Digital Forensics Lead

SAICBethesda, OH
Onsite

About The Position

SAIC is seeking a Digital Forensics Lead to serve as the senior technical and managerial authority for all digital forensics activities performed under an Intelligence Community program. This position provides oversight of forensic examination personnel, manages laboratory workflows, and ensures the timely, technically defensible extraction and analysis of data from digital devices and media in support of the customer’s intelligence mission. Work is performed on site in Bethesda, MD, with CONUS/OCONUS travel as required.

Requirements

  • Active TS/SCI is required to be considered for this role.
  • Willing and able to pass a polygraph.
  • Bachelor's degree or higher in Intelligence Studies, Computer Science, Electrical Engineering, Biometrics, Criminal Justice, or related field.
  • Seven (7) years of experience in digital forensics, including evidence acquisition, forensic imaging, data extraction, and host-based examination across multiple operating systems (Windows, Linux, macOS).
  • Five (5) years of experience in advanced forensic disciplines, including network intrusion analysis, malware forensics, memory analysis, and/or mobile/IoT device exploitation.
  • Three (3) years of experience in a leadership or supervisory role managing a digital forensics team, assigning cases, overseeing laboratory workflows, and maintaining chain of custody documentation.
  • Demonstrated experience testing and validating forensic imaging tools and write-blockers, and utilizing common examination platforms including FTK, EnCase, and X-Ways.
  • Required Certifications (at least one): DC3 Cyber Training Academy Digital Forensic Examiner (DFE), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Forensic Examiner (GCFE), GIAC Certified Incident Handler (GCIH), EnCase Certified Examiner (EnCE), or equivalent certification approved by the COR.

Nice To Haves

  • Experience supporting IC or DoD forensics missions in a SCIF environment compliant with ICD 705.
  • Familiarity with DC3 Terms of Reference and forensic standards applicable to DoD digital exploitation programs.
  • Experience with AI/ML-assisted forensic analysis or large-scale data processing pipelines in support of intelligence production.
  • Prior experience supporting national-level digital exploitation programs.

Responsibilities

  • Leading Digital Forensics and Incident Response (DFIR) activities, including network intrusion analysis, malware forensics, and memory analysis.
  • Overseeing forensic imaging, data extraction, and host-based examination across a variety of media types.
  • Maintaining chain of custody documentation and asset accountability in accordance with applicable Federal law, UCMJ, and program SOPs.
  • Supporting and sustaining laboratory accreditation under ISO/IEC 17025, including SOP development, internal audits, and quality assurance procedures.
  • Collaborating across program functional areas to maximize intelligence value from complex, multi-disciplinary requirements.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service