{"schemaVersion":"jobsearcher.job.v1","id":"2e6fa894f76ba73a6d944dc3","url":"https://jobsearcher.com/jobs/2e6fa894f76ba73a6d944dc3","canonicalUrl":"https://jobsearcher.com/jobs/2e6fa894f76ba73a6d944dc3","title":"AOUSC - Forensic and Malware Lead","description":"cFocus Software seeks a Forensic and Malware Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.\nQualifications:\nActive Public Trust clearance\nB.S. Computer Science, Information Technology, or a related field\nFive (5) years within IR in a large SOC (over 5,000 endpoints) with at least 3 years focused on digital forensics for Operating System or file systems.\nThree (3) years of demonstrated expertise in disk, memory and registry analysis using industry standard tools such as EnCase, FTK, X-Ways, Volatility.\nDemonstrated understanding of file systems and Operating System artifacts including but not limited to (SRUM, Shellbags and Prefetch).\nFamiliarity with federal evidence guidelines and chain of custody requirements.\nThis role aligns with NICE work role PD-WRL-002 (Digital Forensics).\nActive GCFA, GREM, CFCE, or OSED certification\n\nDuties:\nLead digital forensics and malware analysis activities in support of AOUSC Security Operations Division (SOD) operations.\nProvide advanced subject matter expertise for forensic investigations involving Windows, Linux, macOS, cloud, and enterprise environments.\nPerform static and dynamic malware analysis to identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs), and root cause.\nAnalyze forensic artifacts, memory images, endpoint telemetry, SIEM data, and filesystem timelines to identify malicious activity and intrusion vectors.\nCoordinate with Cybersecurity Triage and Incident Response teams to support investigation, escalation, containment, remediation, and recovery activities.\nConduct live forensic analysis utilizing Splunk Enterprise Security, Microsoft Sentinel, EDR tools, and AO-provided investigative tooling.\nCollect, preserve, duplicate, and maintain digital evidence in accordance with forensic evidence handling and chain-of-custody procedures.\nDevelop forensic reports, malware analysis reports, incident artifacts, and technical documentation in accordance with Judiciary SOC Forensics SOPs and JSOCIRP requirements.\nProvide real-time investigative support for Priority 1 and Priority 2 cybersecurity incidents.\nSupport analysis of advanced persistent threats (APT), ransomware, phishing campaigns, malicious scripts, and suspicious binaries.\nPerform memory analysis using approved forensic tools such as Volatility and other Judiciary-approved forensic platforms.\nExtract deleted or hidden data using forensic data carving and recovery techniques.\nConduct analysis of endpoint, network, identity, and cloud telemetry to support incident investigations and threat hunting operations.\nCoordinate escalation and communication of investigative findings to AO leadership, incident responders, SOC management, and federal staff.\nReview and validate forensic and malware analysis deliverables to ensure technical accuracy, completeness, and compliance with SLA requirements.\nDevelop and maintain forensic analysis procedures, malware analysis SOPs, investigative work instructions, and operational playbooks.\nSupport enterprise security awareness reporting by contributing forensic findings, threat trends, and investigative recommendations.\nParticipate in weekly technical meetings, operational briefings, and cybersecurity reporting activities.\nSupport continuous process improvement initiatives related to digital forensics, malware analysis, investigative workflows, and incident response operations.\nAssist in transition-in and transition-out activities including knowledge transfer, operational readiness, training, and documentation support.\n6s0KfwCs9C","company":"Cfocus Software","rawCompany":"cfocus software","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-05-24T15:14:37.098Z","occupations":[{"code":"15-1299.06","title":"Digital Forensics Analysts","slug":"digital-forensics-analysts"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"19-4092.00","title":"Forensic Science Technicians","slug":"forensic-science-technicians"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"AOUSC - Forensic and Malware Lead","description":"cFocus Software seeks a Forensic and Malware Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.\nQualifications:\nActive Public Trust clearance\nB.S. Computer Science, Information Technology, or a related field\nFive (5) years within IR in a large SOC (over 5,000 endpoints) with at least 3 years focused on digital forensics for Operating System or file systems.\nThree (3) years of demonstrated expertise in disk, memory and registry analysis using industry standard tools such as EnCase, FTK, X-Ways, Volatility.\nDemonstrated understanding of file systems and Operating System artifacts including but not limited to (SRUM, Shellbags and Prefetch).\nFamiliarity with federal evidence guidelines and chain of custody requirements.\nThis role aligns with NICE work role PD-WRL-002 (Digital Forensics).\nActive GCFA, GREM, CFCE, or OSED certification\n\nDuties:\nLead digital forensics and malware analysis activities in support of AOUSC Security Operations Division (SOD) operations.\nProvide advanced subject matter expertise for forensic investigations involving Windows, Linux, macOS, cloud, and enterprise environments.\nPerform static and dynamic malware analysis to identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs), and root cause.\nAnalyze forensic artifacts, memory images, endpoint telemetry, SIEM data, and filesystem timelines to identify malicious activity and intrusion vectors.\nCoordinate with Cybersecurity Triage and Incident Response teams to support investigation, escalation, containment, remediation, and recovery activities.\nConduct live forensic analysis utilizing Splunk Enterprise Security, Microsoft Sentinel, EDR tools, and AO-provided investigative tooling.\nCollect, preserve, duplicate, and maintain digital evidence in accordance with forensic evidence handling and chain-of-custody procedures.\nDevelop forensic reports, malware analysis reports, incident artifacts, and technical documentation in accordance with Judiciary SOC Forensics SOPs and JSOCIRP requirements.\nProvide real-time investigative support for Priority 1 and Priority 2 cybersecurity incidents.\nSupport analysis of advanced persistent threats (APT), ransomware, phishing campaigns, malicious scripts, and suspicious binaries.\nPerform memory analysis using approved forensic tools such as Volatility and other Judiciary-approved forensic platforms.\nExtract deleted or hidden data using forensic data carving and recovery techniques.\nConduct analysis of endpoint, network, identity, and cloud telemetry to support incident investigations and threat hunting operations.\nCoordinate escalation and communication of investigative findings to AO leadership, incident responders, SOC management, and federal staff.\nReview and validate forensic and malware analysis deliverables to ensure technical accuracy, completeness, and compliance with SLA requirements.\nDevelop and maintain forensic analysis procedures, malware analysis SOPs, investigative work instructions, and operational playbooks.\nSupport enterprise security awareness reporting by contributing forensic findings, threat trends, and investigative recommendations.\nParticipate in weekly technical meetings, operational briefings, and cybersecurity reporting activities.\nSupport continuous process improvement initiatives related to digital forensics, malware analysis, investigative workflows, and incident response operations.\nAssist in transition-in and transition-out activities including knowledge transfer, operational readiness, training, and documentation support.\n6s0KfwCs9C","datePosted":"2026-05-24T15:14:37.098Z","dateModified":"2026-05-24T15:14:37.098Z","hiringOrganization":{"@type":"Organization","name":"Cfocus Software","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"2e6fa894f76ba73a6d944dc3"},"url":"https://jobsearcher.com/jobs/2e6fa894f76ba73a6d944dc3"}}