The Cyber Defense Forensics Lead provides expert leadership for digital forensics and advanced cyber investigations in support of CBP security operations. This role focuses on identifying, analyzing, and responding to cyber incidents, insider threats, and advanced persistent threats using industry‑leading forensic and monitoring techniques across classified and unclassified environments.
This role is ideal for a forensic leader who thrives on solving complex cyber incidents and uncovering the truth behind advanced threats. As the Cyber Defense Forensics Lead, you’ll be at the forefront of protecting national security systems—leading high‑impact investigations, responding to sophisticated adversaries, and guiding teams through complex digital forensics challenges. You’ll have the autonomy to shape investigative approaches, mentor analysts, and directly influence how threats are detected and neutralized across a large federal enterprise.
What You'll Do:
- Lead digital forensics investigations and advanced incident analysis
- Conduct host‑based and network‑based security monitoring and evidence collection
- Develop forensic dashboards, reports, and investigative workflows
- Direct response activities for high‑impact security incidents
- Train and mentor junior forensic and SOC analysts
What You Have:
- US Citizenship is Required
- Minimum 7 years of professional cybersecurity or digital forensics experience
- At least 5 years hands‑on experience with forensic analysis, SIEM, IDS/IPS, and EDR tools
- Experience with insider threat investigations and advanced threat analysis
- CISSP certification required
- Ability to obtain and maintain TS (SCI‑eligible) clearance
What We Offer:
- 401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed
- Medical, Dental, and Vision Insurance (available on the 1st day of the month following your first day of employment)
- Group Term Life, Short-Term Disability, Long-Term Disability
- Voluntary Life, Hospital Indemnity, Accident, and/or Critical Illness
- Participation in the Discretionary Time Off (DTO) Program
- 11 Paid Holidays Annually
Top Skills
What We Do
Unified Security Operations, Delivered. We tear down the walls between red and blue teams & address risk exposure when it’s discovered—not weeks later. UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as- code platform combines technology innovation and human expertise to make advanced real time cybersecurity accessible for all organizations by eliminating risks of separate red and blue teams. By creating continuously optimized identification, detection and resilience from today’s dynamic threat landscape, UltraViolet Cyber provides both managed and custom-tailored unified security operations solutions to the Fortune 500, Federal Government, and Commercial clients. UltraViolet Cyber is headquartered in McLean, Virginia with global offices across the U.S. and in India.







