Cybervance logo

Forensics Analyst Lead (Remote)

CybervancePortland, OR

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Overview

Schedule
Full-time
Career level
Director
Remote
On-site
Benefits
Career Development

Job Description

Position Title: Forensics Analyst Lead

Location:Portland, OR | Full-Time                                           

Cybervance is a rapidly growing information security and information technology company based in Washington, D.C., and we are an equal opportunity employer.

Cybervance combines advanced cybersecurity expertise with proven federal contracting experience to deliver innovated, mission-focused solutions for U.S. Government agencies. We are committed to helping our partners achieve measurable improvements in security and resilience.

We are seeking a full-time Forensics Analyst Lead who is responsible for leading the organization's digital forensics capability, overseeing investigations related to cyber incidents, insider threats, data breaches, and legal or regulatory matters. This role provides technical leadership, investigative oversight, and expert guidance to ensure forensic activities are conducted accurately, defensibly, and in alignment with legal and regulatory requirements.

The ideal candidate combines deep forensic expertise with leadership skills, sound judgment under pressure, and the ability to communicate complex findings to technical teams, legal partners, and executive leadership.

Responsibilities

  • Lead and oversee all digital forensic investigations across endpoint, server, network, cloud, and mobile environments.
  • Establish forensic standards, methodologies, and toolsets.
  • Act as the primary escalation point for complex or high‑impact forensic cases.
  • Ensure investigations follow best practices for evidence handling and forensic integrity.
  • Support and lead forensic analysis during security incidents, including malware infections, intrusions, and data exfiltration events.
  • Conduct advanced forensic analysis to identify root cause, attacker activity, and impact.
  • Reconstruct timelines and analyze artifacts to support incident response and remediation efforts.
  • Collaborate closely with Incident Response, SOC, Threat Hunting, and Legal teams.
  • Ensure proper evidence preservation, chain of custody, and documentation.
  • Provide forensic findings to legal, compliance, HR, and regulatory stakeholders.
  • Support internal investigations, litigation, and eDiscovery processes.
  • Serve as a subject‑matter expert for forensic procedures during audits or legal proceedings.
  • Evaluate, deploy, and maintain forensic tools and technologies.
  • Improve forensic readiness through logging, data retention, and evidence collection. Strategies.
  • Develop scripts, workflows, or automation to improve forensic efficiency and consistency.
  • Lead, mentor, and train forensic analysts and incident responders.
  • Review forensic work products for quality and accuracy.
  • Contribute to training programs, tabletop exercises, and forensic playbooks.
  • Produce detailed forensic reports, timelines, and root cause analyses.
  • Translate technical findings into clear business, legal, and risk‑based narratives.
  • Brief senior leadership on incident findings, impact, and recommendations.

Required Skills & Qualifications

  • 7–10+ years of experience in digital forensics, incident response, or cybersecurity investigations.
  • Proven experience leading forensic investigations and teams.
  • Deep understanding of:
    • Endpoint, memory, disk, and network forensics
    • Malware analysis and attacker techniques
    • Evidence handling and chain‑of‑custody requirements
  • Hands‑on experience with industry‑standard forensic tools.
  • Strong written communication and technical reporting skills.

Preferred Qualifications

  • Experience with cloud and SaaS forensics (AWS, Azure, GCP, M365, Google Workspace).
  • Experience supporting legal, HR, or regulatory investigations.
  • Scripting or automation experience (Python, PowerShell, Bash).
  • Certifications such as GCFA, GCED, GCIH, CISSP, EnCE, or equivalent.
  • Experience in government, finance, healthcare, or other regulated environments.

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.

pay-wall

FAQs About Forensics Analyst Lead (Remote) Jobs at Cybervance

What is the work location for this position at Cybervance?
This job at Cybervance is located in Portland, OR, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at Cybervance?
Employer has not shared pay details for this role.
What employment applies to this position at Cybervance?
Cybervance lists this role as a Full-time position.
What experience level is required for this role at Cybervance?
Cybervance is looking for a candidate with "Director" experience level.
What benefits are offered by Cybervance for this role?
Cybervance offers Career Development for this position. Actual benefits may vary depending on the employer's policies and employment terms.
What is the process to apply for this position at Cybervance?
You can apply for this role at Cybervance either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.