1

Cyber Forensics Jobs (NOW HIRING)

ECS is seeking a Cyber Forensics Analyst to work in our Portland, OR office. Note: This position is contingent upon contract award. The Forensics Analyst Mid performs hands-on forensic analysis and ...

Nightwing is seeking a Host Forensics Analyst to support this critical customer mission ... in cyber forensic investigations using leading edge technologies and industry standard forensic ...

... forensics findings - Experience with the analysis and characterization of cyber attacks - Experience with proper evidence handing procedures and chain of custody protocols - Skilled in identifying ...

Nightwing is seeking a Host Forensics Analyst to support this critical customer mission ... in cyber forensic investigations using leading edge technologies and industry standard forensic ...

Nightwing is seeking a Host Forensics Analyst to support this critical customer mission ... in cyber forensic investigations using leading edge technologies and industry standard forensic ...

... forensics findings - Experience with the analysis and characterization of cyber attacks - Experience with proper evidence handing procedures and chain of custody protocols - Skilled in identifying ...

Nightwing is seeking a Host Forensics Analyst to support this critical customer mission ... in cyber forensic investigations using leading edge technologies and industry standard forensic ...

Conduct cyber forensics, to include the acquisition, chain of custody, and analysis of electronic evidence from computers, mobile devices, and other digital storage media. * Apply investigation and ...

Conduct cyber forensics, to include the acquisition, chain of custody, and analysis of electronic evidence from computers, mobile devices, and other digital storage media. * Apply investigation and ...

Senior Cyber Lead

Linthicum, MD · On-site

$175K - $225K/yr

Lead forensic investigations involving host-based analysis, network intrusion investigations, malware analysis, memory analysis, and cyber threat activity. * Direct advanced cyber investigations and ...

Lead forensic investigations involving host-based analysis, network intrusion investigations, malware analysis, memory analysis, and cyber threat activity. * Direct advanced cyber investigations and ...

next page

Showing results 1-20

Cyber Forensics information

See salary details

$69.5K

$101.6K

$154.5K

How much do cyber forensics jobs pay per year?

As of Jul 24, 2026, the average yearly pay for cyber forensics in the United States is $101,608.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,500.00 and $132,000.00 per year, depending on experience, location, and employer.

Is cyber forensics a good career?

Cyber forensics is a growing field that involves investigating cybercrimes and analyzing digital evidence using tools like EnCase and FTK. It offers opportunities in law enforcement, cybersecurity firms, and private sectors, often requiring certifications such as GCFA or EnCE. The career typically demands strong technical skills, attention to detail, and the ability to work under pressure.

How much do cybersecurity forensics make?

Cyber forensics specialists typically earn between $60,000 and $120,000 annually, depending on experience, certifications, and location. Entry-level roles may start lower, while experienced professionals with certifications like GCFA or CISSP can earn higher salaries, especially in larger organizations or high-demand areas.

What is a Cyber Forensics job?

A Cyber Forensics job involves investigating digital crimes by analyzing electronic devices, networks, and data to uncover evidence of cybercrimes such as hacking, fraud, and data breaches. Cyber forensic professionals use specialized tools and techniques to recover deleted files, trace cybercriminal activities, and ensure the integrity of digital evidence for legal proceedings. They often work with law enforcement, government agencies, or private companies to prevent and mitigate cyber threats. Additionally, they may provide expert testimony in court and help strengthen an organization’s cybersecurity measures.

What are the key skills and qualifications needed to thrive in the Cyber Forensics position, and why are they important?

To thrive in Cyber Forensics, you need expertise in computer science, digital evidence handling, and incident response, typically supported by a degree in a related field and industry-recognized certifications like EnCE or GCFA. Familiarity with tools such as EnCase, FTK, X-Ways, Cellebrite, and knowledge of operating systems and forensic imaging software is essential. Strong analytical thinking, attention to detail, clear communication, and the ability to work under pressure are crucial soft skills. These skills ensure the accurate extraction, analysis, and reporting of digital evidence in criminal investigations and corporate security incidents.

What are some typical daily responsibilities for a professional in Cyber Forensics?

A Cyber Forensics professional usually spends their day collecting, preserving, and analyzing digital evidence from computers, networks, and mobile devices. They may be tasked with investigating security breaches, recovering deleted or encrypted data, preparing detailed forensic reports, and supporting legal proceedings with credible findings. Collaboration with IT security teams, law enforcement, or legal counsel is common, requiring clear documentation and communication. These responsibilities help organizations or law enforcement agencies understand the nature of security incidents and take appropriate actions.

What can you do with a cyber forensics degree?

A cyber forensics degree prepares individuals for roles such as digital forensic analyst, cybersecurity investigator, or incident responder. Graduates can work in law enforcement, private security firms, or corporate security teams, utilizing skills in data recovery, malware analysis, and digital evidence handling, often using tools like EnCase or FTK. Certifications like GCFA or CISSP can enhance job prospects.

Can I make $200,000 a year in cyber security?

Cyber Forensics professionals can potentially earn $200,000 or more annually, especially with advanced skills, certifications like CISSP or GIAC, and experience in high-demand areas such as incident response or threat analysis. Salaries vary based on location, employer, and level of expertise, with senior roles and specialized knowledge commanding higher pay.
More about Cyber Forensics jobs
What cities are hiring for Cyber Forensics jobs? Cities with the most Cyber Forensics job openings:
What are the most commonly searched types of Cyber Forensics jobs? The most popular types of Cyber Forensics jobs are:
What states have the most Cyber Forensics jobs? States with the most job openings for Cyber Forensics jobs include:
Infographic showing various Cyber Forensics job openings in the United States as of July 2026, with employment types broken down into 94% Full Time, 3% Part Time, and 3% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $101,608 per year, or $48.9 per hour.
Cyber Forensics Analyst

Cyber Forensics Analyst

ECS

Portland, OR • On-site

Full-time

Posted 26 days ago


Job description

ECS is seeking a Cyber Forensics Analyst to work in our Portland, OR office. Note: This position is contingent upon contract award.
The Forensics Analyst Mid performs hands-on forensic analysis and malware investigation activities in support of SOC security investigations, incident response, routine memory checks, and advanced threat hunting. This role uses industry-standard forensic tools and strong investigative skills to collect, analyze, and document technical evidence.
The ideal candidate has solid cybersecurity experience, strong written communication skills, and the ability to operate resourcefully and independently while coordinating with SOC teams, data centers, and senior forensic personnel during investigations.
Key Responsibilities
Digital Forensics and Investigation
  • Perform forensic analysis using industry-standard forensic tools and open-source DFIR utilities.
  • Assist with forensic investigations involving endpoints, servers, malware, and cyber incidents.
  • Analyze Windows Registry, Windows System Calls, Linux artifacts, file system data, logs, and memory artifacts.
  • Create findings and technical notes that support investigative conclusions and remediation actions.

Malware Analysis and IOC Development
  • Analyze malware in a lab environment using standard malware analysis techniques.
  • Create IOCs based on forensic and malware findings for sharing with SOC and security teams.
  • Support Java code de-obfuscation and technical analysis activities within the analyst skill level.
  • Escalate complex malware or reverse-engineering requirements to senior analysts or the FMAT Lead.

SOC and Incident Response Support
  • Assist the SOC with security investigations and incident response activities.
  • Conduct routine memory checks on Linux and Windows servers as directed.
  • Support proactive malware analysis, incident response, and advanced threat hunting activities.
  • Communicate with different teams and data centers during investigations.

Reporting and Collaboration
  • Create clear investigation reports, forensic summaries, and supporting documentation.
  • Communicate findings effectively to SOC analysts, incident responders, data center teams, and leadership.
  • Apply strong investigative, research, and problem-solving skills to ambiguous technical issues.
  • Contribute to repeatable forensic procedures, knowledge sharing, and continuous process improvement.

  • U.S. Citizenship with ability to obtain and maintain a DOE "L" clearance after start.
  • 5 to 8 years of experience in cybersecurity, digital forensics, incident response, or related cyber investigation work.
  • Experience performing forensic analysis using industry-standard forensic tools and open-source tools.
  • Familiarity with Windows Registry, Windows System Calls, Linux operating systems, and Java code de-obfuscation.
  • Hands-on experience with Volatility or other memory forensics tools, FTK, and Wireshark.
  • Ability to create IOCs based on forensic analysis and share them with other security teams.
  • Ability to analyze malware in a lab environment using standard malware analysis techniques.
  • Experience performing or supporting forensic investigations and incident response activities.
  • Excellent written communication, resourcefulness, investigative ability, research skills, and problem-solving skills.