Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

FileImport - Booz Allen Hamilton

Digital Forensics Analyst SME

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
78
out of 100
Average of individual scores

Were these scores useful?

Job Description

Digital Forensics Analyst SME

Job Number:
R0249674
Digital Forensics Analyst SMEThe Opportunity:

Serve as a key member of a 24x7x365 Security Operations Center and Incident Response team, responsible for conducting evidence collection, forensic analysis, data recovery, and reporting in response to incident investigations. The role performs handson digital forensics activities such as forensic imaging, analysis of physical and virtual drives, and incident documentation while leveraging FRED's and forensic tools to capture and preserve evidence for security events. The analyst contributes to the development forensics playbooks and standard operating procedures, conducts ad-hoc forensic analysis, and supports the SOC with investigating security events. This position collaborates closely with federal stakeholders, communicates findings to technical and nontechnical audiences, and produces highquality reports and briefings, all while helping to advance the maturity and effectiveness of the organization's security operations.



Join us. The world can't wait.

You Have:

2+ years of experience in a Security Operations Center (SOC) providing forensic analysis, imaging, log and evidence analysis or preservation, chain-of-custody, incident documentation, and coordination with Federal stakeholdersExperience analyzing and responding to forensic security requests across enterprise host including Linux, Windows, or macOS and network-based platformsExperience developing or contributing to evidence collection, examination, and chain-of-custody documentation or standard operating proceduresExperience using Splunk SIEM platform to support investigations and evidence enrichmentExperience using a forensic recovery of evidence device (FRED) to collect, store, and maintain forensic imagesExperience with malware analysis and reverse engineeringAbility to analyze and correlate data from multiple technical sources to identify malicious activity, artifacts, indicators, or investigative leadsAbility to communicate clearly with both technical and non-technical audiences, including the production of highquality incident reports, briefings, and technical documentationPublic TrustBachelor's degree

Nice If You Have:

Experience using industry forensic suites and toolsets such as EnCase, FTK, X-Ways, Cellebrite, Autopsy, KAPE, or VelociraptorExperience performing volatile memory acquisition and analysis Experience with cloud forensics methodologies such as AWS, Azure, or GCP including log acquisition and artifact preservationExperience with federal security controls such as NIST 80053, RMF, or FedRAMP and impact on investigative activitiesAbility to build strong client relationships, collaborate across varied teams, and communicate complex technical concepts in a clear, inclusive mannerDFIR Certifications such as

GIAC, GCFA, GCFE, GCIH, CFCE, IACIS, and EnCase EnCE CertificationsVetting:

Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client; Public Trust determination is required.



CompensationAt Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to ...For full information see follow application link. Commitment to Non-Discrimination - All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.

Benefits

  • Paid Time Off (PTO)
  • Financial Aid/Assistance
  • Professional Development
  • Other Retirement and Savings