Cyber Security Forensics Analyst
USA-VA-Herndon, USA-Remote Work
Full Time Mid-level / Intermediate Clearance required USD 73K - 136K * est.
General information
Requisition # R60751 Locations USA-VA-Herndon, USA-Remote Work Posting Date 05/29/2025 Security Clearance Required Secret Remote Type Hybrid Time Type Full timeDescription & Requirements
Transform the future of federal services with ManTech! Join a vibrant, energetic team committed to enhancing national security and public services through innovative tech. Since 1968, we’ve partnered with Federal Civilian sectors to deliver impactful solutions. Engage in exciting projects in Digital Transformation, Cybersecurity, IT, Data Analytics and more. Ignite your career and drive change. Your journey starts now—innovate and excel with ManTech!ManTech seeks a motivated, career and customer-oriented Midlevel Cyber Security Forensics Analyst to join our team in the DC, Maryland, and Virginia (DMV) area.
In this role you will be responsible for conducting advanced digital forensics investigations, analyzing cyber threats, and developing strategies to mitigate risks. This role requires a deep understanding of cyber forensics, the MITRE ATT&CK framework, and the MITRE D3FEND framework.
Responsibilities include, but are not limited to:
- Lead and conduct complex digital forensics investigations, including data recovery, analysis, and reporting; write forensics and incident response reports, investigate computer attacks, and extract data from electronic systems; Draft and brief contract and government leadership as needed
- Utilize the MITRE ATT&CK framework and other techniques to identify, assess, and address cyber threats and vulnerabilities; conduct technical analysis against target systems and networks, identify vulnerabilities, and support the development of new exploitation techniques
- Apply the MITRE D3FEND framework to develop and implement defensive measures against cyber threats; collaborate with other cybersecurity professionals, law enforcement agencies, and intelligence organizations to share information and coordinate response efforts.
- Analyze cyber activities to identify entities of interest, determine malicious behavior, and recognize patterns and linkages; conduct dynamic malware analysis and performing memory and dead-box forensics.
- Investigate computer and information security incidents to determine the extent of compromise to information and automated information systems.
- Perform long-term and time-sensitive in-depth technical analysis of malicious code (malware), developing defensive countermeasures, and producing reports for dissemination.
- Collaborate with the Splunk team to implement, enhance, or change existing use cases;.assess scope of malware campaigns and determine necessary remediation actions; conduct remote compromise assessments and producing assessment reports.
Minimum Qualifications:
- Bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field
- 3+ years of related experience
- 8570 compliant certifications in IAT Level III, and one of the following relevant certifications- GIAC Certified Forensic Analyst (GCFA), Certified Information Systems Security Professional (CISSP), or Certified Cyber Forensics Professional (CCFP).
- Knowledge and experience with Threat Intel Frameworks (e.g. Cyber Kill Chain, MITRE ATT&CK, Diamond Model)
- Demonstrated experience using EnCase, FTK, and Open-Source methods and tools to perform Computer Forensic investigations
- Experience with Splunk, CrowdStrike Falcon, Security Onion, EnCase, Axiom, FTK, Volatility, Suricata,
- Experience with network topologies and network security devices (e.g. Firewall, IDS/IPS, Proxy, DNS, WAF, etc).
Clearance Requirements:
- Must have a current/active Secret clearance with the ability to obtain and maintain a TS/SCI.
- The ability to obtain and maintain a DHS EOD suitability is required prior to starting this position.
Physical Requirements:
- Must be able to remain in a stationary position 50%
- Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer
- The person in this position needs to occasionally move about inside the office to access file cabinets, office machinery, etc.
ManTech International Corporation considers all qualified applicants for employment without regard to disability or veteran status or any other status protected under any federal, state, or local law or regulation.
If you need a reasonable accommodation to apply for a position with ManTech, please email us at careers@mantech.com and provide your name and contact information.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Analytics CISSP Clearance Clearance Required Computer Science CrowdStrike Cyber Kill Chain Data Analytics DNS DoDD 8570 EnCase Firewalls Forensics GCFA GIAC IDS Incident response IPS Malware MITRE ATT&CK Network security Security Clearance Splunk TS/SCI Vulnerabilities
Perks/benefits: Career development
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.