BAE Systems
Posted 2mo ago

Digital Forensics Analyst ( Python, Splunk, Arcsight)

BAE Systems
Falls Church or Virginia or United States
$133k-$226k/yrHybridFull Time
Responsibilities
  • conducting analysis
  • leading team
  • developing automation
Requirements
  • Must be eligible for US Secret clearance
  • Industry certification required. Experience in digital forensics
  • Incident response, FTK
  • Splunk
  • Arcsight
  • Python scripting
  • Report writing
  • Case management, and forensic laboratory processes
Technical tools mentioned
Forensic Toolkit (FTK)Microsoft PurviewPythonSplunkArcsight

Job description

Job Description

BAE Systems has a job opening for a Digital Forensics Analyst. The Forensics Analyst will conduct digital media acquisition and analysis, team leadership and mentoring, and incident response analysis in an enterprise network environment.  The candidate will have the ability to perform deep dive analysis of preserved and collected digital evidence to restore deleted files, determine usage patterns, Internet history, USB analysis, data carving/recovery, and other advanced analytical processes to recover evidence and artifacts in support of a variety of case types. The candidate will be familiar with Incident Response and Handling best practices in accordance with NIST SP documentation (800-61, etc.). Digital forensic and incident handling case types may include: advanced malware, digital media misuse, insider threat, and potential criminal conduct. This position requires ongoing proficiency in digital and mobile forensic tools, practices, and procedures, as well as emerging threats to networks and systems. Additionally, this role is responsible for producing and managing automation improvements in the Python scripting language.

State/Province

Virginia

Salary Max Point

226035

Clearance Level – Must be able to obtain for position

Secret

Shift

1st Shift

Union Job

None

Business Area

ESS IT

City

Falls Church

Job Posting Title

Digital Forensics Analyst ( Python, Splunk, Arcsight)

Required Skills and Education

Must be eligible to possess a final US Secret Security Clearance. Minimum of one industry recognized technical certification.

Demonstrated experience in the following skills:
 
  • Written and verbal communications.
  • Professional and technical report writing.
  • Ability to make recommendations to senior leadership in all matters involving digital forensics.
  • Ability to work independently as well as in a team environment.
  • Demonstrated knowledge of current digital forensic techniques and procedures.
  • Knowledge of the forensic laboratory accreditation process.
  • Creative problem solving abilities.
  • Ability to anticipate and respond to changing priorities in a professional manner (triage, prioritization, multi-tasking, project scheduling).
  • Ability to collaborate with and provide support to internal and external customers.
  • Case tracking and investigation management.
Experience with the following tools/languages:
  • Forensic Toolkit (FTK)
  • Microsoft Purview
  • Python
  • Splunk
  • Arcsight
At least one of the following certifications:
  • EnCase® Certified Examiner (EnCE)
  • GIAC Certified Forensic Examiner (GCFE)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Certified Enterprise Defender (GCED)
  • GIAC Certified Incident Handler (GCIH)
  • Access Data Certified Examiner (ACE)
  • Certified Ethical Hacker (CEH)
  • Certified Computer Examiner (CCE)

Company

123_BAE Systems Shared Svcs Inc

Postal Code

22042

Regular or Temporary

Regular

Posting Requirements

Internal/External

Department

IT_CYBGSOC_Cyber GSOC

Country

United States

Job Family

IT Systems Security

Preferred Skills and Education

  • 8+ Years Digital Forensics experience.
  • 5+ years incident response and handling experience.
  • Bachelor’s Degree in Criminal Justice, Digital Forensics, Computer Science, or a related discipline.
  • Relevant forensics or incident handling certification.

Salary Min Point

132962

Travel Percentage

<10%

About BAE Systems, Inc.

BAE Systems, Inc. is the U.S. subsidiary of BAE Systems plc, an international defense, aerospace and security company which delivers a full range of products and services for air, land and naval forces, as well as advanced electronics, security, information technology solutions and customer support services. Improving the future and protecting lives is an ambitious mission, but it’s what we do at BAE Systems. Working here means using your passion and ingenuity where it counts – defending national security with breakthrough technology, superior products, and intelligence solutions. As you develop the latest technology and defend national security, you will continually hone your skills on a team—making a big impact on a global scale. At BAE Systems, you’ll find a rewarding career that truly makes a difference.

This position will be posted for at least 5 calendar days. The posting will remain active until the position is filled, or a qualified pool of candidates is identified.

U.S. Person Required

Yes

Typical Education and Experience

Typically a Bachelor's Degree and 8 years work experience or equivalent experience

Job Category

Engineering & Technology

Physical location of the job

Hybrid

U.S. Citizenship Required

Yes

About BAE Systems

Designs and manufactures advanced defense and aerospace systems.

Similar jobs

Digital Forensics Analyst roles near Falls Church, Virginia
1mo
Save
Mark Applied
Hide
AOUSC - Digital Forensics Analyst
Washington, District of Columbia, United States
HybridFull Time
cFocus Software
cFocus Software: Provides cybersecurity compliance and enterprise IT services for government.
3+ YOEActive Public Trust clearance, BS in computer science/IT or related, 3 years digital forensics experience, expertise with Axiom, EnCase, FTK, X-Ways, Volatility, and knowledge of file systems, OS artifacts, and federal evidence guidelines.
Axiom, EnCase, FTK, X-Ways, Volatility
2mo
Save
Mark Applied
Hide
Digital Forensics Analyst
Tysons Corner, Virginia, United States
OnsiteFull Time
Defianx
Defianx: Provides specialized cybersecurity engineering and zero-trust architecture solutions.
4+ YOERequires Secret clearance, 4+ years experience, advanced digital forensics knowledge, experience across Windows/Linux/macOS/cloud/mobile, strong documentation skills, and relevant forensic certifications (GCFA, GCFE, EnCE, CHFI, CFCE).
Windows, Linux, macOS
2mo
Save
Mark Applied
Hide
Digital Forensics Analyst
Chantilly, Virginia, United States
OnsiteFull Time
SAIC
SAICNASDAQ: SAIC: Provides government and defense clients with technology and engineering services.
14+ YOEActive TS/SCI with CI Poly; bachelor’s with 14+ years, master’s 12+, PhD/JD 9+; experience with forensic tools (Axiom, Cellebrite, EnCase, FTK); strong communication and reporting skills.
Axiom, Cellebrite, EnCase, FTK
6mo
Save
Mark Applied
Hide
Digital Forensics Analyst
Alexandria, Virginia, United States
$101k-$152k/yr HybridFull Time
Applied Information Sciences
Applied Information Sciences: Delivers cloud transformation and software engineering services to organizations.
5+ YOE5+ years in digital forensics including Windows, Linux, MacOS; disk imaging; mobile forensics; malware analysis; cloud forensics (M365, Azure, AWS); EDR/SIEM usage; strong documentation; Secret clearance.
EDR, SIEM, Full Packet Capture, EnCase, SANS methodologies, CloudTrail, IAM logs, Microsoft 365, Azure, AWS, Disk imaging
2w
Save
Mark Applied
Hide
Digital Forensics / Malware Analyst
Bethesda, Maryland, United States
HybridFull Time
Digital Global Connectors
Digital Global Connectors: Provides cybersecurity, engineering, and compliance services to federal agencies.
5+ YOEBachelor's degree,5+ years digital forensics or malware analysis,ability to obtain Tier 2 Public Trust,U.S. citizenship,experience with forensic and malware tools,strong technical writing and communication.
EnCase Forensic, FTK, Magnet AXIOM, Autopsy, Velociraptor, Volatility Framework, Wireshark, Ghidra, IDA Pro, x64dbg, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Sentinel, Splunk Enterprise Security, VirusTotal, Cuckoo Sandbox, Any.Run, Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), MITRE ATT&CK Framework, Microsoft Office Suite, ServiceNow, Jira