DFIR Team Lead

Booz Allen Hamilton

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
McLean, VA
Employment
Full-time
Posted
78 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

How this pay compares to similar roles

Similar $195k
$139k $248k
below market most similar roles pay here above market

This listing doesn't post a salary. Most similar roles pay $162,000–$227,725.

Based on 240 similar postings.

Employer

About Booz Allen Hamilton

Booz Allen Hamilton is a management and technology consulting firm that provides analytics, digital, engineering, and cybersecurity solutions primarily to U.S. government agencies and commercial clients. Industry: Management & Technology Consulting

Booz Allen Hamilton currently has 1504 open roles on FindRole.

Listed pay typically runs $86,800–$198,000 across 918 roles with salary data.

Most-posted roles

View all roles at Booz Allen Hamilton

At a glance

TL;DR · DFIR Team Lead

The DFIR Team Lead manages a team of incident response analysts to lead major cybersecurity incidents and coordinate containment efforts. This role involves providing thought leadership for program improvements, mentoring junior team members, and conveying status updates to stakeholders like legal and operations leaders. Day-to-day responsibilities include developing critical documentation, preparing detailed technical reports, and performing timeline analysis by correlating events from multiple sources. Candidates must possess experience analyzing Windows, Mac, and Linux systems using toolsets such as FTK, EnCase, XWF, and Axiom. Required skills include analyzing firewall, network traffic, IIS, Antivirus, and DNS logs, as well as using Python or PowerShell for scripted toolsets. The work focuses on identifying attack vectors, lateral movement, and data exfiltration within the digital forensics and incident response domain.

What you'll do

  • Lead incident response efforts for major cybersecurity incidents to contain and resolve issues.
  • Convey status updates to critical stakeholders including Cybersecurity, Operations, and legal leaders.
  • Develop, maintain, and review critical documentation for all forensic incidents.
  • Provide thought leadership for program improvements and new initiatives.
  • Mentor junior team members to foster a culture of continuous learning and excellence.
  • Analyze logs from firewalls, network traffic, IIS, antivirus, and DNS.
  • Correlate events from multiple sources to create detailed timeline analyses.
  • Prepare detailed technical reports and organize case notes for client communication.

What we're looking for

  • High school diploma or GED.
  • 3+ years of experience with digital forensics or incident response.
  • Experience analyzing Windows, Mac, and Linux systems using toolsets like FTK, EnCase, XWF, and Axiom.
  • Experience with scripted DFIR toolsets written in Python or PowerShell.
  • Experience analyzing logs including firewall, network traffic, IIS, Antivirus, and DNS.
  • Ability to correlate events from multiple sources to create timeline analyses and prepare detailed technical reports.
  • Ability to work after standard business hours, including evenings and weekends, and take a rotation on call.
  • Bachelor’s degree preferred; Master's degree a plus; DFIR or Cybersecurity Certification (CCE, EnCE, CFCE, CISSP, CISM, GCIA, GCFE, GCFA, GREM, or GNFA) preferred.

More like this

Similar roles

Digital Forensic Examiner

Booz Allen Hamilton

Warrenton, OR +1 23 days ago $112,900–$257,000
Digital Forensics Incident Response Log Analysis Python PowerShell Windows Linux EnCase FTK Axiom Splunk Elk Stack Timeline Analysis IOCs

Digital Forensic Examiner, Mid

Booz Allen Hamilton

Washington, DC 29 days ago
Digital Forensics Incident Response Log Analysis Python PowerShell Windows Linux Mac EnCase FTK Axiom Splunk Elk Stack Timeline Analysis IOCs

Digital Forensic Examiner, Mid

Booz Allen Hamilton

Washington, DC 29 days ago
Digital Forensics Incident Response Log Analysis Python PowerShell Windows Linux Mac EnCase FTK Axiom Splunk Elk Stack Timeline Analysis IOCs

Cyber Defense Response Analyst II

CME Group

Chicago, IL 45 days ago $93,900–$156,500
DFIR Malware Analysis Python REST APIs AWS GCP Azure Q Radar Sentinel Splunk Chronicle ArcSight KAPE EnCase Cellebrite FTK Magnet Axiom Autopsy Ghidra Ida Pro PEStudio x64dbg Pandas Networking Operating Systems SIEM

DFT Lead Engineer

Broadcom

San Jose, CA 61 days ago $143,800–$230,000
DFT ATPG Scan Insertion MBIST TCL Python C++ Verilog Tessent SSN TetraMax Fastscan Mentor TestKompress IEEE1149.1 IEEE1149.6 IEE1687 IJTAG ICL PDL STA SerDes DDR PCIe ATE Ruby Perl
10+ yrs exp

Lead FRACAS Systems Engineer

L3Harris

Salt Lake City, UT 53 days ago
FRACAS Root Cause Analysis Reliability Analysis Fault Tree Analysis SQL Business Objects Data Mining Electronic Systems SATCOM Communications Systems Functional Testing Troubleshooting
9+ yrs exp