Memory Forensics Analyst - DT #11 - Remote
•Today
| Hours | Full-time |
|---|---|
| Location | Philadelphia, PA Philadelphia, Pennsylvania open_in_new |
About this job
Job Description
Job Description
Memory Forensics Analyst
Location: Remote
Duration: 1–2 Weeks with potential extension
We are seeking an experienced Memory Forensics Analyst to investigate volatile memory and identify evidence of sophisticated cyberattacks, malware activity, and advanced persistence mechanisms.
The role will focus on RAM acquisition and analysis, malicious process identification, code injection detection, memory-resident malware, credential artifacts, and correlation of memory findings with endpoint and network evidence. The ideal candidate will have strong expertise in Windows and Linux memory structures, malware analysis, and incident response.
Key Responsibilities- Acquire and analyze RAM and volatile memory images from compromised systems.
- Identify suspicious or malicious:
- Processes
- Threads
- DLLs and loaded modules
- Injected code
- Network connections
- Memory-resident artifacts
- Investigate fileless malware and other memory-resident threats.
- Identify advanced persistence mechanisms and indicators of compromise.
- Analyze Windows memory structures and Linux memory artifacts.
- Investigate credential-related artifacts and suspicious authentication activity within memory.
- Correlate memory-forensic findings with endpoint and network evidence.
- Perform malware analysis and support reverse-engineering activities when required.
- Develop detailed incident timelines based on volatile-memory evidence and other investigative data.
- Support incident response and threat-hunting activities.
- Document forensic methodology, evidence, findings, and conclusions.
- Prepare technical forensic reports and communicate findings to security and incident response teams.
- Volatility
- Rekall
- Windows memory structures
- Linux memory analysis
- RAM acquisition and analysis
- Process and thread analysis
- DLL/module analysis
- Code injection detection
- Network connection analysis
- Credential artifact analysis
- Malware analysis
- Fileless malware investigation
- Reverse engineering
- Persistence mechanism analysis
- Indicators of Compromise (IOCs)
- Advanced attack investigation
- Python
- PowerShell
- Incident response
- Endpoint investigation
- Network evidence correlation
- Timeline development
- Digital evidence analysis and documentation
- Proven experience in memory forensics, digital forensics, malware analysis, or incident response.
- Strong hands-on experience analyzing RAM and volatile memory images.
- Proficiency with Volatility and/or Rekall.
- Strong understanding of Windows memory structures and processes.
- Experience with Linux memory analysis.
- Ability to identify malicious processes, injected code, DLLs, network connections, and other suspicious memory artifacts.
- Experience investigating fileless malware and advanced persistence techniques.
- Understanding of malware analysis and reverse-engineering methodologies.
- Strong Python and/or PowerShell scripting skills.
- Experience correlating memory evidence with endpoint and network telemetry.
- Strong analytical, investigative, and technical documentation skills.
- Ability to work independently in a remote environment.
Nearby locations
Nearby Job Titles
Truck Driver Jobs Radiologic Technologist Jobs Fast Food Preparation Worker Jobs Nursing Assistant Jobs Food Service Supervisor JobsNearby Locations
Philadelphia, PA Jobs Cherry Hill, NJ Jobs King Of Prussia, PA Jobs Camden, NJ Jobs Pennsylvania JobsNearby Companies
U.S. Navy Jobs Copilot Careers Jobs ApexFocusGroup Jobs DoorDash Jobs Care.com JobsNearby Categories
Full-time Jobs Part-time Jobs Gig Jobs Posting ID: 1297156909 Posted: 2026-09-16 Job Title: Memory Forensic Analyst