Cyber Defense Forensics
The Cyber Defense Forensics Lead provides expert leadership for digital forensics and advanced cyber investigations in support of CBP security operations. This role focuses on identifying, analyzing, and responding to cyber incidents, insider threats, and advanced persistent threats using industry‑leading forensic and monitoring techniques across classified and unclassified environments.
This role is ideal for a forensic leader who thrives on solving complex cyber incidents and uncovering the truth behind advanced threats. As the Cyber Defense Forensics Lead, you’ll be at the forefront of protecting national security systems—leading high‑impact investigations, responding to sophisticated adversaries, and guiding teams through complex digital forensics challenges. You’ll have the autonomy to shape investigative approaches, mentor analysts, and directly influence how threats are detected and neutralized across a large federal enterprise.
The Cyber Defense Forensics Lead provides expert leadership for digital forensics and advanced cyber investigations in support of CBP security operations. This role focuses on identifying, analyzing, and responding to cyber incidents, insider threats, and advanced persistent threats using industry‑leading forensic and monitoring techniques across classified and unclassified environments.
This role is ideal for a forensic leader who thrives on solving complex cyber incidents and uncovering the truth behind advanced threats. As the Cyber Defense Forensics Lead, you’ll be at the forefront of protecting national security systems—leading high‑impact investigations, responding to sophisticated adversaries, and guiding teams through complex digital forensics challenges. You’ll have the autonomy to shape investigative approaches, mentor analysts, and directly influence how threats are detected and neutralized across a large federal enterprise.
What You'll Do:
- Lead digital forensics investigations and advanced incident analysis
- Conduct host‑based and network‑based security monitoring and evidence collection
- Develop forensic dashboards, reports, and investigative workflows
- Direct response activities for high‑impact security incidents
- Train and mentor junior forensic and SOC analysts
What You Have:
- US Citizenship is Required
- Minimum 7 years of professional cybersecurity or digital forensics experience
- At least 5 years hands‑on experience with forensic analysis, SIEM, IDS/IPS, and EDR tools
- Experience with insider threat investigations and advanced threat analysis
- CISSP certification required
- Ability to obtain and maintain TS (SCI‑eligible) clearance