Cyber Network Defense Analyst (CNDA) - Cloud Forensics Location: Remote / Onsite (as required) Clearance: Active TS/SCI (DHS EOD eligibility required) Company: Argo Cyber Systems, LLC - A Service ...
Cyber Network Defense Analyst (CNDA) - Cloud Forensics Location: Remote / Onsite (as required) Clearance: Active TS/SCI (DHS EOD eligibility required) Company: Argo Cyber Systems, LLC - A Service ...
Cyber Network Defense Analyst (CNDA) IV - Cloud Forensics
Arlington, VA · On-site
$130K - $160K/yr
Cyber Network Defense Analyst (CNDA) - Cloud Forensics Location: Remote / Onsite (as required) Clearance: Active TS/SCI (DHS EOD eligibility required) Company: Argo Cyber Systems, LLC - A Service ...
Cyber Network Defense Analyst (CNDA) IV - Cloud Forensics
Arlington, VA · On-site
$130K - $160K/yr
Cyber Network Defense Analyst (CNDA) - Cloud Forensics Location: Remote / Onsite (as required) Clearance: Active TS/SCI (DHS EOD eligibility required) Company: Argo Cyber Systems, LLC - A Service ...
Our teams provide rapid incident response, digital forensics, proactive hunt operations, and continuous cyber defense across host-based, network-based, and cloud-based systems. We combine mission ...
Quick apply
Our teams provide rapid incident response, digital forensics, proactive hunt operations, and continuous cyber defense across host-based, network-based, and cloud-based systems. We combine mission ...
Cloud Forensic Analyst IV
Arlington, VA · On-site
Nightwing is seeking a Cloud Forensics Analyst to support this critical customer mission. The CFA is a recently identified position for the HIRT and affords ample opportunities for training and ...
Cloud Forensic Analyst IV
Arlington, VA · On-site
Nightwing is seeking a Cloud Forensics Analyst to support this critical customer mission. The CFA is a recently identified position for the HIRT and affords ample opportunities for training and ...
Nightwing is seeking a Cloud Forensics Analyst to support this critical customer mission. The CFA is a recently identified position for the HIRT and affords ample opportunities for training and ...
Nightwing is seeking a Cloud Forensics Analyst to support this critical customer mission. The CFA is a recently identified position for the HIRT and affords ample opportunities for training and ...
Cloud Forensic Analyst IV with Security Clearance
Arlington, VA · On-site
$134K/yr
Nightwing is seeking a Cloud Forensics Analyst to support this critical customer mission. The CFA is a recently identified position for the HIRT and affords ample opportunities for training and ...
Cloud Forensic Analyst IV with Security Clearance
Arlington, VA · On-site
$134K/yr
Nightwing is seeking a Cloud Forensics Analyst to support this critical customer mission. The CFA is a recently identified position for the HIRT and affords ample opportunities for training and ...
Perform cloud-based forensic analysis using: * Microsoft 365 * Azure * AWS * Analyze cloud-native logs such as CloudTrail, IAM logs, and other platform security telemetry. Threat Hunting ...
Perform cloud-based forensic analysis using: * Microsoft 365 * Azure * AWS * Analyze cloud-native logs such as CloudTrail, IAM logs, and other platform security telemetry. Threat Hunting ...
Digital Forensics Analyst
Alexandria, VA · On-site
Perform cloud-based forensic analysis using: * Microsoft 365 * Azure * AWS * Analyze cloud-native logs such as CloudTrail, IAM logs, and other platform security telemetry. Threat Hunting ...
Digital Forensics Analyst
Alexandria, VA · On-site
Perform cloud-based forensic analysis using: * Microsoft 365 * Azure * AWS * Analyze cloud-native logs such as CloudTrail, IAM logs, and other platform security telemetry. Threat Hunting ...
Perform cloud-based forensic analysis using: * Microsoft 365 * Azure * AWS * Analyze cloud-native logs such as CloudTrail, IAM logs, and other platform security telemetry. Threat Hunting ...
Perform cloud-based forensic analysis using: * Microsoft 365 * Azure * AWS * Analyze cloud-native logs such as CloudTrail, IAM logs, and other platform security telemetry. Threat Hunting ...
Skills include resolving highly complex intrusion scenarios using host, cloud, network, log, IDS and device analysis and forensics. As a Lead Consultant you will respond to, analyze, diagnose, and ...
Skills include resolving highly complex intrusion scenarios using host, cloud, network, log, IDS and device analysis and forensics. As a Lead Consultant you will respond to, analyze, diagnose, and ...
Skills include resolving highly complex intrusion scenarios using host, cloud, network, log, IDS and device analysis and forensics. As a Lead Consultant you will respond to, analyze, diagnose, and ...
Quick apply
Skills include resolving highly complex intrusion scenarios using host, cloud, network, log, IDS and device analysis and forensics. As a Lead Consultant you will respond to, analyze, diagnose, and ...
Lead Consultant (1099): IR/Forensics Practice
Arlington, VA · On-site
$90 - $120/hr
Skills include resolving highly complex intrusion scenarios using host, cloud, network, log, IDS and device analysis and forensics. As a Lead Consultant you will respond to, analyze, diagnose, and ...
Lead Consultant (1099): IR/Forensics Practice
Arlington, VA · On-site
$90 - $120/hr
Skills include resolving highly complex intrusion scenarios using host, cloud, network, log, IDS and device analysis and forensics. As a Lead Consultant you will respond to, analyze, diagnose, and ...
Conduct cloud forensics activities across enterprise cloud environments, including the collection and analysis of cloud audit logs, storage artifacts, identity and access management records, and ...
New
Conduct cloud forensics activities across enterprise cloud environments, including the collection and analysis of cloud audit logs, storage artifacts, identity and access management records, and ...
New
Relevant certifications or training in digital forensics, incident response, eDiscovery, cybersecurity, OSINT, cloud forensics, mobile forensics, or AI governance are desirable. Minimum ...
Relevant certifications or training in digital forensics, incident response, eDiscovery, cybersecurity, OSINT, cloud forensics, mobile forensics, or AI governance are desirable. Minimum ...
Relevant certifications or training in digital forensics, incident response, eDiscovery, cybersecurity, OSINT, cloud forensics, mobile forensics, or AI governance are desirable. Minimum ...
Relevant certifications or training in digital forensics, incident response, eDiscovery, cybersecurity, OSINT, cloud forensics, mobile forensics, or AI governance are desirable. Minimum ...
Conduct cloud forensics activities across enterprise cloud environments, including the collection and analysis of cloud audit logs, storage artifacts, identity and access management records, and ...
New
Conduct cloud forensics activities across enterprise cloud environments, including the collection and analysis of cloud audit logs, storage artifacts, identity and access management records, and ...
New
Digital Forensic Analyst
Washington, DC · On-site
$100K - $130K/yr
Conduct cloud forensics activities across enterprise cloud environments, including the collection and analysis of cloud audit logs, storage artifacts, identity and access management records, and ...
New
Digital Forensic Analyst
Washington, DC · On-site
$100K - $130K/yr
Conduct cloud forensics activities across enterprise cloud environments, including the collection and analysis of cloud audit logs, storage artifacts, identity and access management records, and ...
New
Digital Forensics & eDiscovery Manager
Milpitas, CA · On-site +1
Relevant certifications or training in digital forensics, incident response, eDiscovery, cybersecurity, OSINT, cloud forensics, mobile forensics, or AI governance are desirable. Minimum ...
Digital Forensics & eDiscovery Manager
Milpitas, CA · On-site +1
Relevant certifications or training in digital forensics, incident response, eDiscovery, cybersecurity, OSINT, cloud forensics, mobile forensics, or AI governance are desirable. Minimum ...
Relevant certifications or training in digital forensics, incident response, eDiscovery, cybersecurity, OSINT, cloud forensics, mobile forensics, or AI governance are desirable. Minimum ...
Relevant certifications or training in digital forensics, incident response, eDiscovery, cybersecurity, OSINT, cloud forensics, mobile forensics, or AI governance are desirable. Minimum ...
Digital Forensics & eDiscovery Manager
Milpitas, CA · On-site +1
Relevant certifications or training in digital forensics, incident response, eDiscovery, cybersecurity, OSINT, cloud forensics, mobile forensics, or AI governance are desirable. Minimum ...
Digital Forensics & eDiscovery Manager
Milpitas, CA · On-site +1
Relevant certifications or training in digital forensics, incident response, eDiscovery, cybersecurity, OSINT, cloud forensics, mobile forensics, or AI governance are desirable. Minimum ...
Cloud Forensics information
See salary details
$10.10 - $17.59
5% of jobs
$17.59 - $25.09
0% of jobs
$25.09 - $32.58
0% of jobs
$32.58 - $40.08
1% of jobs
$40.08 - $47.57
5% of jobs
$47.57 - $55.07
11% of jobs
$56.10 is the 25th percentile. Wages below this are outliers.
$55.07 - $62.57
21% of jobs
The median wage is $65 / hr.
$62.57 - $70.06
21% of jobs
$74.33 is the 75th percentile. Wages above this are outliers.
$70.06 - $77.56
19% of jobs
$77.56 - $85.05
11% of jobs
$85.05 - $92.55
6% of jobs
$10
$64
$92
How much do cloud forensics jobs pay per hour?
What is cloud forensics?
What are the key skills and qualifications needed to thrive as a cloud forensics specialist?
What are some common challenges faced by professionals in cloud forensics, and how can they be addressed?
What is the difference between Cloud Forensics vs Cloud Security Analyst?
| Aspect | Cloud Forensics | Cloud Security Analyst |
|---|---|---|
| Required Credentials | Certifications like GCFA, GCFE, CISSP | CISSP, CCSP, Security+ |
| Work Environment | Investigating security incidents, analyzing digital evidence in cloud environments | Monitoring, implementing security measures, risk assessment in cloud platforms |
| Employer & Industry Usage | Cybersecurity firms, law enforcement, enterprise IT teams | IT departments, cloud service providers, enterprise organizations |
| Common Search & Comparison Intent | Understanding forensic roles in cloud security | Security analysis and prevention in cloud environments |
Cloud Forensics focuses on investigating security incidents and analyzing digital evidence within cloud environments, often requiring specialized certifications. Cloud Security Analysts primarily monitor, implement, and manage security measures to prevent breaches. While both roles operate in cloud security, Cloud Forensics is more investigative, whereas Cloud Security Analysts focus on proactive defense and risk management.
Is digital forensics a high paying job?
What cities are hiring for Cloud Forensics jobs?
Cities with the most Cloud Forensics job openings:
What states have the most Cloud Forensics jobs?
States with the most job openings for Cloud Forensics jobs include:
What job categories do people searching Cloud Forensics jobs look for?
The top searched job categories for Cloud Forensics jobs are:
- Digital Forensic
- Freelance Digital Forensics Incident Response
- Senior Digital Forensic
- Digital Forensics Incident Response
- Digital Forensics Sales Analyst
- Vice President Digital Forensics Incident Response
- Digital Forensics Analyst
- Contract Digital Forensics Incident Response
- Assistant Digital Forensics Incident Response
- Internship Digital Forensics Incident Response

Full-time
Re-posted 9 days ago
Job description
Location: Remote / Onsite (as required)
Clearance: Active TS/SCI (DHS EOD eligibility required)
Company: Argo Cyber Systems, LLC - A Service-Disabled Veteran-Owned Small Business (SDVOSB)
Argo Cyber Systems delivers advanced cybersecurity and threat-hunting capabilities to safeguard federal and critical infrastructure environments. Our teams provide rapid incident response, digital forensics, proactive hunt operations, and continuous cyber defense across host-based, network-based, and cloud-based systems. We combine mission experience with innovation-empowering our customers to detect, disrupt, and defeat adversaries in real time.
Position Overview
Argo Cyber Systems is seeking Cyber Network Defense Analysts (CNDA) with deep Cloud Forensics expertise to support a high-visibility federal mission. The CNDA will lead advanced investigations into sophisticated intrusions across hybrid and multi-cloud environments, identifying attacker tactics, techniques, and procedures (TTPs), correlating artifacts, and driving containment and remediation actions in partnership with government cyber teams.
Key Responsibilities
Conduct end-to-end forensic acquisition and analysis across on-premises, cloud, and hybrid environments (Azure AD/Entra ID, M365, AWS, GCP, SaaS).
Investigate identity-based and credential-abuse incidents targeting cloud control planes and hybrid identity infrastructure.
Correlate cloud telemetry (Azure Activity Logs, AWS CloudTrail, GCP Logs, VPC Flow Logs) and network evidence to reconstruct attacker timelines and validate indicators of compromise (IOCs).
Develop and deploy automated detection logic, threat-hunting scripts, and analytical playbooks using Microsoft Sentinel, Defender, AWS GuardDuty, and GCP Chronicle.
Produce comprehensive technical and executive-level reports, integrating findings across endpoints, networks, and cloud assets to inform threat containment and strategic recommendations.
Support continuous improvement of incident response procedures, forensics workflows, and threat-hunting operations.
Collaborate with Argo and government stakeholders to triage alerts, assess risk, and strengthen enterprise detection and response posture.
Required Qualifications
U.S. Citizenship and active TS/SCI clearance (with ability to obtain DHS EOD Suitability).
Minimum 8 years of hands-on experience conducting digital forensics and incident response (DFIR).
Proven expertise in cloud forensics, identity security, and hybrid infrastructure defense.
Proficiency in M365/Azure AD, AWS IAM, and SaaS investigative methodologies.
Deep understanding of SaaS/PaaS/IaaS architectures, including common attack vectors and defensive measures.
Skilled in evidence acquisition, volatile data capture, artifact analysis, and technical reporting.
Desired Qualifications
Scripting and automation proficiency in PowerShell, Python, Bash, or JavaScript.
Familiarity with Terraform, Kubernetes, Docker, CloudFormation, or Azure Resource Manager for automation and orchestration.
Understanding of MITRE ATT&CK for Cloud and adversary emulation techniques.
Strong communication and collaboration skills for working across multidisciplinary teams.
Education
Bachelor's Degree in Computer Science, Cybersecurity, Computer Engineering, or a related field
orHigh School Diploma and 10+ years of directly relevant DFIR experience.
Preferred Certifications
GIAC Cloud Defender (GCLD), GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP
AWS and Microsoft security/cloud certifications (e.g., Azure Security Engineer, AWS Security Specialty)
Why Argo Cyber Systems
At Argo, you'll be part of a mission-driven, veteran-founded cybersecurity team protecting America's most critical systems. We combine hands-on technical excellence with operational precision to outpace the threat. Join us to defend, detect, and innovate at the cyber edge.
About ARGO Cyber Systems
Sourced by ZipRecruiter
Industry
Network security
Company size
11 - 50 Employees
Headquarters location
Pensacola, FL, US
Year founded
2018