Jobs and Careers
AC

Cybersecurity Incident Response Forensics Associate Manager

Accenture Federal Services
United Statesfull_timeVerifiedPosted 21 Jan 2025
💰 $184,500/yr($93,700/yr$184,500/yr)

About the role

At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology and ingenuity for clients across defense, national security, public safety, civilian, and military health organizations.   Join Accenture Federal Services to do the work you love in an inclusive, collaborative, and caring community, where you can be empowered to grow, learn and thrive through hands-on experience, certifications, industry training and more.   Join us to drive positive, lasting change that moves missions and the government forward!  

You Are:

The Cybersecurity Incident Response Forensics Associate Manager works under the forensics lead to ingest and properly handle evidence, analyze, and perform investigation on escalations by the response team, legal, human resources and CISO. Requires technical understanding to collaborate with operations teams and management to investigate security issues and determine true and false positives, perform malware analysis and provide recommendations to increase the organizations security posture. Excellent communication skills and knowledge in incident response lifecycles, digital forensics, evidence handling, common cyber-attacks, and federal incident reporting requirements.

Here's What You Need:

  • US Citizenship required.
  • 3-5 years of experience in information security, or other equivalent combination of education or equivalent work experience.
  • 3 + years(s) experience with performing digital forensics on physical and cloud systems.
  • 2+ year(s) of experience performing event and log analysis including one or more of the following: Anti-Virus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security Information and Event Management (SIEM) solutions.
  • 1+ year(s) of experience investigating, containing, eradicating, and preventing current and future compromises i.e., implementing or requesting an IP/domain/URL block, file hash block, email purge, software removal, device reimage, etc.
  • 1+ years(s) of experience with collecting, processing, reviewing, and producing Electronically Stored Information (ESI) to legal team.
  • Excellent written and oral communication skills, attention to detail, and interpersonal skills.
  • Experience presenting complex technical information to decision makers and leading them through the decision-making process.

Bonus Points if you have: 

  • Work independently to deliver prompt solutions without direct supervision.
  • Familiarity with various network and host-based security applications and tools, such as network and host assessment/scanning tools, network and host-based intrusion detection systems, and other security software packages.
  • Experience with TCP/IP, common application layer protocols, and packet analysis of the same.
  • Experience performing static and dynamic malware analysis.
  • Experience with indicators of attack and compromise.
  • Familiarity with detection design & engineering concepts to tune detections.
  • Familiarity with Windows / Linux architecture and endpoint analysis of the same.
  • Familiarity with basic data parsing and analysis tools, i.e., Excel, grep, sed, awk, regex, etc.
  • Familiarity with evidence preservation and chain of custody.
  • Familiarity with the Electronic Discovery Reference Model (EDRM) for ESI discovery, preservation, and production.
  • SANs GIAC Certifications including but not limited to GCED, GCLD, GCIH, GCFA, GREM.
  • Digital Forensics
  • Network Forensics
  • Memory Forensics
  • Malware Analysis
  • eDiscovery Software (Nuix, Microsoft Purview eDiscovery)
  • Forensic Software (EnCase, Cellebrite, Sumuri, FTK)
  • Understanding/Experience with Electronic Discovery Reference Model (EDRM)
  • Scripting (PowerShell, Bash, Python)
  • Microsoft SIEM (Sentinel, Defender)

 

#LI-CorpFunction

#LI-Hybrid 

 

As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Hawaii, Illinois, Maryland, Minnesota, New York, Washington, and the District of Columbia. The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wid

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Accenture Federal Services

View company profile →