Search Jobs
Cyber Forensics Specialist
Port Hueneme, CA 93041 US
Job Description
Location: Port Hueneme, CA
Job Type: Permanent, On-site
Salary: Open
Key Requirements:
- DoD Top Secret Clearance
- 5 years of relevant work experience
- Graduate degree or CISSP certification
- Proficient with Redline, KAPE, Encase, Autopsy, Yara, Plaso/Log2TimelineVolatility (memory), Endgame, FireEye Helix, Tanium, Carbon Black, StentinelOne, GRR, Splunk, Elastic Stack, CFF Explorer, IDA, Binary Ninja, or similar network analysis tools
- Experienced with Windows/ Linux
- Experience with ICS/SCADA
Key Responsibilities:
- Assist Blue Team remediate or mitigate vulnerabilities identified for the system
- Support Red Team with identifying risks and vulnerabilities in IT/OT environment utilizing cyber security toolkit
- Research tools, techniques, and trends in Operational Technology (OT), network, application and operating system vulnerabilities and securing
- Help develop and establish process for conducting forensic analyses
- Work with the cyber team to conduct vulnerability assessments
- Acquire/collect computer artifacts (e.g., malware, user activity, link files, etc.) from systems in support of onsite engagements
- Assess evidentiary value by triaging electronic devices
- Correlate forensic findings with network events to further develop an intrusion narrative
- When available, collect and document system state information (running processes, network connections, etc.) prior to imaging
- Perform incident triage from a forensic perspective to include determining scope, urgency and potential impact
- Track and document forensic analysis from initial involvement through final resolution
- Collect, process, preserve, analyze and present computer related evidence
- Coordinate with others within the Government and with customer personnel to validate/investigate alerts or other preliminary findings
- Conduct analysis of forensic images and other available evidence and draft forensic write-ups for inclusion in reports
P-WLH-005