About this role
We are seeking a Forensic Analyst for an opportunity in Washington, DC. This opportunity may allow some remote support.
Forensics Specialist Senior-7+ years of experience
Forensics Specialist Mid-5+ years of experience
Forensics Specialist Junior-3+ years of experience
Cyber Forensics Analysis Support
- The Contractor shall provide support to Cyber Investigations (CI) in conjunction with OIT's CDF team in support of insider threat and security operations according to established policies, handbooks, and CBP CDF SOPs. This support includes monitoring activities, conducting threat analysis, investigating policy violations, identifying mitigation and/or remediation courses of action, and assessing risk posed by trusted insiders. The focus of this task is to process CBP email misuse 'egress' cases assigned to OPR in the CBP OPR Joint Intake Case Management System (JICMS), work with the OIT DLP tools to process incidents and assist with SOC Incidents / OPR investigations as needed.
- Support the Cyber Investigations through near real-time (when possible, based on tools) monitoring of the DLP solutions and other applicable tools.
- Provide recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.
- Support the design, development, and deployment of OPR's custom digital forensic builds for triaging, imaging, and advanced analysis.
- Support OIT, OI, OIG and Other Government Agencies in the investigation of CBP personnel operating with potentially malicious or alleged criminal intent.
- Support the Government in conducting enterprise and individual system(s) endpoint (e.g., Windows, Linux, Mac, and Cloud systems) and network based digital forensic analysis and cloud network designs for new forensic tools in support of CI or CDF and for deployment into production networks.
- Leverage commercially available and open-source forensic tools to efficiently perform forensic analysis, assess technical gaps and conduct advanced research and development on forensic technologies and enterprise solutions.
- Support the Government in conducting formal digital forensic investigations and document findings in formal investigation reports.
- Perform Email hygiene activities in support of CBP investigations.
- Support enterprise recovery efforts as necessary to ensure that security events and incidents are properly remediated prior to reconstitution.
- Serve as Subject Matter Experts (SMEs) by supporting the preservation of evidence, which includes a deep understanding of proper chain of custody and proper storage, handling, and transmission procedures for various data sets including but not limited to SBU, FOUO, LES, CONFIDENTIAL, SECRET and TOP SECRET information.
- Create and escalate cases via ticket management system to proper law enforcement entities in compliance with CBP policy and SOPs.
- Assist with authoring, updating, and modernizing OPR's IOD SOPs.
- Support the Government with managing the lifecycle of Cyber investigations from creation to closure in accordance with OPR's Policy and Procedures.
- Assist in static and dynamic file analysis to identify malware characteristics, intent, and origin.