1

Gcfa Jobs (NOW HIRING)

GCFA, CFCE, GREM, or OSED * 5 years within IR in a large SOC (over 5,000 endpoints) with at least 3 years focused on digital forensics for Operating System or file systems * 3 years of demonstrated ...

GIAC (GCIH / GCIA / GCFA) * Microsoft Certified: Security Operations Analyst (SC-200) * ITIL / PMP (optional but valuable for governance)

GCFA; GCIH; SCYBER * Demonstrated experience across the incident response lifecycle. * Experience with SOAR platforms and automated response workflows (e.g., ServiceNow, Splunk SOAR, Microsoft ...

next page

Showing results 1-20

Gcfa information

See salary details

$17

$44

$60

How much do gcfa jobs pay per hour?

As of Aug 9, 2026, the average hourly pay for gcfa in the United States is $44.14, according to ZipRecruiter salary data. Most workers in this role earn between $34.62 and $54.57 per hour, depending on experience, location, and employer.

What is a GCFA?

A GCFA (GIAC Certified Forensic Analyst) is a cybersecurity professional specializing in digital forensics and incident response. They analyze cyberattacks, investigate data breaches, and recover compromised systems. GCFA-certified professionals work in law enforcement, government agencies, and private organizations to detect threats and secure networks. Their role involves collecting and preserving digital evidence while following industry best practices.

What are the key skills and qualifications needed to thrive as a GCFA, and why are they important?

To thrive as a GCFA (GIAC Certified Forensic Analyst), you need a solid background in computer forensics, incident response, and digital investigations, usually supported by relevant IT or cybersecurity qualifications. Proficiency with forensic analysis tools such as EnCase, FTK, and other evidence collection software, as well as the GCFA certification itself, is essential. Strong analytical thinking, attention to detail, and effective written and verbal communication are important soft skills for this position. These competencies ensure accurate, thorough investigations, strong courtroom testimony, and collaboration with technical and non-technical stakeholders.

What are some common challenges faced by GCFA professionals in their daily work?

GCFA professionals often encounter challenges such as rapidly evolving cyber threats, the need to preserve and analyze large volumes of digital evidence, and ensuring findings stand up to legal scrutiny. Balancing quick response times with thorough, precise forensic analysis can be demanding, particularly when working on multiple incidents or under time-sensitive conditions. Additionally, staying current with new forensic tools and techniques requires ongoing professional development. Working in this field may involve collaboration with legal teams, law enforcement, and other IT security personnel to effectively resolve incidents and mitigate future risks.

More about Gcfa jobs
What cities are hiring for Gcfa jobs? Cities with the most Gcfa job openings:
What are the most commonly searched types of Gcfa jobs? The most popular types of Gcfa jobs are:
What states have the most Gcfa jobs? States with the most job openings for Gcfa jobs include:
Infographic showing various Gcfa job openings in the United States as of August 2026, with employment types broken down into 93% Full Time, 1% Part Time, and 6% Contract. Highlights an 78% Physical, 7% Hybrid, and 15% Remote job distribution, with an average salary of $91,821 per year, or $44.1 per hour.

NCO Technical Lead

Jobtailor

Washington, DC โ€ข On-site

$150 - $210/hr

Other

Posted 4 days ago


Job description

Responsibilities
  • Provide day-to-day technical oversight, coordination, and guidance to contractor personnel performing operational cybersecurity and threat intelligence functions.
  • Lead all activities supporting the National Cybersecurity Operations (NCO) mission including threat intelligence collection and analysis, threat hunting, and incident response coordination.
  • Monitor and analyze cyber threat intelligence relevant to FAA and NAS systems.
  • Produce actionable intelligence products that inform assessment priorities and defensive posture decisions.
  • Coordinate incident response activities when potential security events are identified.
  • Ensure response actions follow established procedures and are documented.
  • Attend all Program Management Reviews with the Program Manager and report on NCO operational support activities, threat intelligence findings, deliverables, and technical issues.
  • Maintain awareness of emerging cyber threats targeting critical infrastructure, aviation systems, and government networks.
  • Brief FAA leadership on threat trends and recommended defensive actions.
  • Collaborate with the Security Assessment Lead and Penetration Testing Lead to ensure assessment and testing priorities reflect the current threat landscape.
  • Develop and maintain standard operating procedures for NCO functions including escalation criteria, reporting templates, and coordination protocols.
  • Manage and oversee contractor staff performing NCO functions.
  • Ensure personnel maintain required qualifications and training.
Requirements
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution
  • At least fifteen (15)+ years of cybersecurity experience with at least 5 years of management and supervisory responsibility over operational cybersecurity, threat intelligence teams, or SOC/CIRT functions.
  • At least 2 years of recent relevant experience (performed within the last 3 years).
  • Demonstrated experience leading incident response and threat intelligence operations in a federal or critical infrastructure environment.
  • Strong understanding of cyber threat intelligence frameworks (MITRE ATT&CK, Diamond Model, Cyber Kill Chain) and experience producing actionable intelligence products.
  • Experience with SIEM platforms, threat intelligence platforms, and endpoint detection and response (EDR) tools.Knowledge of network defense monitoring, log analysis, and anomaly detection in complex, multi-segment network environments.
  • Candidate must have the ability to obtain and maintain a Public Trust Active Secret clearance preferred
  • Security certification such as CISSP, CISM, or CASP required
  • GCIH (GIAC Certified Incident Handler) or GCTI (GIAC Cyber Threat Intelligence) strongly preferred
  • GCFA, GNFA, or GCIA preferred for forensics/network analysis depth
  • CND, CNDA, GDAT, GDSA, GCED, GCFA are directly relevant
#J-18808-Ljbffr