Summary
OVA.Work is seeking a detail-oriented and analytical Digital Forensics Analyst to investigate cyber incidents and perform forensic analysis across various platforms. The role involves collecting and preserving digital evidence, collaborating with teams during investigations, and ensuring compliance with industry standards.
Responsibilities
- Conduct digital forensic investigations involving computers, mobile devices, servers, cloud environments, and network systems
- Acquire, preserve, and analyze digital evidence while maintaining chain of custody
- Investigate cybersecurity incidents, including malware infections, insider threats, ransomware, phishing, and data breaches
- Perform disk, memory, and network forensic analysis
- Recover deleted, encrypted, or damaged files using forensic techniques
- Analyze system, application, and security logs to determine attack timelines
- Collaborate with Incident Response, SOC, Legal, HR, and Compliance teams during investigations
- Prepare detailed forensic reports and present findings to technical and non-technical stakeholders
- Support litigation, regulatory, and law enforcement requests when required
- Develop and maintain forensic procedures, documentation, and evidence handling standards
- Stay current with emerging cyber threats, forensic methodologies, and investigative technologies
Skills
- Strong understanding of digital forensic principles and evidence handling
- Experience with forensic acquisition and analysis tools
- Knowledge of Windows, Linux, and macOS operating systems
- Experience in memory, disk, mobile, cloud, and network forensics
- Understanding of file systems (NTFS, FAT, EXT, APFS, HFS+)
- Knowledge of malware analysis and incident response processes
- Familiarity with log analysis, SIEM platforms, and threat detection
- Basic scripting skills in Python, PowerShell, or Bash
- Strong analytical, investigative, and report-writing skills
- Understanding of cybersecurity frameworks and best practices
- Bachelor's degree in Cybersecurity, Computer Science, Digital Forensics, Information Security, or a related field
- 2–5+ years of experience in digital forensics, incident response, or cybersecurity investigations
- Experience with cloud forensics in AWS, Azure, or Google Cloud Platform (GCP)
- Knowledge of mobile device forensics (Android and iOS)
- Familiarity with eDiscovery and legal compliance requirements
- Experience supporting law enforcement or corporate investigations
- Malware reverse engineering
- Threat hunting
- Cloud forensics
- Memory analysis
- YARA rule creation
- MITRE
- Telecommunication&CK framework
- OSINT techniques
- Python
- PowerShell
- Bash
- SQL
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Incident Handler (GCIH)
- Certified Forensic Computer Examiner (CFCE)
- Certified Computer Examiner (CCE)
- EC-Council Computer Hacking Forensic Investigator (CHFI)
- GIAC Certified Enterprise Defender (GCED)
- CompTIA Security+
- CompTIA CySA+
- Certified Information Systems Security Professional (CISSP) *(preferred for senior roles)*
Qualifications
Must Haves
- Strong understanding of digital forensic principles and evidence handling
- Experience with forensic acquisition and analysis tools
- Knowledge of Windows, Linux, and macOS operating systems
- Experience in memory, disk, mobile, cloud, and network forensics
- Understanding of file systems (NTFS, FAT, EXT, APFS, HFS+)
- Knowledge of malware analysis and incident response processes
- Familiarity with log analysis, SIEM platforms, and threat detection
- Basic scripting skills in Python, PowerShell, or Bash
- Strong analytical, investigative, and report-writing skills
- Understanding of cybersecurity frameworks and best practices
Nice to Haves
- Bachelor's degree in Cybersecurity, Computer Science, Digital Forensics, Information Security, or a related field
- 2–5+ years of experience in digital forensics, incident response, or cybersecurity investigations
- Experience with cloud forensics in AWS, Azure, or Google Cloud Platform (GCP)
- Knowledge of mobile device forensics (Android and iOS)
- Familiarity with eDiscovery and legal compliance requirements
- Experience supporting law enforcement or corporate investigations
- Malware reverse engineering
- Threat hunting
- Cloud forensics
- Memory analysis
- YARA rule creation
- MITRE
- Telecommunication&CK framework
- OSINT techniques
- Python
- PowerShell
- Bash
- SQL
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Incident Handler (GCIH)
- Certified Forensic Computer Examiner (CFCE)
- Certified Computer Examiner (CCE)
- EC-Council Computer Hacking Forensic Investigator (CHFI)
- GIAC Certified Enterprise Defender (GCED)
- CompTIA Security+
- CompTIA CySA+
- Certified Information Systems Security Professional (CISSP) *(preferred for senior roles)*
Benefits
- Work_model: [remote, onsite]