Job Requirements
Washington, DC
Intel Agency (NSA, CIA, FBI, etc) Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Forensics Specialist Senior
CBP BI - High Trust
Washington DC
$180,000
Years of experience - 7+ years
Education - Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field may reduce required experience to 5 year
Certification - At least one Tier 3 certification
Job Description -
The Contractor shall support SOC investigations and digital forensic tasks according to established policies, handbooks, and CBP CDF Standard Operating Procedures (SOPs). This includes conducting forensic analysis on malware samples, desktops, laptops, mobile devices, and network appliances.
• Conduct enterprise and individual system(s) endpoint (e.g., Windows, Linux, Mac, and Cloud systems) and network based digital forensic analysis in support of Cyber Defense Forensics or Insider Threat investigations.
• Leverage commercially available and open-source forensic tools to efficiently perform forensic analysis.
• Assist with maintaining CBP SOC's Forensics lab equipment, while also providing recommendations on how to modernize or enhance the lab capability.
• Assist with conducting formal digital forensic investigations and document findings in formal investigation reports.
• Assist with performing email hygiene activities in support of CBP investigations when necessary.
• Support enterprise recovery efforts as necessary to ensure that security events and incidents are properly remediated prior to reconstitution.
• Assist with categorizing, prioritizing, and reporting on security events in accordance with CBP CDF SOPs and other relevant policy documents.
• Serve as Subject Matter Experts (SMEs) in the preservation of evidence, which includes a deep understanding of proper chain of custody and proper storage, handling, and transmission procedures for various data sets including, but not limited to, Sensitive But Unclassified (SBU), For Official Use Only (FOUO), Law Enforcement Sensitive (LES), CONFIDENTIAL, SECRET and TOP SECRET information.
• Assist with creating and escalating cases via ticket management system to proper law enforcement entities in compliance with CBP policy and SOPs.
• Answer and respond to security events reported via external and /or internal parties via phone calls and group mailboxes.
• Assist with authoring, updating, and modernizing CBP CDF SOPs and Playbooks.
• Manage the lifecycle of CDF investigations from creation to closure in accordance with CBP Policy and Procedures.
• Assist with performing static and dynamic file analysis to identify malware characteristics, intent, and origin.
• Assist with conducting malware analysis and providing Malware Analysis Reports.
• Assist with creating metrics and Key Performance Indicators (KPIs) detailing the operational status and performance of the Cyber Defense Forensics.
• Assist with providing requirements, playbooks, and workflows to support automation of Cyber Defense Forensics tasks.
• Provide support for the CBP Foreign Travel Service with pre- and post-scans of all CBP laptops and mobile devices before and after a CBP employee's approved travel. Perform forensics investigation analysis when necessary.
• Provide support for the CBP Separation and File Transfer Scans by identifying any content that may contain FOUO, For Official Use Only, LES, or Law Enforcement Sensitive keywords.
CBP BI - High Trust
Washington DC
$180,000
Years of experience - 7+ years
Education - Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field may reduce required experience to 5 year
Certification - At least one Tier 3 certification
Job Description -
The Contractor shall support SOC investigations and digital forensic tasks according to established policies, handbooks, and CBP CDF Standard Operating Procedures (SOPs). This includes conducting forensic analysis on malware samples, desktops, laptops, mobile devices, and network appliances.
• Conduct enterprise and individual system(s) endpoint (e.g., Windows, Linux, Mac, and Cloud systems) and network based digital forensic analysis in support of Cyber Defense Forensics or Insider Threat investigations.
• Leverage commercially available and open-source forensic tools to efficiently perform forensic analysis.
• Assist with maintaining CBP SOC's Forensics lab equipment, while also providing recommendations on how to modernize or enhance the lab capability.
• Assist with conducting formal digital forensic investigations and document findings in formal investigation reports.
• Assist with performing email hygiene activities in support of CBP investigations when necessary.
• Support enterprise recovery efforts as necessary to ensure that security events and incidents are properly remediated prior to reconstitution.
• Assist with categorizing, prioritizing, and reporting on security events in accordance with CBP CDF SOPs and other relevant policy documents.
• Serve as Subject Matter Experts (SMEs) in the preservation of evidence, which includes a deep understanding of proper chain of custody and proper storage, handling, and transmission procedures for various data sets including, but not limited to, Sensitive But Unclassified (SBU), For Official Use Only (FOUO), Law Enforcement Sensitive (LES), CONFIDENTIAL, SECRET and TOP SECRET information.
• Assist with creating and escalating cases via ticket management system to proper law enforcement entities in compliance with CBP policy and SOPs.
• Answer and respond to security events reported via external and /or internal parties via phone calls and group mailboxes.
• Assist with authoring, updating, and modernizing CBP CDF SOPs and Playbooks.
• Manage the lifecycle of CDF investigations from creation to closure in accordance with CBP Policy and Procedures.
• Assist with performing static and dynamic file analysis to identify malware characteristics, intent, and origin.
• Assist with conducting malware analysis and providing Malware Analysis Reports.
• Assist with creating metrics and Key Performance Indicators (KPIs) detailing the operational status and performance of the Cyber Defense Forensics.
• Assist with providing requirements, playbooks, and workflows to support automation of Cyber Defense Forensics tasks.
• Provide support for the CBP Foreign Travel Service with pre- and post-scans of all CBP laptops and mobile devices before and after a CBP employee's approved travel. Perform forensics investigation analysis when necessary.
• Provide support for the CBP Separation and File Transfer Scans by identifying any content that may contain FOUO, For Official Use Only, LES, or Law Enforcement Sensitive keywords.
group id: 10290999