Job Summary:
ECS is seeking a Cyber Forensics Analyst to work in our Portland, OR office. This role involves performing hands-on forensic analysis and malware investigation activities to support security investigations and incident response efforts using industry-standard forensic tools.
Responsibilities:
• Perform forensic analysis using industry-standard forensic tools and open-source DFIR utilities.
• Assist with forensic investigations involving endpoints, servers, malware, and cyber incidents.
• Analyze Windows Registry, Windows System Calls, Linux artifacts, file system data, logs, and memory artifacts.
• Create findings and technical notes that support investigative conclusions and remediation actions.
• Analyze malware in a lab environment using standard malware analysis techniques.
• Create IOCs based on forensic and malware findings for sharing with SOC and security teams.
• Support Java code de-obfuscation and technical analysis activities within the analyst skill level.
• Escalate complex malware or reverse-engineering requirements to senior analysts or the FMAT Lead.
• Assist the SOC with security investigations and incident response activities.
• Conduct routine memory checks on Linux and Windows servers as directed.
• Support proactive malware analysis, incident response, and advanced threat hunting activities.
• Communicate with different teams and data centers during investigations.
• Create clear investigation reports, forensic summaries, and supporting documentation.
• Communicate findings effectively to SOC analysts, incident responders, data center teams, and leadership.
• Apply strong investigative, research, and problem-solving skills to ambiguous technical issues.
• Contribute to repeatable forensic procedures, knowledge sharing, and continuous process improvement.
Qualifications:
Required:
• 5 to 8 years of experience in cybersecurity, digital forensics, incident response, or related cyber investigation work.
• Experience performing forensic analysis using industry-standard forensic tools and open-source tools.
• Familiarity with Windows Registry, Windows System Calls, Linux operating systems, and Java code de-obfuscation.
• Hands-on experience with Volatility or other memory forensics tools, FTK, and Wireshark.
• Ability to create IOCs based on forensic analysis and share them with other security teams.
• Ability to analyze malware in a lab environment using standard malware analysis techniques.
• Experience performing or supporting forensic investigations and incident response activities.
• Excellent written communication, resourcefulness, investigative ability, research skills, and problem-solving skills.
Preferred:
• Experience with EnCase (OpenText), Autopsy, Axiom, Zimmerman tools, and other DFIR tools.
• Experience supporting a U.S. Government civilian agency, enterprise SOC, or regulated environment.
• Experience with OllyDbg, IdaPro, or comparable reverse-engineering tools.
• Knowledge of X86 Intel Assembly Language.
• GCFE
• GCFA
• EnCE
• FOR508
• Security+
• GREM
• CEH
• CSFA
Company:
Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Founded in 2001, the company is headquartered in Fairfax, USA, with a team of 1001-5000 employees. The company is currently Late Stage.