Cyber Investigations Analyst - Mid
Quick Summary
Supports systems engineering, administration, cyber security/compliance, and digital forensics support for the organization's internal investigations function,
Supports systems engineering, administration, cyber security/compliance, and digital forensics support for the organization's internal investigations function, securing the IT networks used to detect and investigate cybercrimes and internal policy violations. The role spans three areas: security engineering support for the internal investigations forensic network infrastructure; ISSO-adjacent support for the unit's tool suite, SIEM, and network security posture; and cyber forensics analyst support for digital investigations. On the forensics side, the role monitors data-loss-prevention (DLP) solutions and processes email-misuse ("egress") cases in the unit's case management system, conducts endpoint and network digital forensic analysis across Windows, Linux, Mac, and cloud systems, and serves as SME on evidence preservation and chain-of-custody procedures spanning classification levels up to Top Secret. The position also manages the full lifecycle of cyber investigations from creation to closure and supports authoring/updating the unit's standard operating procedures.
- Advise and assist with maintenance and engineering of the internal investigations forensic network infrastructure across its lifecycle; manage priorities/service requests via the internal ticketing/Change Request process.
- Collaborate, administer, configure, tune, and secure the unit's tool suite/devices/sensors to avoid unnecessary POA&Ms; review network security architecture/design and provide recommendations to leadership.
- Maintain SIEM infrastructure/OS supporting collection/aggregation of IDS, firewall, proxy, DLP, antivirus, and vulnerability-scanner data.
- Support near real-time monitoring of DLP solutions; recommend information-spillage incident-response handling/sanitization per NIST 800-88.
- Support design/deployment of custom digital forensic builds for triaging, imaging, and advanced analysis; conduct endpoint (Windows/Linux/Mac/cloud) and network-based digital forensic analysis.
- Support formal digital forensic investigations, documenting findings in formal investigation reports; perform email hygiene activities and process email-misuse ("egress") cases in the case management system.
- Serve as SME on evidence preservation/chain-of-custody across classification levels and on advanced forensic extraction techniques (encryption bypass, mobile-device unlocking, board-level repair).
- Create and escalate cases to law-enforcement entities per internal policy/SOPs; manage the lifecycle of cyber investigations from creation to closure; author/update unit SOPs.
Requirements
~2 min read- Bachelor’s Degree in Computer Science, Engineering, or other Engineering or Technical discipline or equivalent relevant experience.
- Minimum 5 years of experience in system administration, database administration, network engineering, software engineering, or software development with a concentration in Cyber Security; or, with a bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field.
- Minimum 3 years of professional experience performing digital media forensic analysis, static malware code disassembly/analysis, and/or runtime malware code analysis.
- US Citizenship / No Dual
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
Nice to Have
~1 min read- CISSP (Certified Information Systems Security Professional) or CompTIA Security+.
- GCFE (GIAC Certified Forensic Examiner), GCFA (GIAC Certified Forensic Analyst), or EnCE (EnCase Certified Examiner).
What We Offer
~1 min readCompensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
Location & Eligibility
Listing Details
- Posted
- October 6, 2026
- First seen
- October 6, 2026
- Last seen
- October 6, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 57%
- Scored at
- October 6, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.