tags.new

Cyber Forensic Specialist

Arlington, VA
 
At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology and ingenuity for clients across defense, national security, public safety, civilian, and military health organizations. 
 
Join Accenture Federal Services, a technology company within global Accenture. Recognized as a Glassdoor Top 100 Best Place to Work, we offer a collaborative and caring community where you feel like you belong and are empowered to grow, learn and thrive through hands-on experience, certifications, industry training and more. 
 
Join us to drive positive, lasting change that moves missions and the government forward!
 

We are seeking a skilled and detail-oriented Cyber Forensic Specialist to join our Digital Forensics and Incident Response (DFIR) team. This role is critical in supporting the organization's Cyber Incident Response Team (CIRT) by providing expert-level digital forensic and investigative support. Additionally, the position involves working closely with cross-functional teams, including Human Resources, Legal, and Insider Threat, to conduct sensitive internal investigations related to policy adherence and organizational concerns.

The Cyber Forensic Specialist will also collaborate with the internal Legal team to execute litigation holds and eDiscovery-related evidence captures, ensuring full compliance with organizational and regulatory requirements. The role further involves serving as the central point for evidence intake, processing, and management for cases, litigation holds, and investigations. 

The Work

  1. DFIR Support:
    • Collaborate with the Cyber Incident Response Team (CIRT) to investigate and respond to cybersecurity incidents, including malware infections, unauthorized access, data breaches, and advanced persistent threats (APTs).
    • Perform digital forensic analysis on devices such as laptops, desktops, servers, mobile devices, and network logs to identify the root cause and scope of incidents.
    • Provide recommendations on containment, remediation, and recovery activities.
  2. Investigative Support:
    • Conduct internal investigations in collaboration with HR, Legal, and Insider Threat teams related to:
      • Potential risks to organizational assets and operations.
      • Inquiries requiring the collection and analysis of electronic evidence.
      • Other internal matters involving digital investigations.
    • Analyze electronic communications, file systems, and digital artifacts to uncover evidence.
    • Prepare detailed, well-documented reports and findings to support decision-making and potential actions.
  3. Litigation Holds and eDiscovery:
    • Partner with the Legal team to ensure the timely and accurate implementation of litigation holds, including identifying, preserving, and collecting electronically stored information (ESI).
    • Perform eDiscovery-related data captures, including on-premises and cloud-based systems, in alignment with legal and regulatory requirements.
    • Maintain thorough documentation of all eDiscovery activities for legal proceedings and audits.
  4. Evidence Intake and Management:
    • Serve as the central point for evidence intake, ensuring proper chain of custody and documentation for all collected digital evidence.
    • Maintain and enforce evidence management protocols, including secure storage, tagging, and tracking for litigation holds and legal proceedings.
    • Ensure compliance with data retention and destruction policies.
  5. Process Optimization and Tooling:
    • Leverage forensic tools (e.g., EnCase, FTK, X-Ways, Magnet Axiom) to analyze and process evidence efficiently.
    • Continuously improve and document forensic methodologies, workflows, and playbooks.
    • Stay up to date with emerging forensic techniques, tools, and industry best practices.
  6. Collaboration and Training:
    • Provide guidance and training to the CIRT and other internal teams on forensic processes and evidence handling.
    • Collaborate with outside counsel or external third-party forensic services, when required.

What you need

  • US Citizenship required.
  • 3-5 years of experience in information security, or other equivalent combination of education or equivalent work experience.
  • 3 + years of experience with performing digital forensics on physical and cloud systems.
  • 2+ years of experience performing event and log analysis including one or more of the following: Anti-Virus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security Information and Event Management (SIEM) solutions.
  • 1+ years of experience investigating, containing, eradicating, and preventing current and future compromises i.e., implementing or requesting an IP/domain/URL block, file hash block, email purge, software removal, device reimage, etc.
  • 1+ years of experience with collecting, processing, reviewing, and producing Electronically Stored Information (ESI) to legal teams.
  • Work independently to deliver prompt solutions without direct supervision.
  • Excellent written and oral communication skills, attention to detail, and interpersonal skills.
  • Experience presenting complex technical information to decision makers and leading them through the decision-making process.
  • Experience with digital forensic imaging (FTK, Cellebrite, Paladin, etc.) and analysis tools (EnCase, Autopsy, Nuix, etc.)
  • Experience with evidence preservation and chain of custody.
  • Experience with TCP/IP, common application layer protocols, and packet analysis of the same.
  • Experience performing static and dynamic malware analysis.
  • Experience with indicators of attack and compromise.
  • Experience with basic data parsing and analysis tools, i.e., Excel, grep, sed, awk, regex, etc.
  • Familiarity with various network and host-based security applications and tools, such as network and host assessment/scanning tools, network and host-based intrusion detection systems, and other security software packages.
  • Familiarity with detection design & engineering concepts to tune detections.
  • Familiarity with Windows / Linux architecture and endpoint analysis of the same.
  • Familiarity with the Electronic Discovery Reference Model (EDRM) for ESI discovery, preservation, and production.

Bonus if you have

  • DFIR related certifications including but not limited to: SANS (GCED, GCLD, GCIH, GCFE,GCFA,GREM),CFCE,EnCE.
  • Knowledge of scripting languages (e.g., Python, PowerShell) to automate forensic tasks.
  • Experience with eDiscovery toolsets such as: Microsoft Purview eDiscovery (Standard/Premium) and Nuix.

 

As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Washington, Vermont, the District of Columbia, and the city of Cleveland. The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wide array of factors, including but not limited to office location, role, skill set, and level of experience. Accenture Federal Services offers a wide variety of benefits. You can find more information on benefits here. We accept applications on an on-going basis and there is no fixed deadline to apply.

 

The pay range for the states of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Washington, Vermont, the District of Columbia, and the city of Cleveland is:

$69,900 - $153,000 USD

 
What We Believe
As a company wholly dedicated to serving the US federal government, we bring together the best talent to help reinvent how federal agencies operate and deliver greater value for their mission and the American people. We have an unwavering commitment to creating a culture in which all our people are respected, feel a sense of belonging, and have equal opportunity. As a business imperative, every person at Accenture Federal Services has the responsibility to create and sustain a culture where everyone feels welcomed and included. This is grounded in our core values and our experience that hiring and developing great people who reflect different perspectives, experiences, and backgrounds is key to driving innovation and delivering the results that our clients and the country count on.
 
Equal Employment Opportunity Statement
We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities. For details, view a copy of the Accenture Federal Services Equal Opportunity Policy Statement.
 
Accenture Federal Services is an Equal Employment Opportunity employer. Additionally, as an Affirmative Action Employer for Veterans and Individuals with Disabilities, Accenture Federal Services is committed to providing veteran employment opportunities to our service men and women.
 
Requesting An Accommodation 
Accenture Federal Services is committed to providing equal employment opportunities for persons with disabilities or religious observances, including reasonable accommodation when needed. If you are hired by Accenture Federal Services and require accommodation to perform the essential functions of your role, you will be asked to participate in our reasonable accommodation process. Accommodations made to facilitate the recruiting process are not a guarantee of future or continued accommodations once hired.
 
If youare being considered for employment opportunities with Accenture Federal Services and need an accommodation for a disability or religious observance during the interview process or for the job you are interviewing for, please speak with your recruiter.
 
Other Employment Statements 
Applicants for employment in the US must have work authorization that does not now or in the future require sponsorship of a visa for employment authorization in the United States.
 
Candidates who are currently employed by a client of Accenture Federal Services or an affiliated Accenture business may not be eligible for consideration.
 
Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process.
 
The Company will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. Additionally, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the Company's legal duty to furnish information.
 
California requires additional notifications for applicants and employees. If you are a California resident, live in or plan to work from Los Angeles County upon being hired for this position, please click here for additional important information.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...

Exceptions: Enlisted Personnel in the military, teachers, teaching  assistants, professors, student teachers,  computer lab-type positions at an academic institution, research assistants, residential  assistants or advisors at schools or universities, correctional officers (police officers, parole officers, sheriff’s or sheriff’s deputies), lifeguards, camp counselors, firefighters, EMT, paramedics or other emergency personnel, postal carriers, Peace Corps workers or AmeriCorps workers NOT working in a main office or headquarters.

Select...
Select...

Exceptions: Enlisted Personnel in the military, teachers, teaching  assistants, professors, student teachers,  computer lab-type positions at an academic institution, research assistants, residential  assistants or advisors at schools or universities, correctional officers (police officers, parole officers, sheriff’s or sheriff’s deputies), lifeguards, camp counselors, firefighters, EMT, paramedics or other emergency personnel, postal carriers, Peace Corps workers or AmeriCorps workers NOT working in a main office or headquarters 

Select...
Select...

By selecting I agree above, I am consenting to the processing of my personal data by Accenture Federal Services as explained in its privacy statement. I understand that Accenture Federal Services is an "at-will" employer, meaning that my employment has no specified term, and that the employment relationship may be terminated any time at the will of either party on notice to the other. I also certify that all information on this application is complete and accurate to the best of my knowledge, and I understand that the intentional misrepresentation of any information may invalidate this application and may result in the termination of subsequent employment with Accenture Federal Services. 

I also acknowledge that I have been made aware that I am able to redact or remove information from any attached documents that may identify my age (e.g., date of birth, or dates of attendance at or graduation from an educational institution).

I also acknowledge that I have been made aware that it is unlawful in Massachusetts (and elsewhere) to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Accenture Federal Services’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.