Job Description
Employment Type: Regular, Full-Time
Shift:
About the Company
Athena Technology Group, Inc. (ATG) is a Service-Disabled Veteran Owned Small Business (SDVOSB) focused on Information Technology and Communications consulting, system engineering, integration, deployment and operation of state of the art command and control and information systems that deliver critical network centric solution to the warfighter. With a proven track record of technical support to our customers, we are looking for innovative industry professionals to join our team.
ATG is an Equal Opportunity/Affirmative Action Employer Minorities/Females/Vets/Disability
Job Summary
We are seeking a Senior Forensic and Malware Analyst to support ARCYBER G3 cyber operations at Fort Gordon, GA. The selected candidate will conduct advanced digital forensic analysis, malware analysis, reverse engineering, network forensic analysis, and incident handling in support of mission-critical cyber investigations.
The candidate will analyze compiled executable code and non-compiled malicious content, support cyber threat hunting activities, develop malware detection signatures, and provide detailed analytic findings to leadership and mission partners. This position requires an active TS clearance with the ability to obtain and maintain SCI eligibility and a CI Polygraph.
Key Responsibilities
- Conduct malware analysis and reverse engineering of compiled executable code to characterize malicious software functions, behaviors, and capabilities
- Analyze and deobfuscate scripts, encoded commands, macros, PowerShell, VBScript, batch files, and other non-compiled malicious content to determine intent and functionality
- Utilize static, dynamic, and hybrid analysis techniques to detect, identify, and characterize anomalous or malicious software and activity
- Conduct dead-box forensic analysis and live forensic/incident handling analysis
- Perform digital media forensic examinations using tools such as EnCase, FTK, Autopsy, or equivalent forensic platforms
- Collect, preserve, document, and transfer forensic evidence associated with intrusions involving on-premises Information Systems
- Analyze forensic images, suspicious and malicious files, intrusion-related artifacts, entry points, vectors, and indicators of compromise
- Conduct network forensic analysis, including inspection of packet captures (PCAPs) for malicious indicators, protocol anomalies, command-and-control communications, domains, URI paths, User Agent strings, TLS metadata, and other intrusion artifacts
- Conduct mobile device forensic examinations using mobile forensic laboratory tools and capabilities to acquire, examine, and analyze data from mobile devices
- Develop and maintain malware detection signatures, including YARA rules, based on analytic findings to support detection engineering and threat hunting activities
- Support cyber threat hunting activities and analysis of indicators of compromise and associated threat artifacts
- Use scripting languages such as PowerShell, BASH, Python, or similar languages to automate analysis tasks, parse artifacts, and develop tools supporting malware and forensic workflows
- Open, maintain, and close forensic cases in accordance with applicable DC3 and DoD forensic guidelines
- Develop and maintain malware analysis artifacts, forensic case notes, supporting evidence, and all case-related documentation
- Produce detailed written forensic and malware analysis reports in accordance with DoD reporting standards
- Deliver daily, weekly, monthly, and ad hoc operational briefings to leadership and mission partners
- Coordinate with internal and external mission partners and intelligence professionals to contextualize malware findings within broader adversary tactics, techniques, procedures, and campaign activity
- Update forensic and malware analysis portions of Standard Operating Procedures (SOPs), Tactics, Techniques, and Procedures (TTPs), CSSP documentation, and applicable website information
- Support surge operations as required by mission needs
Qualifications
Required:
- Active TS clearance with the ability to obtain and maintain SCI eligibility and a CI Polygraph
- Minimum of 12 years of relevant experience with a Bachelor’s degree
- Minimum of 10 years of relevant experience with a Master’s degree
- Minimum of 7 years of relevant experience with a PhD
- An Associate degree with a minimum of 14 years of relevant experience may be considered
- A high school diploma with a minimum of 16 years of relevant experience may be considered
- Must possess an approved IA certification upon start, including one of the following or equivalent: CCNA-Security, CCNA-Cybersecurity, CySA+, GICSP, GSEC, Security+, CND, or SSCP
- Experience conducting malware analysis and reverse engineering of malicious executable code
- Experience analyzing non-compiled malicious content, including scripts, macros, encoded commands, and obfuscated files
- Experience conducting dead-box forensic analysis and live forensic/incident handling analysis
- Experience using static, dynamic, and hybrid malware analysis techniques
- Experience with forensic tools such as EnCase, FTK, Autopsy, or equivalent platforms
- Experience inspecting packet captures and conducting network forensic analysis
- Experience identifying malicious domains, URI paths, protocols, User Agent strings, TLS metadata, command-and-control communications, and other indicators of compromise
- Experience with scripting languages such as PowerShell, BASH, Python, or equivalent technologies
- Experience developing or maintaining YARA rules or similar malware detection signatures
- Experience collecting, preserving, and documenting digital forensic evidence
- Experience with DoD standards of reporting and forensic case documentation
- Strong analytical, technical writing, briefing, and communication skills
- Ability to support surge operations when required by mission needs
Desired:
- Active or previously held GIAC Certified Forensic Analyst (GCFA) certification
- CHFI or other relevant digital forensic or malware analysis certifications
- Experience supporting cyber threat hunting operations
- Experience conducting mobile device forensic examinations
- Experience with DC3 forensic standards and case management processes
- Advanced experience developing malware detection signatures and threat hunting analytics
- Background in quantitative disciplines such as mathematics, statistics, computer science, cybersecurity, engineering, or related technical disciplines
Physical and Environmental Conditions
Normal Office Environment. Requires Sitting, Standing, Near Acuity, Speaking with colleagues and customers, Listening, Sight, Use of hands/fingers.
Additional Benefits
- Performance Bonuses and annual salary reviews
- Health, dental, and vision insurance
- Short Term Disability, Long Term Disability, and Life Insurance
- 401(k) plan with company match
- Opportunities for professional growth and development
- A collaborative and inclusive work environment
EEO Statement
ATG is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, religion, creed, color, national origin, ancestry, sex (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, medical condition, marital or domestic partner status, sexual orientation, gender, gender identity, gender expression and transgender status, mental disability or physical disability, genetic information, military or veteran status, citizenship, low-income status or any other status or characteristic protected by applicable law.