Digital Forensics Analyst (1668)

SOLUTION ONE INDUSTRIESFayetteville, NC
$83,712 - $100,460Onsite

About The Position

Solution One Industries, Inc. is seeking an experienced Digital Forensics Analyst to support the U.S. Special Operations Command (USSOCOM) Special Operations Forces – Global Logistics Support Services (SOF GLSS) contract. The Digital Forensics Analyst performs forensic triage, examination, and technical exploitation of digital media recovered through sensitive site exploitation and captured enemy material in support of the supported organization's intelligence requirements. The analyst is responsible for rapidly processing mobile devices, computers, removable media, and other digital storage; recovering and validating relevant data; and producing clear, accurate, and timely reporting that places forensic findings in operational and analytical context. Work is performed in a fast-paced environment supporting current and future operations, and may include deployed and OCONUS support.

Requirements

  • Demonstrated experience in the following areas: Mobile device forensics and computer/media forensics in an operational or law enforcement environment
  • Commercial forensic suites such as Cellebrite (UFED, Physical Analyzer, Inseyets), Magnet AXIOM, OpenText EnCase, X-Ways Forensics, Oxygen Forensic Detective, MSAB XRY/XAMN, or FTK
  • Forensically sound imaging, hashing, verification, and write-blocking procedures
  • Windows, macOS, Linux, Android, and iOS file systems and artifact locations
  • Technical exploitation workflows and their role in supporting the intelligence cycle
  • Evidence handling, chain of custody, and documentation standards
  • Clear and concise written reporting and verbal briefing of technical findings to non-technical audiences
  • Ability to work independently with minimal supervision as well as effectively within a small team
  • Bachelor's degree in Digital Forensics, Cybersecurity, Computer Science, Information Technology, or a related field
  • 5+ years of hands-on digital forensics and media exploitation experience (DoD, Intelligence Community, or law enforcement preferred)
  • Demonstrated experience conducting examinations and producing reporting in support of operational or investigative requirements
  • Must be a U.S. Citizen.
  • Must possess an active DoD Top Secret security clearance with SCI eligibility.
  • This position directly supports a U.S. Government contract requiring a company-sponsored security clearance.

Nice To Haves

  • Prior support to USSOCOM, USASOC, a Theater Special Operations Command, or other Joint SOF organization
  • Experience in a deployed or expeditionary exploitation environment
  • Military, law enforcement, Intelligence Community, or commercial forensic laboratory background
  • Experience with password recovery, encryption bypass, and chip-off or advanced acquisition techniques
  • Familiarity with document and media exploitation (DOMEX) and biometric enabled intelligence
  • Scripting and automation for artifact parsing and reporting (Python, PowerShell)
  • Malware analysis, reverse engineering, or network forensics experience
  • Familiarity with intelligence analysis tools and reporting standards
  • Industry forensic certifications strongly preferred: GCFA, GCFE, GASF, EnCE, CCE, CFCE, ACE, CHFI, or Cellebrite CCO/CCPA.
  • DoD 8140/8570.01-M compliance for the assigned work role may be required based on system access.

Responsibilities

  • Serve as a digital forensic examiner supporting the collection, handling, triage, and technical exploitation of digital media and captured enemy material.
  • Conduct forensically sound acquisition, preservation, and examination of mobile devices, computers, servers, removable media, and other digital storage.
  • Perform advanced logical, file system, and physical extractions, including handling of locked, damaged, or encrypted devices using approved methods.
  • Recover, analyze, and report on artifacts such as user contacts, call and message logs, internet and browser history, chat and third-party application data, geolocation data, images, multimedia, and timeline activity.
  • Conduct malware triage and identify indicators of compromise or malicious software present on exploited media, referring items for deeper analysis as required.
  • Maintain strict chain of custody, evidence handling, labeling, and accountability procedures in accordance with organizational policy and forensic best practices.
  • Produce timely, accurate forensic examination reports and analytical products that directly answer standing and ad hoc intelligence requirements.
  • Provide analytic context and assessments derived from exploitation findings, and respond to associated requests for information.
  • Support link, pattern, and timeline analysis in coordination with intelligence analysts and mission partners.
  • Validate and quality-check forensic findings, tool output, and reporting prior to dissemination.
  • Maintain, configure, update, and validate forensic hardware, software, licensing, and write-blocking equipment.
  • Develop and maintain standard operating procedures, examination checklists, and technical documentation for exploitation workflows.
  • Provide training and technical guidance to operators and junior examiners on evidence handling, device collection, and exploitation procedures.
  • Deploy in support of forward operations and provide on-site exploitation support when required.

Benefits

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • 401(k)
  • Life Insurance
  • Employee Assistance Program
  • Employee Referral Program
  • Employee Award Program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service