About The Position

The Digital Forensics Analyst is responsible for collecting, preserving, analyzing, and documenting digital evidence associated with cybersecurity incidents, investigations, legal proceedings, and insider threat cases. This position conducts forensic examinations of computers, servers, mobile devices, cloud environments, virtual systems, and storage media to determine what occurred during a security incident. The analyst reconstructs timelines, identifies attacker activity, recovers deleted artifacts, and supports root cause investigations. The Digital Forensics Analyst maintains evidence integrity, follows chain-of-custody procedures, and produces detailed investigative reports suitable for executive, legal, regulatory, and law enforcement review. The position frequently supports ransomware investigations, insider threat investigations, fraud investigations, intellectual property theft cases, and major breach investigations.

Requirements

  • Advanced knowledge of digital forensics principles, evidence preservation techniques, forensic acquisition methods, operating systems, file systems, memory analysis, and artifact analysis.
  • Experience using industry-standard forensic tools.
  • Experience conducting investigations across Windows, Linux, macOS, cloud platforms, and mobile devices.
  • Strong documentation skills.
  • Patience, precision, and objectivity.
  • Ability to produce defensible findings based on evidence rather than assumptions.
  • Required certifications include GCFA, GCFE, EnCE, CHFI, CFCE, or equivalent forensic certifications.

Responsibilities

  • Collecting, preserving, analyzing, and documenting digital evidence associated with cybersecurity incidents, investigations, legal proceedings, and insider threat cases.
  • Conducting forensic examinations of computers, servers, mobile devices, cloud environments, virtual systems, and storage media to determine what occurred during a security incident.
  • Reconstructing timelines, identifying attacker activity, recovering deleted artifacts, and supporting root cause investigations.
  • Maintaining evidence integrity and following chain-of-custody procedures.
  • Producing detailed investigative reports suitable for executive, legal, regulatory, and law enforcement review.
  • Supporting ransomware investigations, insider threat investigations, fraud investigations, intellectual property theft cases, and major breach investigations.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service