Intrusion Analyst

Spry MethodsWashington, DC
1d

About The Position

We’re looking for an Intrusion Analyst to conduct intrusion-focused digital forensics across host and network evidence, reconstruct attack activity, and communicate findings that can stand up to investigative and legal scrutiny. This role is part of a digital forensics capability supporting complex cyber and computer intrusion cases.  The ideal candidate is a disciplined examiner with strong technical depth, excellent documentation habits, and the ability to explain complex intrusion activity to non-expert audiences.

Requirements

  • U.S. Citizenship required.
  • Active TS clearance with SCI eligibility required. 
  • Demonstrated experience with intrusion-focused forensic analysis across host/network artifacts and multiple OS platforms.
  • Strong writing and verbal communication skills; ability to present findings clearly and defend methodologies.

Nice To Haves

  • Experience supporting rapid response investigative operations that may require extended/irregular hours. 
  • Experience correlating enterprise telemetry sources (security device logs, captures, cloud logs) to identify persistence, escalation, lateral movement, and exfiltration.

Responsibilities

  • Intrusion-Focused Forensic Analysis
  • Perform host- and network-based forensic analysis across Windows, Linux, macOS, and mobile platforms.
  • Examine volatile memory, log exports, and pre-acquired datasets; identify IOCs and adversary TTPs; reconstruct timelines and scope. 
  • Tool-Driven Investigation & Automation
  • Use forensic and analysis tooling such as Magnet Axiom, X-Ways, FTK, Volatility, Splunk, ELK Stack, and open-source utilities.
  • Apply scripting/automation (Python, PowerShell, Bash) to accelerate artifact parsing and correlation. 
  • Reporting, Testimony Readiness & Quality
  • Produce thorough documentation of findings and conclusions; communicate clearly for non-expert audiences.
  • Successfully complete a mock examination and defend results in a practical courtroom exercise (Government-run). 
  • Operational Support
  • Support mission needs that may drive irregular hours and location-specific requirements depending on investigative activity. 

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Education Level

No Education Listed

Number of Employees

101-250 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service