Digital Forensics Incident Response Lead
What Your Day-To-Day Looks Like (Position Responsibilities):
-
Lead CFL Digital Forensics and Incident Response activities.
-
Manage intrusion analysis and incident response personnel.
-
Direct network intrusion analysis, malware forensics, and memory analysis.
-
Lead intrusion investigations and monitor investigative quality and efficiency.
-
Analyze advanced persistent threat activity.
-
Correlate findings from host forensics, network logs, and threat intelligence.
-
Brief technical findings to Government leadership.
-
Ensure all intrusion and incident response activities comply with the PWS.
-
Serve as the primary Government technical point of contact for intrusion analysis and incident response.
-
Proactively identify and communicate technical, programmatic, and resource limitations.
What You Need to Succeed (Minimum Requirements):
-
TS/SCI clearance eligible .
-
Active DFE, GCFA, GIAC Certified Incident Handler (GCIH), or equivalent certification approved by the COR.
-
At least seven years of hands-on Digital Forensics and Incident Response experience, including at least five years focused on network intrusion analysis, malware forensics, and memory analysis.
-
At least three years of leadership or supervisory experience within the last five years leading intrusion investigations, managing incident responders, and briefing technical findings to leadership.
-
Demonstrated experience within the last three years analyzing advanced persistent threat activity and correlating findings across host forensics, network logs, and threat intelligence.
Source: the employer's careers page. Last checked 2026-10-09. Posted 2026-10-07.