TXCC - DFL Investigator (Cybersecurity Analyst IV)

• Posted 2 days ago • Updated 6 hours ago
Full Time
USD $11,000.00 - 11,750.00 per month
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • System Integration Testing
  • Supervision
  • Shared Services
  • Law
  • Recovery
  • Decision-making
  • Analytical Skill
  • Professional Development
  • System On A Chip
  • Threat Analysis
  • Security Operations
  • Leadership
  • PASS
  • Information Technology
  • Computer Science
  • Acquisition
  • Legal
  • Auditing
  • Human Resources
  • SAP BASIS
  • Law Enforcement
  • Public Sector
  • Incident Management
  • Digital Forensics
  • Quality Assurance
  • Litigation
  • Reporting
  • EnCase
  • Forensics
  • Workflow
  • GCFA
  • CHFI
  • CISSP
  • GCIH
  • Operating Systems
  • File Systems
  • Storage
  • Cyber Security
  • Electronic Discovery
  • Privacy
  • Records Management
  • Criminal Justice
  • Knowledge Transfer
  • Mentorship
  • Documentation
  • Collaboration
  • Management
  • Collections
  • Information Security
  • Military
  • Recruiting
  • Training
  • Promotions

Summary

Agency Information

The Texas Cyber Command (TXCC) is the state's front line of cyber defense, established by the 89th Texas Legislature to protect Texans, critical infrastructure, and government systems from evolving cyber threats. Headquartered in San Antonio (a national hub of cybersecurity talent), TXCC unites threat detection, incident response, and statewide cyber readiness under one missiondriven agency to establish Texas as the most cyberresilient state in the nation. At TXCC, your work doesn't just sit in a queue it actively secures, protects, defends, and educates over 31 million Texans every day.

Job Description

The Digital Forensic Investigator performs advanced (seniorlevel) cybersecurity analysis and digital forensic investigative work within Texas Cyber Command's Unified Cyber Task Force (UCTF), Digital Forensics Laboratory (DFL). The position collects, preserves, examines, and interprets digital evidence to establish what occurred, identify incident causes and scope of harm, and support response, recovery, and authorized investigations involving state agencies and other eligible entities, including critical infrastructure partners.

Reporting to the DFL Director, the investigator works under limited supervision and exercises independent technical judgment in conducting assigned complex examinations. This senior, handson individualcontributor position produces defensible findings, contributes to laboratory improvements, and may coordinate assigned forensic casework and mentor personnel. The position does not supervise staff; laboratory management, policy approval, and overall case prioritization remain with the DFL Director.

The investigator works closely with the Cybersecurity Incident Response Unit (CIRU), SOC Platform and Shared Services, the Cybersecurity Threat Intelligence Center (CTIC), Regional Security Operations Centers (RSOCs), and authorized investigative partners. CIRU leads assigned incident response; the investigator provides timely forensic support while maintaining DFL evidencehandling and examination requirements.

Work is performed within assigned authority, approved agreements, applicable law, and established procedures.

Essential Job Duties

  • Plans and conducts complex digital forensic examinations. Clarifies investigative objectives, confirms authorized scope, identifies relevant evidence sources, selects appropriate examination methods, and coordinates priorities and deliverables with Digital Forensics Laboratory (DFL) leadership and assigned incident or investigative personnel.
  • Collects, acquires, preserves, and safeguards digital evidence using approved onsite and remote methods, including forensic imaging and acquisition of relevant system, storage, email, log, and other electronic data. Documents acquisition conditions, verifies evidence integrity, and maintains accurate chainofcustody, access, storage, transfer, retention, and disposition records.
  • Examines and analyzes digital artifacts to reconstruct events, recover relevant data, evaluate user and system activity, and identify unauthorized access, malicious activity, data exposure, or other significant findings. Correlates forensic results with available incident and investigative information and seeks specialized support when an examination exceeds available capabilities.
  • Provides timely forensic findings to Cyber Incident Response Unit (CIRU) and other authorized personnel regarding affected systems, accounts, data, incident causes, scope of impact, and remaining evidence gaps. Explains implications for containment, eradication, recovery, and related investigative actions while clearly distinguishing preliminary findings from validated conclusions.
  • Maintains contemporaneous examiner notes and complete case documentation describing evidence sources, examination methods, tool versions, significant settings, results, limitations, and other information necessary to support reproducibility and technical review. Prepares clear, objective forensic reports, briefings, evidence manifests, and supporting documentation for investigative, administrative, lawenforcement, or judicial purposes.
  • Provides technical explanations, depositions, or testimony regarding forensic examinations, evidence handling, methodologies, and findings within the scope of the investigator's qualifications. Supports authorized eDiscovery, litigation holds, audits, administrative investigations, records requests, and related matters while maintaining appropriate separation from legal, personnel, disclosure, and other decisionmaking responsibilities.
  • Recommends and implements approved improvements to forensic laboratory procedures, examination environments, evidence workflows, tool readiness, and quality practices. Evaluates forensic methods and tools, participates in technical peer review, documents limitations and corrective actions, and supports consistent and reproducible examination practices.
  • Uses approved automation and technical workflows to improve evidence processing, analysis, and reporting. Defines forensic requirements, tests and validates workflows, verifies automated outputs against source evidence, documents processing history, and escalates unreliable results while retaining responsibility for analytical conclusions.
  • Provides technical guidance, mentoring, and knowledge transfer to analysts and approved support personnel. Demonstrates forensic examination methods, evidencepreservation practices, case documentation, and report preparation and contributes to training, exercises, and professional development activities.
  • Shares authorized forensic findings and technical information with CIRU, Security Operations Center (SOC), Cyber Threat Intelligence Center (CTIC), Regional Security Operations Center (RSOC), and other appropriate personnel to support incident scoping, threat hunting, detection improvements, and prevention of recurring incidents. Keeps DFL leadership informed of case status, deadlines, evidence risks, workload, resource needs, and significant investigative developments and contributes to afteraction improvements.
  • Performs other workrelated duties as assigned.

Qualifications

All TXCC employees must:
  • Be a United States citizen; and
  • Complete and pass a fingerprint criminal background check.

Minimum Qualifications

Education:
  • Graduation from an accredited fouryear college or university. Coursework in digital forensics, cybersecurity, information technology, computer science, criminal justice, or a related field is preferred.

Experience:
  • A minimum eight (8) years of progressively responsible experience in digital forensics, cybersecurity investigations, incident response, eDiscovery, or closely related technical investigative work.
  • A minimum five (5) years of handson experience conducting digital forensic examinations, including evidence acquisition, preservation, analysis, documentation, and reporting. These five years may be included within the eight years of required experience.
  • Experience using professional digital forensic acquisition and analysis tools and maintaining chain of custody, evidence integrity, examiner documentation, and technically defensible examination records.
  • Experience supporting cybersecurity incidents or complex investigations involving sensitive electronic information and collaborating with technical, investigative, legal, audit, human resources, or other relevant stakeholders.
  • Experience documenting and applying forensic methodologies and clearly communicating technical findings to both technical and nontechnical audiences.

Licensure:
  • Must obtain and maintain any required security clearances and satisfy applicable state employment requirements.

Acceptable Substitutions:
  • Additional related work experience may be used to substitute the formal education requirement on a yearforyear basis. Candidates must possess a high school diploma or equivalent certificate.

Preferred Qualifications

Experience:
  • Experience working in a government, law enforcement, publicsector incident response, or multidisciplinary enterprise digital forensics environment.
  • Experience establishing, leading, or substantially improving a digital forensics laboratory or program, including examination procedures, evidence controls, quality assurance practices, validation processes, or examiner training.
  • Experience supporting eDiscovery, litigation holds, internal investigations, investigative reporting, depositions, or testimony in administrative or judicial proceedings.
  • Advanced experience with EnCase, Magnet Forensics, or comparable forensic and eDiscovery platforms, including enterprise evidence collection or validated automated evidenceprocessing workflows.

Licensure:
  • Relevant professional certification, such as GCFA, GCFE, EnCE, MCFE, CHFI, CISSP, GCIH, or a comparable forensic or cybersecurity credential.

Knowledge/Skills/Abilities

  • Knowledge of digital forensic principles, examination methodologies, and evidentiary standards.
  • Knowledge of operating systems, file systems, storage technologies, and common sources of digital evidence.
  • Knowledge of cybersecurity incident concepts, investigative processes, and methods for interpreting digital artifacts.
  • Knowledge of electronic evidence preservation, chainofcustody requirements, forensic quality practices, and examination integrity.
  • Knowledge of eDiscovery concepts and processes, including preservation, collection, review, and production of electronically stored information.
  • Knowledge of applicable confidentiality, privacy, recordsmanagement, informationsecurity, and criminal justice information requirements.

  • Skill in acquiring, preserving, examining, and interpreting digital evidence using appropriate forensic tools and techniques.
  • Skill in correlating information from multiple sources, identifying relevant artifacts, and reconstructing timelines or sequences of events.
  • Skill in selecting appropriate examination methods, validating results, and identifying technical limitations or sources of uncertainty.
  • Skill in maintaining accurate, complete, and defensible case records and examination documentation.
  • Skill in preparing clear, objective, and technically supported investigative findings and reports.
  • Skill in communicating complex technical information, findings, limitations, and investigative considerations to technical and nontechnical audiences.
  • Skill in using forensic software, evidence repositories, casemanagement systems, and standard office and collaboration technologies used to support investigative work.
  • Skill in providing technical guidance, knowledge transfer, and mentoring to other forensic personnel.

  • Ability to exercise sound independent technical judgment within established policies, procedures, and evidentiary standards.
  • Ability to evaluate multiple possible explanations, weigh available evidence, and distinguish supported conclusions from assumptions or unresolved questions.
  • Ability to recognize the limitations of available evidence and determine when additional examination, information, or specialized expertise is needed.
  • Ability to organize and prioritize multiple investigations, examinations, and assignments while maintaining accuracy and appropriate documentation.
  • Ability to identify relevant investigative issues and determine appropriate next steps based on available technical evidence.
  • Ability to adapt examination approaches to evolving technologies, forensic methods, and investigative requirements.

Working Conditions

  • Work is performed in office, laboratory, and authorized field environments and involves prolonged computer use, detailed examination of sensitive electronic information, and collaboration with multidisciplinary teams.
  • Duties may include handling electronic equipment and evidence, managing competing case deadlines, participating in assigned oncall coverage, occasional travel, and working extended or nonstandard hours during incidents, exercises, surge operations, field collections, partner support, or testimony.
  • Some assignments may require travel or response on short notice. Work requires adherence to applicable confidentiality, informationsecurity, evidencehandling, and evidencesecurity requirements.

Military/Veteran Information

Military Occupation Specialty Code

The Military Occupation Specialty Codes applicable to this position can be found at this link .

Selective Service Registration

Section 651.005 of the Government Code requires males, ages 18 through 25 years, to provide proof of their Selective Service registration or proof of their exemption from the requirement as a condition of state employment.

Additional Information

H1B Visa Sponsorship

We are unable to sponsor or take over sponsorship of an employment visa. Texas Cyber Command employees of the United States.

Equal Opportunity Employer

Texas Cyber Command does not exclude anyone from consideration for recruitment, selection, appointment, training, promotion, retention, or any other personnel action, or deny any benefits or participation in programs or activities, which it sponsors on the grounds of race, color, national origin, sex, religion, age, or disability. Please call to request reasonable accommodation.

How to Apply

Application Requirements

Every application must reflect a full employment history for each job held. You may provide this either directly in the Work History section of your application or as an attached rsum, but either way, each position listed must include:
  • Job title
  • Name of employer
  • Employment start and end dates (month and year)
  • A summary of the duties and responsibilities you held

If a listed position was parttime, please note that in the work history section or on your rsum.

Applicants must also answer the supplemental questions in the job application. Applications missing this information may be treated as incomplete and will not move forward in the review process.

Additional Application Information
  • Fields that don't apply to you should be marked "N/A."
  • If you're relying on education (rather than experience) to meet the minimum qualifications for this position, please attach a copy of your college transcript to your application.
  • Leaving out required information could result in your application being disqualified from consideration.

Applying Through Work In Texas (WIT)

If you're applying via Work In Texas, you'll also need to complete the set of supplemental questions before your application can be considered. These questions are only in CAPPS Recruit, so you'll need to register for or sign in to your candidate profile: Access CAPPS Candidate Gateway

Need some help putting together a rsum? Work In Texas offers a "Create a Rsum" tool for job seekers on their website .

Contact Information

If you have any questions, please reach out to TXCC Human Resources at .
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 80183300
  • Position Id: a272bc635bb806e8e8132291e45284af
  • Posted 2 days ago
Create job alert
Never miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Bethesda, Maryland

•

Today

Full-time

USD 200,001.00 - 240,000.00 per year

Ashburn, Virginia

•

Today

Full-time

Linthicum Heights, Maryland

•

Today

Full-time

USD 63,600.00 - 111,300.00 per year

Boston, Massachusetts

•

Today

Full-time

USD 30.00 - 37.50 per hour

Search all similar jobs