We use essential cookies

Please Accept our Privacy Policy

Digital Forensic Intrusions Lead

Spry Methods

Linthicum, MD • $200,000 to $225,000 / yr • 10/8/2026

Job Description

Job Description
Spry Methods is seeking a Forensic Acquisition and Extraction Lead to direct all forensic imaging and data extraction activities at a government digital forensics laboratory. This position manages the Imaging and Extraction section and gives its staff technical oversight. It is responsible for evidence acquisition from hard drives, mobile devices, and IoT devices, and for running laboratory workflows and maintaining chain-of-custody documentation.
What Your Day-To-Day Looks Like (Position Responsibilities):
  • Lead technical efforts supporting system and network forensic examinations.

  • Supervise teams operating in a forensic laboratory environment.

  • Oversee malware analysis and reverse engineering activities.

  • Guide digital and multimedia forensic examinations and analysis.

  • Analyze endpoint, Packet Capture (PCAP), and other relevant data sources.

  • Apply forensic network analysis in support of investigative processes.

  • Ensure technical activities comply with applicable legal, accreditation, and Government requirements.

  • Use common forensic examination tools, including FTK, EnCase, and X-Ways.

  • Support the quality and efficiency of task performance and assist with task-level financial and business processes, excluding inherently governmental functions.

What You Need to Succeed (Minimum Requirements):
  • TS/SCI clearance eligible.

  • Experience within the last five years leading technical efforts and supervising teams in a forensic laboratory environment similar in scope and complexity to the PWS.

  • Experience within the last seven years performing digital and multimedia forensic examinations, analysis, and techniques.

  • Experience within the last seven years using Microsoft Windows, Apple/UNIX, and Linux operating systems in forensic examinations.

  • Experience within the last seven years conducting forensic network analysis in support of investigations.

  • Experience within the last seven years analyzing endpoint, PCAP, and other relevant data sources.

  • Experience within the last five years using common digital forensic tools, including FTK, EnCase, and X-Ways.

Final compensation will be based on experience, qualifications, certifications, clearance level, and contract requirements. This position is contingent upon contract award.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.