... network topology and device configurations identifying critical security concerns and providing ... forensics liaison to stakeholders and explaining investigation details Required Skills: - U.S.
... network topology and device configurations identifying critical security concerns and providing ... forensics liaison to stakeholders and explaining investigation details Required Skills: - U.S.
... network topology and device configurations identifying critical security concerns and providing ... forensics liaison to stakeholders and explaining investigation details Required Skills: - U.S.
... network topology and device configurations identifying critical security concerns and providing ... forensics liaison to stakeholders and explaining investigation details Required Skills: - U.S.
The candidate should have experience in network forensics, IP address tracking, and mitigation of obscured or falsified IP address origins to ensure accurate identification and enhance investigative ...
New
The candidate should have experience in network forensics, IP address tracking, and mitigation of obscured or falsified IP address origins to ensure accurate identification and enhance investigative ...
New
Senior Network Engineer
Chantilly, VA · Hybrid
$106K - $145K/yr
The candidate should be a cybersecurity expert with experience in network forensics, IP address tracking, and mitigation of obscured or falsified IP address origins to ensure accurate identification ...
Senior Network Engineer
Chantilly, VA · Hybrid
$106K - $145K/yr
The candidate should be a cybersecurity expert with experience in network forensics, IP address tracking, and mitigation of obscured or falsified IP address origins to ensure accurate identification ...
Network Systems Engineer
Chantilly, VA · On-site
The candidate should have experience in network forensics, IP address tracking, and mitigation of obscured or falsified IP address origins to ensure accurate identification and enhance investigative ...
New
Network Systems Engineer
Chantilly, VA · On-site
The candidate should have experience in network forensics, IP address tracking, and mitigation of obscured or falsified IP address origins to ensure accurate identification and enhance investigative ...
New
Cyber Threat (Forensics) Analyst, Senior Associate
Chantilly, VA · On-site
$104K - $166K/yr
Candidates will conduct in-depth host-based and network-based digital forensic examinations using both industry-wide forensic and network tools, as well as specialized applications to forward the ...
Cyber Threat (Forensics) Analyst, Senior Associate
Chantilly, VA · On-site
$104K - $166K/yr
Candidates will conduct in-depth host-based and network-based digital forensic examinations using both industry-wide forensic and network tools, as well as specialized applications to forward the ...
Network forensics and analysis * Generate professional technical exploitation reports of interest to the customer and the Intel Community. * Perform application and internet activities analysis to ...
Quick apply
Network forensics and analysis * Generate professional technical exploitation reports of interest to the customer and the Intel Community. * Perform application and internet activities analysis to ...
Strong background in endpoint and network forensics, log analysis, and forensic tooling ... Excellent communication and executive reporting skills, including the ability to translate ...
Strong background in endpoint and network forensics, log analysis, and forensic tooling ... Excellent communication and executive reporting skills, including the ability to translate ...
Network forensics and analysis * Generate professional technical exploitation reports of interest to the customer and the Intel Community. * Perform application and internet activities analysis to ...
Network forensics and analysis * Generate professional technical exploitation reports of interest to the customer and the Intel Community. * Perform application and internet activities analysis to ...
The candidate should have experience in network forensics, IP address tracking, and mitigation of obscured or falsified IP address origins to ensure accurate identification and enhance investigative ...
New
The candidate should have experience in network forensics, IP address tracking, and mitigation of obscured or falsified IP address origins to ensure accurate identification and enhance investigative ...
New
Cyber Threat (Forensics) Analyst, Senior Associate
Chantilly, VA · On-site
$104K - $166K/yr
Candidates will conduct in-depth host-based and network-based digital forensic examinations using both industry-wide forensic and network tools, as well as specialized applications to forward the ...
Cyber Threat (Forensics) Analyst, Senior Associate
Chantilly, VA · On-site
$104K - $166K/yr
Candidates will conduct in-depth host-based and network-based digital forensic examinations using both industry-wide forensic and network tools, as well as specialized applications to forward the ...
The client is seeking Network Forensics Cybersecurity Analysts to support this critical customer mission. Responsibilities: - Assists the Government lead in coordinating teams in preliminary incident ...
The client is seeking Network Forensics Cybersecurity Analysts to support this critical customer mission. Responsibilities: - Assists the Government lead in coordinating teams in preliminary incident ...
The client is seeking Network Forensics Cybersecurity Analysts to support this critical customer mission. Responsibilities: - Assists the Government lead in coordinating teams in preliminary incident ...
The client is seeking Network Forensics Cybersecurity Analysts to support this critical customer mission. Responsibilities: - Assists the Government lead in coordinating teams in preliminary incident ...
Cyber Threat (Forensics) Analyst, Senior Associate
Chantilly, VA · On-site
$104K - $166K/yr
Candidates will conduct in-depth host-based and network-based digital forensic examinations using both industry-wide forensic and network tools, as well as specialized applications to forward the ...
Cyber Threat (Forensics) Analyst, Senior Associate
Chantilly, VA · On-site
$104K - $166K/yr
Candidates will conduct in-depth host-based and network-based digital forensic examinations using both industry-wide forensic and network tools, as well as specialized applications to forward the ...
Perform mobile device and computer forensics, and wired and wireless network exploitation Work with All-Source intelligence and use social media analysis to assist with network forensics Properly ...
Perform mobile device and computer forensics, and wired and wireless network exploitation Work with All-Source intelligence and use social media analysis to assist with network forensics Properly ...
Required : • Ten (10) years of experience with security operations, network forensics, insider threat. • Bachelor's degree in computer science, information systems, international relations, or ...
New
Required : • Ten (10) years of experience with security operations, network forensics, insider threat. • Bachelor's degree in computer science, information systems, international relations, or ...
New
... forensics, network forensics, log analysis, and malware triage in support of hunt operations • Interface with client contact(s) and staff in a constructive and professional manner • Utilize ...
... forensics, network forensics, log analysis, and malware triage in support of hunt operations • Interface with client contact(s) and staff in a constructive and professional manner • Utilize ...
Perform mobile device and computer forensics, and wired and wireless network exploitation Work with All-Source intelligence and use social media analysis to assist with network forensics Properly ...
Perform mobile device and computer forensics, and wired and wireless network exploitation Work with All-Source intelligence and use social media analysis to assist with network forensics Properly ...
Computer Science Adjunct Faculty: Digital forensics, Cyber law and Ethics, Network forensics, Clo...
Cranford, NJ · On-site
Digital forensics, Cyber law and Ethics, Network forensics, Cloud and Personal device forensics (EVENING COURSES) - Fall 2026 Campus Cranford, Elizabeth, Plainfield Department Computer Science ...
Computer Science Adjunct Faculty: Digital forensics, Cyber law and Ethics, Network forensics, Clo...
Cranford, NJ · On-site
Digital forensics, Cyber law and Ethics, Network forensics, Cloud and Personal device forensics (EVENING COURSES) - Fall 2026 Campus Cranford, Elizabeth, Plainfield Department Computer Science ...
Conduct forensic extraction and analysis of data and electronic evidence from seized digital media * Analyze computer network security settings, server, system, router, firewall, intrusion detection ...
Conduct forensic extraction and analysis of data and electronic evidence from seized digital media * Analyze computer network security settings, server, system, router, firewall, intrusion detection ...
Network Forensics information
See salary details
$22K - $34.8K
0% of jobs
$34.8K - $47.5K
0% of jobs
$47.5K - $60.3K
5% of jobs
$60.3K - $73.1K
11% of jobs
$83.3K is the 25th percentile. Wages below this are outliers.
$73.1K - $85.9K
12% of jobs
$85.9K - $98.6K
15% of jobs
The median wage is $106K / yr.
$98.6K - $111.4K
14% of jobs
$111.4K - $124.2K
17% of jobs
$126.4K is the 75th percentile. Wages above this are outliers.
$124.2K - $137K
14% of jobs
$137K - $149.7K
6% of jobs
$149.7K - $162.5K
7% of jobs
$22K
$106.6K
$162.5K
How much do network forensics jobs pay per year?
What are the key skills and qualifications needed to thrive in the Network Forensics position, and why are they important?
To thrive in Network Forensics, you need strong analytical abilities, in-depth knowledge of networking protocols, cybersecurity concepts, and a degree in computer science or a related field. Familiarity with tools such as Wireshark, EnCase, FTK, and certifications like GCFA or CFCE is highly valuable. Attention to detail, critical thinking, and effective communication skills are essential soft qualities for this role. These skills enable professionals to accurately investigate network incidents, interpret digital evidence, and collaborate efficiently with technical and non-technical stakeholders.
What are the typical day-to-day responsibilities for someone working in Network Forensics?
Network Forensics professionals spend their days analyzing network traffic, identifying security breaches or anomalous activities, and reconstructing the timeline of events using specialized forensic tools. They often collaborate with IT security teams, law enforcement, or legal departments to gather, preserve, and report on digital evidence. Preparing detailed documentation and presenting findings clearly to both technical and non-technical audiences is also a vital part of the job. This role can involve responding to incidents in real time as well as conducting thorough post-incident investigations, making adaptability and a meticulous approach important for success.
What is a Network Forensics job?
A Network Forensics job involves analyzing network traffic to detect, investigate, and mitigate cybersecurity incidents. Professionals in this role collect and examine digital evidence to identify security breaches, malicious activities, or policy violations. They use specialized tools to track intrusions, reconstruct cyberattacks, and support legal proceedings if necessary. This role is crucial for maintaining network security, preventing data breaches, and ensuring compliance with cybersecurity regulations.

Job description
TS/SCI
Client seeking Cyber Forensics Analysts to support the DHS Hunt and Incident Response Team (HIRT). This team secures the Nation's cyber and communications infrastructure while providing front line response for cyber incidents and hunting for malicious cyber activity. The client, as a prime contractor to DHS, performs HIRT investigations to develop a diagnosis of the severity of breaches. Contract personnel provide front line response for digital forensics/incident response and proactively hunting for malicious cyber activity for this critical customer mission.
Responsibilities:
- Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack
- Assesses network topology and device configurations identifying critical security concerns and providing security best practice recommendations
- Collects network intrusion artifacts (e.g., PCAP, domains, URI's, certificates, etc.) and uses discovered data to enable mitigation of potential incidents
- Collects network device integrity data and analyze for signs of tampering or compromise
- Analyzes identified malicious network and system log activity to determine weaknesses exploited, exploitation methods, effects on system and information
- Tracking and documenting on-site incident response activities and providing updates to leadership through executive summaries and in-depth technical reports
- Planning, coordinating and directing the inventory, examination and comprehensive technical analysis of computer related evidence
- Serving as technical forensics liaison to stakeholders and explaining investigation details
Required Skills:
- U.S. Citizenship
- Must have an active Secret clearance (TS/SCI eligible) and be able to obtain DHS Suitability
- 8+ years of directly relevant experience in cyber forensic and network investigations using leading edge technologies and industry standard forensic tools
- Experience with reconstructing a malicious attack or activity
- Ability to characterize and analyze network traffic, identify anomalous activity / potential threats, analyze anomalies in network traffic using metadata
- Ability to create forensically sound duplicates of evidence (forensic images)
- Able to write cyber investigative reports documenting forensics findings
- In depth knowledge and experience of:
• identifying different classes and characterization of attacks and attack stages
• CND policies, procedures and regulations
• proactive analysis of systems and networks, to include creating trust levels of critical resources
• system and application security threats and vulnerabilities
• of network topologies, Wi-Fi Networking, and TCP/IP protocols
• Splunk (or other SIEMs)
• Vulnerability scanning, assessment and monitoring tools such as Security Center, Nessus, and Endgame
• MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
- Must be able to work collaboratively across physical locations.
Desired Skills:
- Experience and proficiency with the following tools and techniques:
• EnCase, FTK, SIFT, X-Ways, Volatility, WireShark, Sleuth Kit/Autopsy, and Snort
• EDR Tools: Crowdstrike, Carbon Black, Etc
• Carving and extracting information from PCAP data
• Non-traditional network traffic: Command and Control
• Preserving evidence integrity according to national standards
• Designing cyber security systems and environments in a Linux environment
• Virtualized environments
• Conducting all-source research
Required Education:
8+ years of experience and BS Computer Science, Cybersecurity, Computer Engineering or related degree; or HS Diploma and 10+ years of host or digital forensics or network forensic experience
Desired Certifications:
- GCFA, GCFE, EnCE, CCE, CFCE, CEH, CCNA, CCSP, CCIE, OSCP, GNFA
About Beyond Sof
Sourced by ZipRecruiter
Company size
11 - 50 Employees
Headquarters location
McLean, VA, US
Year founded
2011