Network Forensics Analyst - DT #7 - Remote

Compu-Vision - IT

  • Philadelphia, PA
  • Today
  • Remote

    Highlights

    We are seeking an experienced Network Forensics Analyst to investigate cybersecurity incidents through the analysis of network traffic, communications, and related security telemetry. The role will focus on identifying malicious network activity, investigating attacker behavior, reconstructing attack timelines, and supporting incident response efforts.

    Numbers & Facts

    LocationPhiladelphia, PA (
    Remote
    )

    Description

    Network Forensics Analyst

    Location: Remote
    Duration: 1–2 Weeks with potential extension

    Position Overview

    We are seeking an experienced Network Forensics Analyst to investigate cybersecurity incidents through the analysis of network traffic, communications, and related security telemetry.

    The role will focus on identifying malicious network activity, investigating attacker behavior, reconstructing attack timelines, and supporting incident response efforts. The ideal candidate will have strong hands-on experience with packet analysis, network security monitoring, firewall and IDS/IPS technologies, and network forensic investigation.

    Key Responsibilities

    • Analyze packet captures and network traffic associated with cybersecurity incidents.
    • Investigate suspicious network connections and anomalous communications.
    • Identify and analyze:
      • Lateral movement
      • Command-and-control (C2) traffic
      • Data exfiltration
      • Malicious protocols and network behavior
    • Analyze logs from:
      • Firewalls
      • Proxy servers
      • DNS infrastructure
      • VPN systems
      • IDS/IPS platforms
      • Network devices
    • Identify malicious or suspicious IP addresses, domains, protocols, and communication patterns.
    • Correlate network traffic with other security telemetry to reconstruct attack activity.
    • Develop detailed attack timelines and investigative findings.
    • Support incident response and threat investigation activities.
    • Document forensic evidence, analysis methodology, findings, and conclusions.
    • Prepare clear and defensible network forensic reports.
    • Communicate technical findings to security and incident response teams.

    Key Technical Skills

    Network Analysis & Forensics

    • Wireshark
    • Zeek
    • tcpdump
    • NetworkMiner
    • Packet capture and deep packet analysis
    • Network traffic reconstruction
    • Network behavioral analysis

    Security Monitoring

    • Splunk
    • Firewall technologies
    • IDS/IPS
    • VPN technologies
    • DNS/DHCP
    • Network security monitoring

    Networking

    • TCP/IP
    • Network protocols
    • Routing and network communications
    • Network security architecture
    • Malicious traffic identification

    Incident Response

    • Network-based incident investigation
    • Attack timeline development
    • Threat detection and analysis
    • Incident response methodologies
    • Evidence collection and documentation

    Required Qualifications

    • Proven experience in network forensics, network security analysis, or incident response.
    • Strong hands-on experience analyzing packet captures and network traffic.
    • Experience investigating suspicious communications and network-based attacks.
    • Strong understanding of TCP/IP, DNS, DHCP, and common network protocols.
    • Experience analyzing firewall, proxy, DNS, VPN, IDS/IPS, and network-device logs.
    • Ability to identify malicious IPs, domains, protocols, and network behaviors.
    • Experience investigating lateral movement, C2 communications, and data exfiltration.
    • Proficiency with tools such as Wireshark, Zeek, tcpdump, or NetworkMiner.
    • Experience using SIEM platforms such as Splunk for security investigations.
    • Strong analytical, investigative, and technical documentation skills.
    • Ability to work independently in a remote environment.

    Similar Jobs