronic data from digital media, conducting security assessments, evaluating emerging forensic technologies,

Lateral Digital Forensics Unit (DFU) Detective

The Role Detectives in this unit recover, analyse, and preserve electronic evidence as their primary daily responsibility, working a four-day schedule with periodic on-call duties averaging one week per month. They also contribute to patrol staffing when operationally required and

Senior Digital Forensic Analyst

The Role The analyst conducts forensic examinations of digital evidence across a range of sources, including mobile devices, computers, removable media, and cloud platforms. Work is performed in support of criminal, civil, and administrative investigations, with examinations carried out in

Incident Response and Forensic Analyst

The Role This position leads the full lifecycle of cybersecurity incident response, from initial detection through containment, eradication, and recovery. Day to day work includes conducting digital forensic investigations on compromised systems, analysing disk images, memory dumps, and network traffic,

Digital Forensics and Incident Response Analyst

The Role This senior-level position leads investigations into high-priority cybersecurity incidents, conducting in-depth forensic analysis and coordinating response efforts across teams. The analyst serves as an escalation point for junior colleagues, liaises with law enforcement and third-party vendors, develops detection

Digital Forensics Examiner

The Role This position supports a Department of Defense customer from a Lorton, VA office, conducting hands-on examination of computers, mobile devices, storage media, and other electronic devices. Day-to-day work encompasses digital evidence preservation, forensic analysis, electronic discovery, and contributing

Principal Consultant, Cloud DFIR (Unit 42) – Remote

The Role This senior individual contributor position focuses on leading cloud-focused incident response and digital forensics investigations across AWS, Azure, GCP, and hybrid enterprise environments. Day to day involves acting as technical lead on active security incidents, scoping breaches, containing

Senior Investigator Digital Forensics, Incident Response (DFIR)

The Role This senior-level position involves leading complex digital forensic investigations and incident response engagements across cloud, OT, and enterprise environments. Day-to-day responsibilities include memory forensics, malware triage, threat hunting, log analysis, timeline development, and mentoring junior investigators across concurrent

Tier 3 Digital Forensics and Incident Response Analyst

The Role This senior-level position leads investigations into high-priority cybersecurity incidents, coordinating cross-functional teams and serving as the primary escalation point for junior analysts. Day-to-day responsibilities include alert triage, root cause analysis, detection rule tuning, threat research, post-incident review, and

Digital Media Forensics SME

The Role This position involves conducting comprehensive digital media forensic examinations, including evidence acquisition, imaging, analysis, and reporting in support of national security missions. Day-to-day work spans on-site and off-site investigations, maintaining chain-of-custody integrity, developing advanced forensic workflows, mentoring junior

Sr. Digital Forensics & eDiscovery Engineer, Security Intelligence

The Role This position leads complex insider threat investigations across endpoints, cloud environments, and network infrastructure, conducting forensically sound evidence acquisition and deep-dive artifact analysis. The engineer also manages eDiscovery matters end-to-end, serving as the primary technical liaison between Security,

Cyber Incident Responder/ Forensic Analyst

The Role This position centres on investigating cyber incidents through the analysis of logs, endpoint artifacts, and network data. Day to day, the analyst collects and preserves digital evidence, documents findings and timelines, and supports containment and remediation efforts, coordinating

Digital Forensic Lab Analyst (DFL Analyst)

The Role This position sits within a prosecutor’s digital forensics laboratory, where analysts review and interpret evidence extracted from mobile devices, computers, and storage media. Daily tasks include analysing call detail and cell site records, performing redactions in Cellebrite and

Digital Forensics Examiner

The Role Working across laboratory, remote, and on-site environments throughout the United States, the examiner collects and preserves digital evidence, conducts forensic acquisitions, performs artifact and timeline analysis, recovers deleted data, and produces clear, defensible reports for attorneys, investigators, and

Digital Forensics Lead (#26-091)

The Role This hybrid position supports a federal health research agency’s cybersecurity team, leading and conducting digital forensics investigations across agency systems and devices. Day-to-day responsibilities include maturing the organisation’s forensics programme and delivering clear, actionable investigation reports to senior

DIGITAL FORENSICS EXAMINER CELLEX/MEDEX

The Role This position involves conducting digital forensic examinations across a range of media types, supporting USSOCOM through both stateside and overseas deployments, including in hostile fire environments. Responsibilities include sensitive site exploitation, producing technical reports, briefing stakeholders, and designing

Digital Forensic Examiner II

The Role This position involves extracting and analysing digital evidence from mobile phones, tablets, GPS devices, computers, and storage media. Examiners document their methodology and findings, validate results using multiple tools, perform data recovery, and are expected to present their

Digital Forensics Analyst

The Role This full-time, on-site position involves conducting forensic acquisition and analysis across computers, mobile devices, IoT hardware, cloud environments, and non-standard media. Daily work includes capturing volatile data, reviewing evidentiary artefacts, producing reports for both technical and executive audiences,

Cyber Defense Forensics Analyst

The Role This position sits within a global cyber defense function, serving as a senior escalation point during suspect or confirmed security incidents. Day to day involves conducting digital forensic analysis, supporting incident response activities, performing malware analysis, and identifying

Cyber Forensic Specialist

The Role This position sits within a Digital Forensics and Incident Response team, where the specialist investigates cybersecurity incidents, performs device forensic analysis, manages evidence intake and processing, executes litigation holds, supports eDiscovery captures, and collaborates with HR, Legal, and

Digital Forensics Examiner

The Role This position involves examining electronic media — including hard drives, storage devices, mobile phones, and other digital devices — in support of sensitive criminal investigations for a federal government agency. Examiners apply forensic tools and analytical techniques to

IBM CISO – Cybersecurity Forensic Analyst

The Role This position sits within a global cybersecurity incident response team, conducting forensic investigations across endpoint, network, and cloud environments. Day to day, analysts collect and preserve digital evidence, support triage and containment activities, and correlate forensic findings with

Lead Digital Investigations Engineer

The Role This position involves conducting digital investigations across a range of scenarios including cybersecurity incidents, insider threats, and policy violations. Day-to-day work includes collecting, preserving, analysing, and documenting digital evidence from endpoints, servers, mobile devices, cloud environments, network sources,

Senior Investigations Analyst – Digital Forensics

The Role This position leads forensically sound investigations into security incidents, policy violations, and potential litigation matters. Day to day involves acquiring and preserving digital evidence from workstations, mobile devices, cloud environments, and server logs, then analysing large datasets to

Digital Forensics Examiner

The Role This onsite position supports federal criminal investigations by examining computers, mobile devices, and storage media for digital evidence. Day-to-day work includes forensic analysis, data recovery, evidence preservation, and producing detailed reports suitable for courtroom use, with the possibility

Junior Digital Forensic Analyst

The Role This position supports a federal cyber program by conducting forensic examinations of digital media, including mobile devices and storage drives. Day to day, the analyst recovers and analyzes digital evidence for criminal, cyber, and administrative investigations, ensuring all

Senior Investigations Analyst – Digital Forensics

The Role This position leads complex digital investigations across the enterprise, conducting forensically sound examinations of security breaches, policy violations, and litigation matters. Day-to-day work involves acquiring and preserving digital evidence from endpoints, mobile devices, cloud environments, and server logs,

Digital Forensics Cybersecurity Advisor

The Role This position supports a federal health research agency by advising on cybersecurity strategy and conducting digital forensics investigations. Day-to-day work involves examining physical and virtual assets, investigating security incidents across Windows, macOS, and iOS environments, and presenting findings

Cyber Forensics Analyst

The Role This position supports security operations through hands-on digital forensics, malware analysis, and incident response. Day to day, analysts examine endpoints, servers, memory, and file system artifacts, develop indicators of compromise, produce clear technical findings, and collaborate with SOC

Digital Forensics Analyst ( Python, Splunk, Arcsight)

The Role This position involves conducting digital media acquisition and forensic analysis across an enterprise network environment, supporting incident response efforts and a range of case types including insider threat, malware, and digital misuse. Day-to-day work includes evidence recovery, data