Mid-Level Forensics Analyst

Posted 2 Days Ago
Be an Early Applicant
Portland, OR, USA
In-Office
Mid level
Security • Cybersecurity
The Role
Perform hands-on digital forensic acquisitions and analysis on endpoints, servers, and removable media. Preserve evidence, analyze disk/memory/artifacts, identify IOCs, support incident response, produce forensic reports, and improve forensic processes while collaborating with senior staff, legal, and incident response teams.
Summary Generated by Built In




Position Title: Mid-Level Digital Forensics Analyst

Location:Portland, OR | Full-Time                                               

Cybervance is a rapidly growing information security and information technology company based in Washington, D.C., and we are an equal opportunity employer.

Cybervance combines advanced cybersecurity expertise with proven federal contracting experience to deliver innovated, mission-focused solutions for U.S. Government agencies. We are committed to helping our partners achieve measurable improvements in security and resilience.

We are seeking a full-time Mid-Level Digital Forensics Analyst who supports and conducts digital forensic investigations related to cybersecurity incidents, insider threats, data loss, and policy or regulatory inquiries. This role performs hands‑on forensic analysis under established methodologies while working closely with senior forensics staff, incident response teams, and legal or compliance stakeholders.

The ideal candidate has practical forensic experience, strong attention to evidentiary detail, and the ability to independently analyze systems while escalating complex findings appropriately.

Responsibilities

  • Conduct forensic analysis on endpoints, servers, and removable media.
  • Acquire, preserve, and analyze digital evidence in accordance with forensic best practices.
  • Perform disk, memory, and artifact analysis to identify user activity, malware, or unauthorized access.
  • Support investigations involving security incidents, insider activity, and data exfiltration.
  • Assist incident response teams with forensic scoping, timeline creation, and root cause analysis.
  • Analyze forensic artifacts to determine attack vectors, persistence mechanisms, and impact.
  • Identify indicators of compromise (IOCs) and support remediation efforts.
  • Maintain proper evidence handling and chain‑of‑custody documentation.
  • Produce clear forensic notes, findings, and supporting artifacts.
  • Contribute to forensic and incident reports used by technical, legal, or leadership teams.
  • Utilize forensic tools for data acquisition, analysis, and reporting.
  • Perform artifact validation and cross‑verification to ensure analytical accuracy.
  • Support improvements to forensic workflows and repeatable procedures.
  • Work closely with senior forensic analysts and incident responders.
  • Participate in tabletop exercises, incident reviews, and training activities.
  • Continue skill development in forensic techniques, tools, and emerging technologies.                                                                                                                                                            Required Skills & Qualifications
  • 3–5 years of experience in digital forensics, incident response, or cybersecurity analysis.
  • Hands‑on experience performing forensic acquisitions and analysis.
  • Solid understanding of:
    • Windows and Linux operating systems
    • File systems, logs, and system artifacts
    • Common attacker behaviors and malware indicators
  • Strong documentation and written communication skills.
  • Ability to follow evidence handling and legal defensibility requirements.

Preferred Qualifications

  • Experience with memory forensics, log correlation, or malware triage.
  • Familiarity with cloud, SaaS, or email forensics (e.g., M365, cloud platforms).
  • Scripting or automation experience (Python, PowerShell, Bash).
  • Certifications such as GCFA, GCIH, CHFI, EnCE, or equivalent.
  • Experience in regulated, enterprise, or government environments.

Skills Required

  • 3-5 years of experience in digital forensics, incident response, or cybersecurity analysis
  • Hands-on experience performing forensic acquisitions and analysis
  • Solid understanding of Windows operating systems
  • Solid understanding of Linux operating systems
  • Knowledge of file systems, logs, and system artifacts
  • Knowledge of common attacker behaviors and malware indicators
  • Strong documentation and written communication skills
  • Ability to follow evidence handling and legal defensibility requirements
  • Experience with memory forensics, log correlation, or malware triage
  • Familiarity with cloud, SaaS, or email forensics (e.g., M365, cloud platforms)
  • Scripting or automation experience (Python, PowerShell, Bash)
  • Certifications such as GCFA, GCIH, CHFI, EnCE, or equivalent
  • Experience in regulated, enterprise, or government environments
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Kensington, , Maryland
29 Employees
Year Founded: 2019

What We Do

Cybervance has a long history of supporting USG agencies in areas related to international capacity building programs. From foreign assistance capacity building to collaboration with partner nations, Cybervance services are comprehensive and turnkey. We provide initial assessments and planning, training across multiple cyber disciplines, equipment installations, operational support and mentoring. All of Cybervance’s services are supported by insightful reporting for program stakeholders needing to stay informed about key issues in plain English, not cyber-speak. Our logistics function handles everything needed for program success, including all equipment procurements, shipping, customs and duties processing, travel, and in-country event support. Our services are tailored for international delivery. Our team is adept at making in-country, real-time adjustments to address regional and situational dynamics. We understand that cyber programming is part of a larger diplomatic mission, and we focus on achieving tangible programming results. With an extensive background in law enforcement, our team brings specialized service delivery to cyber-related programs with a criminal or counterterrorism nexus.

Similar Jobs

Hybrid
Portland, OR, USA
205000 Employees
Hybrid
Bend, OR, USA
205000 Employees
Hybrid
Tigard, OR, USA
205000 Employees

Cox Enterprises Logo Cox Enterprises

Human Resources Business Partner

Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Remote or Hybrid
United States
50000 Employees
67K-101K Annually

Similar Companies Hiring

Oso Thumbnail
Software • Security • Infrastructure as a Service (IaaS)
New York, New York
36 Employees
Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account