Digital Forensics Analyst SME

Booz Allen HamiltonBethesda, MD
$62,000 - $141,000Remote

About The Position

Serve as a key member of a 24x7x365 Security Operations Center and Incident Response team, responsible for conducting evidence collection, forensic analysis, data recovery, and reporting in response to incident investigations. The role performs hands‑on digital forensics activities such as forensic imaging, analysis of physical and virtual drives, and incident documentation while leveraging FRED’s and forensic tools to capture and preserve evidence for security events. The analyst contributes to the development forensics playbooks and standard operating procedures, conducts ad-hoc forensic analysis, and supports the SOC with investigating security events. This position collaborates closely with federal stakeholders, communicates findings to technical and non‑technical audiences, and produces high‑quality reports and briefings, all while helping to advance the maturity and effectiveness of the organization’s security operations.

Requirements

  • 2+ years of experience in a Security Operations Center (SOC) providing forensic analysis, imaging, log and evidence analysis or preservation, chain-of-custody, incident documentation, and coordination with Federal stakeholders
  • Experience analyzing and responding to forensic security requests across enterprise host including Linux, Windows, or macOS and network-based platforms
  • Experience developing or contributing to evidence collection, examination, and chain-of-custody documentation or standard operating procedures
  • Experience using Splunk SIEM platform to support investigations and evidence enrichment
  • Experience using a forensic recovery of evidence device (FRED) to collect, store, and maintain forensic images
  • Experience with malware analysis and reverse engineering
  • Ability to analyze and correlate data from multiple technical sources to identify malicious activity, artifacts, indicators, or investigative leads
  • Ability to communicate clearly with both technical and non-technical audiences, including the production of high‑quality incident reports, briefings, and technical documentation
  • Public Trust clearance
  • Bachelor's degree

Nice To Haves

  • Experience using industry forensic suites and toolsets such as EnCase, FTK, X-Ways, Cellebrite, Autopsy, KAPE, or Velociraptor
  • Experience performing volatile memory acquisition and analysis
  • Experience with cloud forensics methodologies such as AWS, Azure, or GCP including log acquisition and artifact preservation
  • Experience with federal security controls such as NIST 800‑53, RMF, or FedRAMP and impact on investigative activities
  • Ability to build strong client relationships, collaborate across varied teams, and communicate complex technical concepts in a clear, inclusive manner
  • DFIR Certifications such as GIAC, GCFA, GCFE, GCIH, CFCE, IACIS, and EnCase EnCE Certifications

Responsibilities

  • Conduct evidence collection, forensic analysis, data recovery, and reporting in response to incident investigations.
  • Perform hands-on digital forensics activities such as forensic imaging, analysis of physical and virtual drives, and incident documentation.
  • Leverage FRED’s and forensic tools to capture and preserve evidence for security events.
  • Contribute to the development of forensics playbooks and standard operating procedures.
  • Conduct ad-hoc forensic analysis.
  • Support the SOC with investigating security events.
  • Collaborate closely with federal stakeholders.
  • Communicate findings to technical and non-technical audiences.
  • Produce high-quality reports and briefings.
  • Help advance the maturity and effectiveness of the organization’s security operations.

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service