Digital Forensics Analyst SME

Booz Allen HamiltonBethesda, MD
Remote

About The Position

Serve as a key member of a 24x7x365 Security Operations Center and Incident Response team, responsible for conducting evidence collection, forensic analysis, data recovery, and reporting in response to incident investigations. The role performs hands‑on digital forensics activities such as forensic imaging, analysis of physical and virtual drives, and incident documentation while leveraging FRED’s and forensic tools to capture and preserve evidence for security events. The analyst contributes to the development forensics playbooks and standard operating procedures, conducts ad-hoc forensic analysis, and supports the SOC with investigating security events. This position collaborates closely with federal stakeholders, communicates findings to technical and non‑technical audiences, and produces high‑quality reports and briefings, all while helping to advance the maturity and effectiveness of the organization’s security operations.

Requirements

  • 2+ years of experience in a Security Operations Center (SOC) providing forensic analysis, imaging, log and evidence analysis or preservation, chain-of-custody, incident documentation, and coordination with Federal stakeholders
  • Experience analyzing and responding to forensic security requests across enterprise host including Linux, Windows, or macOS and network-based platforms
  • Experience developing or contributing to evidence collection, examination, and chain-of-custody documentation or standard operating procedures
  • Experience using Splunk SIEM platform to support investigations and evidence enrichment
  • Experience using a forensic recovery of evidence device (FRED) to collect, store, and maintain forensic images
  • Experience with malware analysis and reverse engineering
  • Ability to analyze and correlate data from multiple technical sources to identify malicious activity, artifacts, indicators, or investigative leads
  • Ability to communicate clearly with both technical and non-technical audiences, including the production of high‑quality incident reports, briefings, and technical documentation
  • Public Trust

Nice To Haves

  • Experience using industry forensic suites and toolsets such as EnCase, FTK, X-Ways, Cellebrite, Autopsy, KAPE, or Velociraptor
  • Experience performing volatile memory acquisition and analysis
  • Experience with cloud forensics methodologies such as AWS, Azure, or GCP including log acquisition and artifact preservation
  • Experience with federal security controls such as NIST 800 ‑ 53, RMF, or FedRAMP and impact on investigative activities
  • Ability to build strong client relationships, collaborate across varied teams, and communicate complex technical concepts in a clear, inclusive manner
  • DFIR Certifications such as GIAC, GCFA, GCFE, GCIH, CFCE, IACIS, and EnCase EnCE Certifications

Responsibilities

  • Conducting evidence collection, forensic analysis, data recovery, and reporting in response to incident investigations.
  • Performing hands‑on digital forensics activities such as forensic imaging, analysis of physical and virtual drives, and incident documentation.
  • Leveraging FRED’s and forensic tools to capture and preserve evidence for security events.
  • Contributing to the development of forensics playbooks and standard operating procedures.
  • Conducting ad-hoc forensic analysis.
  • Supporting the SOC with investigating security events.
  • Collaborating closely with federal stakeholders.
  • Communicating findings to technical and non‑technical audiences.
  • Producing high‑quality reports and briefings.
  • Helping to advance the maturity and effectiveness of the organization’s security operations.

Benefits

  • health
  • life
  • disability
  • financial
  • retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service