Cyber Forensics Analyst, Senior in Herndon, VA at Booz Allen Hamilton

Date Posted: 2/5/2018

Job Snapshot

Job Description

Job Number: R0020735

Booz Allen Hamilton has been at the forefront of strategy and technology for more than 100 years. Today, the firm provides management and technology consulting and engineering services to leading Fortune 500 corporations, governments, and not-for-profits across the globe. Booz Allen partners with public and private sector clients to solve their most difficult challenges through a combination of consulting, analytics, mission operations, technology, systems delivery, cybersecurity, engineering and innovation expertise.

Cyber Forensics Analyst, Senior

Key Role:

Use leading–edge technology and industry standard forensic tools and procedures to provide insight into the cause and effect of suspected Cyber intrusions. Follow proper evidence handling procedures and chain of custody protocols. Produce written reports documenting digital forensic findings. Determine programs that have been executed, including finding files that have been changed on disk and in memory. Use timestamps, logs hosts, and network logs to develop authoritative timelines of activity and find evidence of deleted files and hidden data. Identify and document case relevant file–system artifacts, including browser histories, account usage, and USB histories.

Basic Qualifications:

-8+ years of experience with digital forensics

-Experience with creating forensically sound duplicates of evidence, including forensic images to use for data recovery and analysis and performing all–source research for similar or equivalent network events or incidents

-Experience with using timestamps and host and network logs to develop authoritative timelines of activity to find evidence of deleted files, hidden data, browser histories, account usage, and USB histories

-Experience in assisting with preliminary analysis by tracing an activity to its source and documents findings for input into a forensic report, documenting the original condition of digital and associated evidence by taking photographs, and collecting hash information

-Experience in assisting with gathering, accessing, and assessing evidence from electronic devices using forensic tools while identifying and comprehending TTP threats

-TS/SCI clearance with a polygraph

-BA or BS degree

Additional Qualifications:

-Experience with a common scripting or programming language, including Perl, Python, Bash, or PowerShell

-Experience with Endpoint Detection and Response tools

-Experience with commonly used forensic toolsets, including EnCase, FTK, or BlackLight

-BA or BS degree in an IT– or Cyber–related field

-Active Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), GIAC Certified Incident Handler (GCIH), GIAC Reverse Engineering Malware (GREM), GIAC Certified Forensic Examiner (GCFE), or GIAC Certified Forensic Analyst (GCFA) Certification


Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information. TS/SCI clearance with polygraph is required.

Integrating a full range of consulting capabilities, Booz Allen is the one firm that helps clients solve their toughest problems by their side to help them achieve their missions.  Booz Allen is committed to delivering results that endure.

We are proud of our diverse environment, EOE, M/F/Disability/Vet.

Your Career is Waiting.

Get job alerts. Learn about new work and upcoming events. Share open roles with friends and colleagues.
Our Talent Network is your opportunity hub.

Get Answers and Access.

Need more information? Find it in our FAQs.

Application already in-process? Log in to keep going.