
Cyber Defense Forensics Analyst [Various Levels] Contingent
- 🇺🇸 United States
- On-site
- Mid level
- 9 hours ago
- $80,000 – $95,000 / year
- Incident Response
- CySA+
- GCFA
- CISSP
Position Description: Cyber Defense Forensics Analyst
Role Specification & Overview
Attribute | Definition |
|---|---|
PWS Capability Area | Cybersecurity Operations (CSO)Â |
DCWF Work Role Code | 612 - Cyber Defense Forensics Analyst |
Minimum Proficiency Level | Intermediate |
Key Personnel Status | No |
Clearance Requirement | Active Secret or Top Secret |
Position Summary
TheCyber Defense Forensics Analyst serves within the Cybersecurity Operations (CSO) capability area to support incident response, threat analysis, and digital evidence processing for global C4ISR and distribution operations. Operating in accordance with DoDM 8140.03 standards, this role performs deep-dive technical investigations, host and network-level artifact recovery, and threat timeline reconstruction to ensure operational effectiveness and mission assurance during active security events.
Core Responsibilities
- Digital Forensics & Artifact Collection: Execute digital forensic collections, host-based memory analysis, disk image acquisition, and reverse engineering during operational security incidents.
- Evidence Handling & Chain of Custody: Maintain strict evidence handling and legal chain-of-custody protocols for all collected host artifacts, network packet captures, and system memory dumps.
- Threat Analysis & Reconstruction: Evaluate disk images, volatile memory, system logs, and network traffic captures to reconstruct attack vectors, establish timelines, and determine breach scope and impact.
- Incident Response Technical Support: Assist in technical measures to isolate, contain, eradicate, and recover from security events upon direction from the COR.
- Reporting & CDRL Deliverables: Author comprehensive forensic investigation reports and provide technical analysis inputs for formal Security Incident Reports.
Qualifications & Certifications
Minimum Education & Experience
- Technical degree in Cybersecurity, Computer Science, Information Technology, or a related field, OR 5+ years of direct operational experience in digital forensics and cyber incident response.
DCWF Qualification Framework (DoDM 8140.03)
Personnel assigned to this role must satisfy the foundational qualification requirements for DCWF Work Role 612 at anIntermediate proficiency level prior to commencing work. Qualifying certifications across proficiency tiers include:
Tier Level | Qualifying Certifications |
|---|---|
Basic | Security+, GCFE, CCFP |
Intermediate(Required Minimum) | CySA+, GCFA, EnCE, CCE |
Advanced | SecurityX (CASP+), CISSP, GCFA |
Operational Compliance & Governance
- Workforce Qualification Compliance: Contractor personnel must be fully qualified and certified prior to performance. Compliance is tracked and verified via the Personnel Qualification & Certification Report (CDRL A008) and quarterly training rosters (CDRL A050).
- Privileged Access Requirements: Must meet residential qualification requirements for elevated or privileged network access prior to performing technical duties.
- Security Program Adherence: Execute all information handling in strict accordance with AR 380-5 for classified data and DoDI 5200.48 for Controlled Unclassified Information (CUI).
Position & Compensation Disclaimer (Pay Transparency Mandates):
Employment for this role is conditional upon contract award, executed funding, and client approval. Advertised ranges do not constitute a binding promise of specific salary. In compliance with applicable federal, state, and municipal pay transparency requirements—including but not limited to pay disclosure rules in California, Colorado, New York, and Washington—posted salary bands remain flexible. Compensation ranges may be modified prior to an offer to reflect candidate expertise, client budget constraints, and localized geographic pay scales tied to the assigned work site or state of residence.
Cyber Defense Forensics Analyst [Various Levels] Contingent · LufCo