Collect, analyze and present digital-related evidence in support of computer criminal investigations. Apply basic principles, theories, and concepts, and limited industry knowledge. Solve routine problems of limited scope and complexity, and refer more complex issues to higher levels. Work under direct supervision. This position will require travel of up to 40% of the time to client sites. This position is open to temporary remote delivery anywhere within the U.S., to include the District of Columbia.
Experience with forensic suite of tools, including Windows, Linux, and Mac operating systems
Knowledge of live response, event logs, user activity, memory analysis, and timelining user actions
Ability to conduct deadbox forensics, live response collections, and network log forensics
Ability to manage short and long term projects to completion
Ability to travel up to 40% of the time
Ability to obtain a security clearance
Knowledge of Incident Response, Mitre Att&ck framework, Cyber Kill Chain
Ability to communicate and work with multiple teams
Ability to articulate forensic findings in a technical report, multi-task
Ability to manage shift work, weekends
Net+, Sec+, CHFI, SANS Certification
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.
The proposed salary range for this position in Colorado is $80,000 to $90,000 USD Annual. Final salary will be determined based on various factors.
At Booz Allen, we celebrate your contributions, provide you with opportunities and choice, and support your total well-being. Our comprehensive benefit offerings include healthcare, retirement plan, insurance programs, commuter program, employee assistance program, paid and unpaid leave programs, education assistance, and childcare benefits.
We’re an EOE that empowers our people—no matter their race, color, religion, sex, gender identity, sexual orientation, national origin, disability, veteran status, or other protected characteristic—to fearlessly drive change.