... Splunk o EnCase o Magnet AXIOM o X-Ways Forensics • Understanding of cyber intrusion methodologies, attacker kill chains, malware behavior, and forensic artifact analysis. • Experience ...
Quick apply
... Splunk o EnCase o Magnet AXIOM o X-Ways Forensics • Understanding of cyber intrusion methodologies, attacker kill chains, malware behavior, and forensic artifact analysis. • Experience ...
Quick apply
... Splunk o EnCase o Magnet AXIOM o X-Ways Forensics • Understanding of cyber intrusion methodologies, attacker kill chains, malware behavior, and forensic artifact analysis. • Experience ...
... tools: --- EnCase --- SIFT --- X-Ways --- Volatility --- WireShark --- Sleuth Kit/ Autopsy --- Magnet Axiom Cyber --- Snort --- Splunk or other SIEM Tools (ArcSight, LogRythm, Elastic, Etc ...
... tools: --- EnCase --- SIFT --- X-Ways --- Volatility --- WireShark --- Sleuth Kit/ Autopsy --- Magnet Axiom Cyber --- Snort --- Splunk or other SIEM Tools (ArcSight, LogRythm, Elastic, Etc ...
$107K - $139K/yr
... Examinations - Encase - DC3 Certified Ethical Hacker Counterintelligence Collection in a Cyber Environment - JCITA Counterintelligence Investigations in a Cyber Environment - JCITA ...
$107K - $139K/yr
... Examinations - Encase - DC3 Certified Ethical Hacker Counterintelligence Collection in a Cyber Environment - JCITA Counterintelligence Investigations in a Cyber Environment - JCITA ...
Desired Skills: - Experience with or knowledge of two or more of the following tools: --- EnCase --- FTK --- SIFT --- X-Ways --- Volatility --- WireShark --- Sleuth Kit/Autopsy --- Splunk --- Snort ...
Desired Skills: - Experience with or knowledge of two or more of the following tools: --- EnCase --- FTK --- SIFT --- X-Ways --- Volatility --- WireShark --- Sleuth Kit/Autopsy --- Splunk --- Snort ...
Quantico, VA · On-site
Windows Forensic Examinations - Encase - DC3 * Certified Ethical Hacker * Counterintelligence Collection in a Cyber Environment - JCITA * Counterintelligence Investigations in a Cyber Environment ...
Quantico, VA · On-site
Windows Forensic Examinations - Encase - DC3 * Certified Ethical Hacker * Counterintelligence Collection in a Cyber Environment - JCITA * Counterintelligence Investigations in a Cyber Environment ...
EnCase * FTK * SIFT * X-Ways * Volatility * WireShark * Sleuth Kit/Autopsy * Splunk * Snort * Other EDR Tools (Crowdstrike, Carbon Black, Etc.) Desired Certifications * GCFA, GCFE, EnCE, CCE, CFCE ...
Quick apply
EnCase * FTK * SIFT * X-Ways * Volatility * WireShark * Sleuth Kit/Autopsy * Splunk * Snort * Other EDR Tools (Crowdstrike, Carbon Black, Etc.) Desired Certifications * GCFA, GCFE, EnCE, CCE, CFCE ...
Arlington, VA · On-site
EnCase * FTK * SIFT * X-Ways * Volatility * WireShark * Sleuth Kit/Autopsy * Splunk * Snort * Other EDR Tools (Crowdstrike, Carbon Black, Etc.) Desired Certifications * GCFA, GCFE, EnCE, CCE, CFCE ...
Arlington, VA · On-site
EnCase * FTK * SIFT * X-Ways * Volatility * WireShark * Sleuth Kit/Autopsy * Splunk * Snort * Other EDR Tools (Crowdstrike, Carbon Black, Etc.) Desired Certifications * GCFA, GCFE, EnCE, CCE, CFCE ...
EnCase FTK SIFT X-Ways Volatility WireShark Sleuth Kit/Autopsy Splunk Snort Other EDR Tools (Crowdstrike, Carbon Black, Etc.) Desired Certifications GCFA, GCFE, EnCE, CCE, CFCE, CISSP About Us For ...
EnCase FTK SIFT X-Ways Volatility WireShark Sleuth Kit/Autopsy Splunk Snort Other EDR Tools (Crowdstrike, Carbon Black, Etc.) Desired Certifications GCFA, GCFE, EnCE, CCE, CFCE, CISSP About Us For ...
Desired Skills: - Experience with or knowledge of two or more of the following tools: --- EnCase --- FTK --- SIFT --- X-Ways --- Volatility --- WireShark --- Sleuth Kit/Autopsy --- Splunk --- Snort ...
Quick apply
Desired Skills: - Experience with or knowledge of two or more of the following tools: --- EnCase --- FTK --- SIFT --- X-Ways --- Volatility --- WireShark --- Sleuth Kit/Autopsy --- Splunk --- Snort ...
EnCase SIFT X-Ways Volatility WireShark Sleuth Kit/ Autopsy Magnet Axiom Cyber Snort Splunk or other SIEM Tools (ArcSight, LogRythm, Elastic, etc.) Other EDR Tools (Crowdstrike, MDE, Trellix, etc ...
EnCase SIFT X-Ways Volatility WireShark Sleuth Kit/ Autopsy Magnet Axiom Cyber Snort Splunk or other SIEM Tools (ArcSight, LogRythm, Elastic, etc.) Other EDR Tools (Crowdstrike, MDE, Trellix, etc ...
EnCase * FTK * SIFT * X-Ways * Volatility * WireShark * Sleuth Kit/Autopsy * Splunk * Snort * Other EDR Tools (Crowdstrike, Carbon Black, Etc.) Desired Certifications * GCFA, GCFE, EnCE, CCE, CFCE ...
EnCase * FTK * SIFT * X-Ways * Volatility * WireShark * Sleuth Kit/Autopsy * Splunk * Snort * Other EDR Tools (Crowdstrike, Carbon Black, Etc.) Desired Certifications * GCFA, GCFE, EnCE, CCE, CFCE ...
... Encase, Palantir, i2 Analyst's Notebook, FTK or similar tools or extensive statistical analysis tool experience (including extensive use of MS Excel) What you'll need: - Demonstrable interest in ...
... Encase, Palantir, i2 Analyst's Notebook, FTK or similar tools or extensive statistical analysis tool experience (including extensive use of MS Excel) What you'll need: - Demonstrable interest in ...
Experience with or knowledge of two or more of the following tools: --- EnCase --- FTK --- SIFT --- X-Ways --- Volatility --- WireShark --- Sleuth Kit/Autopsy --- Splunk --- Snort --- Other EDR Tools ...
Experience with or knowledge of two or more of the following tools: --- EnCase --- FTK --- SIFT --- X-Ways --- Volatility --- WireShark --- Sleuth Kit/Autopsy --- Splunk --- Snort --- Other EDR Tools ...
Quantico, VA · On-site
$51K - $69K/yr
... EnCase, FTK, Magnet Axiom), and memory and/or malware analysis. Required education: * Must be a graduate from an accredited CI Special Agent credentialing school. * Demonstrated abilities through ...
Quantico, VA · On-site
$51K - $69K/yr
... EnCase, FTK, Magnet Axiom), and memory and/or malware analysis. Required education: * Must be a graduate from an accredited CI Special Agent credentialing school. * Demonstrated abilities through ...
GIAC Certified Forensic Analyst (GCFA) Certified Computer Examiner (CCE) Certified Forensic Computer Examiner (CFCE) EnCase Certified Examiner (EnCE) 6+ years of experience in digital/mobile ...
GIAC Certified Forensic Analyst (GCFA) Certified Computer Examiner (CCE) Certified Forensic Computer Examiner (CFCE) EnCase Certified Examiner (EnCE) 6+ years of experience in digital/mobile ...
Chantilly, VA · On-site
$104K - $166K/yr
Experience with EnCase, Autopsy, X-Ways, Axiom, and other forensic tools * Experience conducting disk and network forensic analysis * Experience with volatile memory analysis * Experience writing ...
Chantilly, VA · On-site
$104K - $166K/yr
Experience with EnCase, Autopsy, X-Ways, Axiom, and other forensic tools * Experience conducting disk and network forensic analysis * Experience with volatile memory analysis * Experience writing ...
EnCase * SIFT * X-Ways * Volatility * WireShark * Sleuth Kit/ Autopsy * Magnet Axiom Cyber * Snort * Splunk or other SIEM Tools (ArcSight, LogRythm, Elastic, etc.) * Other EDR Tools (Crowdstrike, MDE ...
EnCase * SIFT * X-Ways * Volatility * WireShark * Sleuth Kit/ Autopsy * Magnet Axiom Cyber * Snort * Splunk or other SIEM Tools (ArcSight, LogRythm, Elastic, etc.) * Other EDR Tools (Crowdstrike, MDE ...
Chantilly, VA · On-site
$104K - $166K/yr
Experience with EnCase, Autopsy, X-Ways, Axiom, and other forensic tools * Experience conducting disk and network forensic analysis * Experience with volatile memory analysis * Experience writing ...
Chantilly, VA · On-site
$104K - $166K/yr
Experience with EnCase, Autopsy, X-Ways, Axiom, and other forensic tools * Experience conducting disk and network forensic analysis * Experience with volatile memory analysis * Experience writing ...
Arlington, VA · On-site
EnCase * SIFT * X-Ways * Volatility * WireShark * Sleuth Kit/ Autopsy * Magnet Axiom Cyber * Snort * Splunk or other SIEM Tools (ArcSight, LogRythm, Elastic, etc.) * Other EDR Tools (Crowdstrike, MDE ...
Arlington, VA · On-site
EnCase * SIFT * X-Ways * Volatility * WireShark * Sleuth Kit/ Autopsy * Magnet Axiom Cyber * Snort * Splunk or other SIEM Tools (ArcSight, LogRythm, Elastic, etc.) * Other EDR Tools (Crowdstrike, MDE ...
Chantilly, VA · On-site
$104K - $166K/yr
Experience with EnCase, Autopsy, X-Ways, Axiom, and other forensic tools * Experience conducting disk and network forensic analysis * Experience with volatile memory analysis * Experience writing ...
Chantilly, VA · On-site
$104K - $166K/yr
Experience with EnCase, Autopsy, X-Ways, Axiom, and other forensic tools * Experience conducting disk and network forensic analysis * Experience with volatile memory analysis * Experience writing ...
$22.16 - $25.76
2% of jobs
$25.76 - $29.36
3% of jobs
$29.36 - $32.95
3% of jobs
$32.95 - $36.55
7% of jobs
$36.55 - $40.15
7% of jobs
$40.48 is the 25th percentile. Wages below this are outliers.
$40.15 - $43.74
17% of jobs
The median wage is $46.98 / hr.
$43.74 - $47.34
11% of jobs
$47.34 - $50.94
19% of jobs
$51.89 is the 75th percentile. Wages above this are outliers.
$50.94 - $54.53
18% of jobs
$54.53 - $58.13
6% of jobs
$58.13 - $61.73
5% of jobs
$22
$46
$61
| Aspect | Encase | Forensic Analyst |
|---|---|---|
| Certifications | Encase Certified Examiner (EnCE) | EnCE, CFCE, or similar certifications |
| Work Environment | Digital forensics, law enforcement, cybersecurity firms | Law enforcement, corporate security, consulting firms |
| Primary Focus | Data acquisition, analysis, and reporting using Encase software | Investigating digital crimes, analyzing digital evidence, report writing |
Encase is a specialized software tool used by forensic examiners to perform digital investigations, while a Forensic Analyst is a professional who conducts digital investigations, often utilizing tools like Encase. Both roles require similar certifications and work in related environments, but Encase refers specifically to the software, whereas Forensic Analyst describes the job function.

Full-time
Posted 9 days ago
Cyber Threat Analyst
5 Year DoJ Contract | Chantilly, VA
Amatriot is seeking a Cyber Threat Analyst to support a Cyber Technical Analysis Unit in
analyzing cyber intrusion activity, digital communications, and host/network forensic artifacts in
support of DoJ mission operations. This role is focused on cyber threat analysis, intrusion
investigation, host-based forensic analysis, network traffic analysis, and attribution support
within a highly sensitive operational environment. The ideal candidate will possess experience
analyzing Splunk data, conducting host and network forensic analysis, and utilizing industrystandard
forensic and cyber analysis tools to identify malicious activity, recover artifacts, and
support investigative operations.
Responsibilities
• Process, evaluate, and analyze digital network communications and cyber threat data to
identify malicious activity and support investigative operations.
• Conduct cyber intrusion investigations and end-to-end kill chain analysis across host and
network environments.
• Perform host-based forensic analysis leveraging Splunk and standard forensic toolsets
to identify indicators of compromise, attacker activity, persistence mechanisms, and
unauthorized access.
• Analyze packet capture (PCAP) and NetFlow data to identify malicious communications,
software usage, command execution, credential activity, and network-based indicators of
compromise.
• Correlate digital artifacts including IP addresses, URLs, malware indicators, system logs,
and user activity across multiple data sources to support attribution and investigative
lead generation.
• Analyze encrypted and plaintext credentials, registry artifacts, rootkit activity, commandline
execution, and other system-level forensic evidence.
• Draft detailed technical reports and analytical findings based on cyber investigations
while participating in internal review and quality assurance processes.
• Support development and refinement of cyber analysis processes, CONOPS, SOPs,
and investigative methodologies.
• Conduct open-source and intelligence community research to maintain awareness of
emerging cyber threats, malware trends, and adversary tactics, techniques, and
procedures (TTPs).
• Collaborate with internal teams and mission partners across the intelligence community
to support tactical and strategic cyber operations.
• Provide operational updates and analytical findings to leadership and investigative
stakeholders.
Required Skills & Experience
• Active Top Secret Clearance required, with willingness and ability to obtain a Counter
Intelligence (CI) Polygraph.
• BS/BA degree with 5+ years of relevant experience or 9 years with no degree. Advanced
certifications, specialized training, or equivalent hands-on experience may be considered
in lieu of years of experience
• Experience performing host-based forensic analysis utilizing Splunk.
• Experience analyzing network traffic, packet capture (PCAP), and NetFlow data.
• Hands-on experience with industry-standard forensic tools such as:
o Splunk
o EnCase
o Magnet AXIOM
o X-Ways Forensics
• Understanding of cyber intrusion methodologies, attacker kill chains, malware behavior,
and forensic artifact analysis.
• Experience correlating threat indicators and investigative data to support attribution and
operational analysis.