Your role and responsibilities IBM's Cyber Security Incident Response Team (CSIRT) is seeking a high-performing Incident Response Forensic Analyst to support the investigation and response to ...
Your role and responsibilities IBM's Cyber Security Incident Response Team (CSIRT) is seeking a high-performing Incident Response Forensic Analyst to support the investigation and response to ...
Network Forensics Cybersecurity Analyst * Arlington, VA * Information Technology Our Partner ... e., forensic collections, intrusion correlation and tracking, threat analysis, and advising on ...
Network Forensics Cybersecurity Analyst * Arlington, VA * Information Technology Our Partner ... e., forensic collections, intrusion correlation and tracking, threat analysis, and advising on ...
Mid-Level Digital Forensic Analyst
Arlington, VA · On-site
$100 - $125/hr
SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical ... Responsibilities * Conduct forensic examinations of digital data from cellphones, tablets ...
Mid-Level Digital Forensic Analyst
Arlington, VA · On-site
$100 - $125/hr
SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical ... Responsibilities * Conduct forensic examinations of digital data from cellphones, tablets ...
Tharros is seeking a Cyber Security Vulnerability Researcher, Forensic Analyst to conduct digital forensic analysis and incident response in support of NAWCAD Cyber Warfare Division programs at NAS ...
Tharros is seeking a Cyber Security Vulnerability Researcher, Forensic Analyst to conduct digital forensic analysis and incident response in support of NAWCAD Cyber Warfare Division programs at NAS ...
Senior Digital Forensic Analyst
Arlington, VA · On-site
$104K - $166K/yr
Stay current on developments in digital forensics, cybersecurity, forensic law, mobile devices and applications, social media platforms, and encryption/decryption methods. Qualifications Minimum ...
Senior Digital Forensic Analyst
Arlington, VA · On-site
$104K - $166K/yr
Stay current on developments in digital forensics, cybersecurity, forensic law, mobile devices and applications, social media platforms, and encryption/decryption methods. Qualifications Minimum ...
Software Engineering, Computer Science, Computer Engineering, Digital Forensics, Cyber Security); or Non-related Bachelor degree with 2 years proven performance in related assignment(s); or
Software Engineering, Computer Science, Computer Engineering, Digital Forensics, Cyber Security); or Non-related Bachelor degree with 2 years proven performance in related assignment(s); or
Description Tharros is seeking a Cyber Security Vulnerability Researcher, Forensic Analyst to conduct digital forensic analysis and incident response in support of NAWCAD Cyber Warfare Division ...
Description Tharros is seeking a Cyber Security Vulnerability Researcher, Forensic Analyst to conduct digital forensic analysis and incident response in support of NAWCAD Cyber Warfare Division ...
Stay current on developments in digital forensics, cybersecurity, forensic law, mobile devices and applications, social media platforms, and encryption/decryption methods. Qualifications Minimum ...
Stay current on developments in digital forensics, cybersecurity, forensic law, mobile devices and applications, social media platforms, and encryption/decryption methods. Qualifications Minimum ...
Stay current on developments in digital forensics, cybersecurity, forensic law, mobile devices and applications, social media platforms, and encryption/decryption methods. Qualifications Minimum ...
Stay current on developments in digital forensics, cybersecurity, forensic law, mobile devices and applications, social media platforms, and encryption/decryption methods. Qualifications Minimum ...
Conduct cybersecurity and digital forensic investigations involving cellphones, laptops, desktops, tablets, removable media, servers, email systems, cloud platforms, and other electronic devices.
Conduct cybersecurity and digital forensic investigations involving cellphones, laptops, desktops, tablets, removable media, servers, email systems, cloud platforms, and other electronic devices.
Conduct cybersecurity and digital forensic investigations involving cellphones, laptops, desktops, tablets, removable media, servers, email systems, cloud platforms, and other electronic devices.
Conduct cybersecurity and digital forensic investigations involving cellphones, laptops, desktops, tablets, removable media, servers, email systems, cloud platforms, and other electronic devices.
Forensic Analyst
Annapolis Junction, MD · On-site
... Forensics, Cyber Security, Software Engineering, Information Assurance, or Computer Security). • Relevant experience must include the design and/or development of computer or information systems ...
Forensic Analyst
Annapolis Junction, MD · On-site
... Forensics, Cyber Security, Software Engineering, Information Assurance, or Computer Security). • Relevant experience must include the design and/or development of computer or information systems ...
Conduct cybersecurity and digital forensic investigations involving cellphones, laptops, desktops, tablets, removable media, servers, email systems, cloud platforms, and other electronic devices.
Conduct cybersecurity and digital forensic investigations involving cellphones, laptops, desktops, tablets, removable media, servers, email systems, cloud platforms, and other electronic devices.
Conduct cybersecurity and digital forensic investigations involving cellphones, laptops, desktops, tablets, removable media, servers, email systems, cloud platforms, and other electronic devices.
Quick apply
Conduct cybersecurity and digital forensic investigations involving cellphones, laptops, desktops, tablets, removable media, servers, email systems, cloud platforms, and other electronic devices.
Mid-Level Digital Forensic Analyst
Arlington, VA · On-site
$86K - $138K/yr
Stay current on developments in digital forensics, cybersecurity, forensic law, mobile devices and applications, social media platforms, and encryption/decryption methods. Qualifications Minimum ...
Mid-Level Digital Forensic Analyst
Arlington, VA · On-site
$86K - $138K/yr
Stay current on developments in digital forensics, cybersecurity, forensic law, mobile devices and applications, social media platforms, and encryption/decryption methods. Qualifications Minimum ...
Mid-Level Digital Forensic Analyst
Arlington, VA · On-site
$86K - $138K/yr
Stay current on developments in digital forensics, cybersecurity, forensic law, mobile devices and applications, social media platforms, and encryption/decryption methods. Qualifications Minimum ...
Mid-Level Digital Forensic Analyst
Arlington, VA · On-site
$86K - $138K/yr
Stay current on developments in digital forensics, cybersecurity, forensic law, mobile devices and applications, social media platforms, and encryption/decryption methods. Qualifications Minimum ...
As part of the Enterprise Information Security team, this Cybersecurity Engineer (Insider Risk and Forensic Analysis) will have the opportunity to act as a key contributor in the CSOC's growth and ...
As part of the Enterprise Information Security team, this Cybersecurity Engineer (Insider Risk and Forensic Analysis) will have the opportunity to act as a key contributor in the CSOC's growth and ...
As part of the Enterprise Information Security team, this Cybersecurity Engineer (Insider Risk and Forensic Analysis) will have the opportunity to act as a key contributor in the CSOC's growth and ...
As part of the Enterprise Information Security team, this Cybersecurity Engineer (Insider Risk and Forensic Analysis) will have the opportunity to act as a key contributor in the CSOC's growth and ...
As part of the Enterprise Information Security team, this Cybersecurity Engineer (Insider Risk and Forensic Analysis) will have the opportunity to act as a key contributor in the CSOC's growth and ...
As part of the Enterprise Information Security team, this Cybersecurity Engineer (Insider Risk and Forensic Analysis) will have the opportunity to act as a key contributor in the CSOC's growth and ...
Mid-Level Digital Forensic Analyst
$86K - $138K/yr
Stay current on developments in digital forensics, cybersecurity, forensic law, mobile devices and applications, social media platforms, and encryption/decryption methods. Qualifications Minimum ...
Mid-Level Digital Forensic Analyst
$86K - $138K/yr
Stay current on developments in digital forensics, cybersecurity, forensic law, mobile devices and applications, social media platforms, and encryption/decryption methods. Qualifications Minimum ...
Forensic Cyber Security information
See salary details
$57K - $68.7K
1% of jobs
$68.7K - $80.5K
4% of jobs
$80.5K - $92.2K
5% of jobs
$92.2K - $103.9K
9% of jobs
$110.4K is the 25th percentile. Wages below this are outliers.
$103.9K - $115.6K
11% of jobs
$115.6K - $127.4K
10% of jobs
The median wage is $131.9K / yr.
$127.4K - $139.1K
28% of jobs
$145.9K is the 75th percentile. Wages above this are outliers.
$139.1K - $150.8K
14% of jobs
$150.8K - $162.5K
11% of jobs
$162.5K - $174.3K
4% of jobs
$174.3K - $186K
4% of jobs
$57K
$133K
$186K
How much do forensic cyber security jobs pay per year?
What is a forensic cyber security?
A Forensic Cyber Security job involves investigating cybercrimes, analyzing digital evidence, and identifying security breaches. Professionals in this field work to trace cyberattacks, recover lost data, and help law enforcement or organizations strengthen their security measures. They utilize specialized tools to examine compromised systems, detect vulnerabilities, and create reports detailing their findings. Often, forensic cyber security specialists testify in legal cases to explain technical evidence. The role requires expertise in digital forensics, ethical hacking, and incident response.
What skills and qualifications are needed for forensic cyber security?
To thrive as a Forensic Cyber Security professional, you need a solid grounding in digital forensics, cyber threat analysis, and IT security protocols, often backed by a degree in computer science or a related field. Experience with forensic tools such as EnCase, FTK, or X-Ways, and certifications like CISSP, GCFA, or CCFP are highly valued in the industry. Strong analytical thinking, meticulous attention to detail, and effective written and verbal communication skills are crucial for success. These skills and qualities ensure accurate investigation of cyber incidents, preservation of digital evidence, and clear reporting for legal and organizational decision-making.
What are typical challenges faced by forensic cyber security professionals?
Forensic Cyber Security professionals often face the challenge of working with incomplete or damaged digital evidence, requiring strong problem-solving skills and creative thinking to reconstruct events. They may work under tight deadlines during active security incidents, collaborating with IT, legal, and law enforcement teams to piece together digital footprints. Additionally, staying current with constantly evolving cyber threats and new malware techniques is crucial for accurate investigations. These challenges make the role both demanding and rewarding, offering continuous learning and professional growth opportunities.
Is forensic cyber security a good career?
What cities are hiring for Forensic Cyber Security jobs?
Cities with the most Forensic Cyber Security job openings:
What are the most commonly searched types of Forensic Cyber Security jobs?
The most popular types of Forensic Cyber Security jobs are:
What states have the most Forensic Cyber Security jobs?
States with the most job openings for Forensic Cyber Security jobs include:
What job categories do people searching Forensic Cyber Security jobs look for?
The top searched job categories for Forensic Cyber Security jobs are:

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 24 days ago
Key responsibilities
Conduct forensic investigations on endpoint, network, and cloud environments
Collect, preserve, and analyze digital evidence in accordance with established standards
Support incident response activities, including triage, containment, eradication, and recovery
IBM rating
8.0
Based on 76 frontline employees who took The Breakroom Quiz
125th of 247 rated software companies
Job description
The Office of the CISO has the responsibility to safeguard not only IBM systems but those of clients we support around the globe. The IBM CISO office is comprised of teams that cover all aspects of security - from Vulnerabilty Management, Threat Detection, Security Operations, Product Security, Mail Security, System Inventory, Endpoint Detection, as well as Computer Security Incidence Response. CSIRT is responsible for maintaining and managing the IBM internal global incident response process for cybersecurity and data privacy cases across IBM.
We are looking for individuals who bring both technical depth and professional discipline-those who can dig into the evidence, uncover the story behind an incident, and communicate it clearly to drive action.
Your role and responsibilities
IBM's Cyber Security Incident Response Team (CSIRT) is seeking a high-performing Incident Response Forensic Analyst to support the investigation and response to cybersecurity incidents across the Americas region.
In this role, you will work at the intersection of incident response, digital forensics, and threat analysis, partnering closely with responders, threat detection teams, and leadership to investigate security events, preserve forensic evidence, and drive timely containment and remediation.
This is a hands-on analytical role requiring the ability to translate complex technical findings into actionable insights, enabling both operational response and executive decision-making. The successful candidate will demonstrate strong technical depth, investigative rigor, and the ability to operate effectively in high-pressure environments.
Key Responsibilities:
-Conduct forensic investigations on endpoint, network, and cloud environments
-Collect, preserve, and analyze digital evidence in accordance with established standards
-Support incident response activities, including triage, containment, eradication, and recovery
-Correlate forensic evidence with threat intelligence and detection signals
-Ability to analyze disk images, logs, and recovered data
-Reconstruct attack timelines and identify root cause and impact
-Document findings and produce clear, defensible reports for technical and non-technical stakeholders
-Collaborate across CSIRT, SOC, Legal, and Compliance teams as needed
-Contribute to post-incident reviews and continuous improvement of response capabilities
Required education
Associate's Degree/College Diploma
Preferred education
Bachelor's Degree
Required technical and professional expertise
- 3-5 years of experience in Incident Response, SOC and/or Digital Forensics in a global corporate environment
- Key Technical Skills
- Strong digital forensics expertise across endpoints, systems, and network artifacts; experience with industry-standard tools (e.g., EnCase, FTK, Autopsy)
- Ability to collect, preserve, and analyze evidence while maintaining chain of custody and audit readiness
- Strong investigative and analytical skills, including correlation of logs, endpoint, and network data to determine root cause and reconstruct timelines
- Experience operating within incident response workflows and using EDR, SIEM, and detection platforms in active incident environments
- Understanding of attacker TTPs, with exposure to malware analysis or memory forensics preferred
- Analysis using EDR tooling such as Crowdstrike or Microsoft Defender for Endpoint (MDE)
- Basic scripting/automation skills (e.g., Python, PowerShell) are a plus
- Strong understanding of Windows, Mac, and Linux operating systems
- Solid working knowledge of networking topology, technology and tools, such as firewalls, proxies, IDS/IPS, EDR
Event analysis and correlation
Excellent technical writing and presentation skills
- The ability to work independently and effectively, as well as in a group setting required.
Preferred technical and professional experience
- Demonstrated computer forensic investigations experience
- Demonstrated knowledge of commercial and open-source forensic tools, such as X-Ways, Axiom, Autopsy, ELK, SIFT, Plaso, etc
- Familiarity with enterprise cybersecurity tooling (EDR, SIEM, forensic
platforms) Scripting & Automation (Nice to Have)
- Certifications such as: GCFA, CHFI, GCIH (or equivalent experience, nice to have)
- Demonstrated knowledge of analysis with EDR tooling, such as Crowdstrike or Microsoft Defender for Endpoint (MDE)
- Knowledge of incident response and analysis in cloud environments, such as IBM Cloud, AWS, or Azure
- Ability to successfully lead and facilitate information gathering meetings
- Experience managing small and large scale cyber security incidents
ABOUT BUSINESS UNIT
IBM Systems helps IT leaders think differently about their infrastructure. IBM servers and storage are no longer inanimate - they can understand, reason, and learn so our clients can innovate while avoiding IT issues. Our systems power the world's most important industries and our clients are the architects of the future. Join us to help build our leading-edge technology portfolio designed for cognitive business and optimized for cloud computing.
YOUR LIFE @ IBM
In a world where technology never stands still, we understand that, dedication to our clients success, innovation that matters, and trust and personal responsibility in all our relationships, lives in what we do as IBMers as we strive to be the catalyst that makes the world work better.
Being an IBMer means you'll be able to learn and develop yourself and your career, you'll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background.
Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do.
Are you ready to be an IBMer?
ABOUT IBM
IBM's greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world.
Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we're also one of the biggest technology and consulting employers, with many of the Fortune 500 companies relying on the IBM Cloud to run their business.
At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computing and blockchain. Now it's time for you to join us on our journey to being a responsible technology innovator and a force for good in the world.
IBM is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, neurodivergence, age, or other characteristics protected by the applicable law. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
OTHER RELEVANT JOB DETAILS
IBM offers a competitive and comprehensive benefits program. Eligible employees may have access to:
- Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
- Financial programs such as 401(k), the IBM Employee Stock Purchase Plan, financial counseling, life insurance, short & long- term disability coverage, and opportunities for performance based salary incentive programs
- Generous paid time off including 12 holidays, minimum 56 hours sick time, 120 hours vacation, 12 weeks parental bonding leave in accordance with IBM Policy, and other Paid Care Leave programs. IBM also offers paid family leave benefits to eligible employees where required by applicable law
- Training and educational resources on our personalized, AI-driven learning platform where IBMers can grow skills and obtain industry-recognized certifications to achieve their career goals
- Diverse and inclusive employee resource groups, giving & volunteer opportunities, and discounts on retail products, services & experiences
We consider qualified applicants with criminal histories, consistent with applicable law.
This position was posted on the date cited in the key job details section and is anticipated to remain posted for 21 days from this date or less if not needed to fill the role.
IBM will not be providing visa sponsorship for this position now or in the future. Therefore, in order to be considered for this position, you must have the ability to work without a need for current or future visa sponsorship.
The compensation range and benefits for this position are based on a full-time schedule for a full calendar year. The salary will vary depending on your job-related skills, experience and location. Pay increment and frequency of pay will be in accordance with employment classification and applicable laws. For part time roles, your compensation and benefits will be adjusted to reflect your hours. Benefits may be pro-rated for those who start working during the calendar year.
About IBM
Sourced by ZipRecruiter
At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most challenging problems? If so, lets talk.
Industry
It services
Company size
10,000+ Employees
Headquarters location
Armonk, NY, US
Year founded
1911