Cyber Forensic Specialist
Accenturefederalservices · Arlington, VA
About this role
**Cyber Forensic Specialist** **About the role** Accenture Federal Services is seeking a skilled, detail-oriented **Cyber Forensic Specialist** to join the **Digital Forensics and Incident Response (DFIR)** team. This role supports the organization’s **Cyber Incident Response Team (CIRT)** with expert digital forensic and investigative support, including sensitive internal investigations in partnership with **HR, Legal, and Insider Threat**. **Key responsibilities** - **DFIR Support** - Collaborate with CIRT to investigate and respond to cybersecurity incidents (e.g., malware, unauthorized access, data breaches, APTs). - Perform digital forensic analysis on laptops, desktops, servers, mobile devices, and network logs to determine root cause and incident scope. - Recommend containment, remediation, and recovery actions. - **Investigative Support** - Conduct internal investigations with HR, Legal, and Insider Threat related to risks to organizational assets/operations and matters requiring electronic evidence collection and analysis. - Analyze electronic communications, file systems, and digital artifacts. - Produce detailed, well-documented reports and findings. - **Litigation Holds & eDiscovery** - Partner with Legal to implement litigation holds and preserve/collect **ESI (Electronically Stored Information)**. - Perform eDiscovery data captures across on-prem and cloud systems in line with legal/regulatory requirements. - Maintain documentation for legal proceedings and audits. - **Evidence Intake & Management** - Serve as the central point for evidence intake, ensuring proper **chain of custody** and documentation. - Enforce evidence management protocols (secure storage, tagging, tracking) and ensure compliance with retention/destruction policies. - **Process Optimization & Tooling** - Use forensic tools such as **EnCase, FTK, X-Ways, Magnet Axiom**. - Improve and document forensic methodologies, workflows, and playbooks. - Stay current on emerging forensic techniques and best practices. - **Collaboration & Training** - Provide guidance/training to CIRT and other internal teams on forensic processes and evidence handling. - Coordinate with outside counsel or external forensic services when needed. **What you need** - **US Citizenship required** - **3–5 years** experience in information security (or equivalent education/experience) - **3+ years** performing digital forensics on physical and cloud systems - **2+ years** event/log analysis experience (e.g., AV, IDS, firewalls, Active Directory, web proxies, DLP, SIEM) - **1+ years** experience investigating/containing/eradicating/preventing compromises (e.g., IP/domain/URL blocks, hash blocks, email purge, device reimage) - **1+ years** collecting/processing/reviewing/producing **ESI** for legal teams - Ability to work independently and deliver prompt solutions - Strong written/oral communication, attention to detail, and interpersonal skills - Experience presenting complex technical information to decision makers - Experience with forensic imaging and analysis tools (e.g., **FTK, Cellebrite, Paladin, EnCase, Autopsy, Nuix**) - Evidence preservation and chain of custody experience - Familiarity with **TCP/IP**, common application protocols, and packet analysis - Experience with static/dynamic malware analysis and indicators of attack/compromise - Basic data parsing/analysis tools (e.g., Excel, grep/sed/awk, regex) - Familiarity with network/host se
Listing freshness
CronJobs last confirmed this listing 18h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.