Overview
The Digital Forensic Examiner plays a critical role in the Information Security Office by conducting advanced forensic examinations, eDiscovery, and investigative analysis across a wide range of digital platforms. This position supports legal, HR, law enforcement, and cybersecurity investigations, ensuring all evidence is collected, preserved, and analyzed according to the highest technical and legal standards. The examiner's work may be used in civil litigation, administrative proceedings, depositions, or criminal trials, requiring both technical precision and adherence to evidentiary protocols.
Key Responsibilities
Digital Forensics & eDiscovery :
- Perform forensic acquisition, analysis, and preservation of data from cloud services, endpoints, mobile devices, laptops / desktops, and cloud storage.
- Conduct parameter-based forensic services within a Microsoft enterprise environment, including M365, Azure, and other enterprise platforms.
- Implement and maintain automated forensic tools and workflows to ensure consistency, accuracy, and defensibility of digital evidence.
- Conduct HR-related investigations, eDiscovery for lawsuits, fraud, misuse / abuse investigations, and internal police or city employee crimes.
- Provide forensic support for criminal investigations in coordination with city law enforcement, special investigative units, and external agencies as appropriate.
Legal & Investigative Support
Prepare detailed forensic reports documenting methodologies, findings, and evidentiary handling.Maintain strict chain of custody and ensure all analysis meets court-admissible standards.Provide expert witness testimony in depositions, hearings, or criminal proceedings regarding forensic processes and evidence integrity.Collaborate with City Legal, HR, Public Safety, and external law enforcement during active investigations.Risk & Sensitivity Management
Handle cases that may involve exposure to sensitive or disturbing imagery and confidential information with professionalism and discretion.Apply forensic best practices to minimize risk of data corruption, exposure, or mishandling.Ensure compliance with public records laws, federal / state / local regulations, and privacy / security mandates.Required Qualifications
Minimum 15 years of hands-on experience in digital forensic investigations, eDiscovery, and incident response.Proven ability to independently manage complex forensic cases from acquisition through testimony.Expertise with forensic and eDiscovery tools such as EnCase, FTK, X-Ways, Cellebrite, Nuix, Oxygen, Magnet Axiom, and Microsoft Advanced eDiscovery.Advanced knowledge of Microsoft enterprise environments (M365, Exchange, Azure AD, Teams, SharePoint, OneDrive).Strong understanding of chain of custody, rules of evidence, and legal standards for forensic admissibility.Must successfully pass an advanced background check— no felonies or Class A misdemeanors acceptable.Exceptional written and verbal communication skills, with the ability to translate complex forensic findings into reports usable by attorneys, executives, and law enforcement.Preferred Qualifications
Bachelor's or Master's degree in Computer Science, Information Security, Digital Forensics, Criminal Justice, or related field.Industry certifications such as GCFA, GCFE, EnCE, CCE, CFCE, CHFI, MCFE, or ACE.Prior experience in a government, law enforcement, or large enterprise information security environment.Experience testifying in legal proceedings or depositions as a subject matter expert.Familiarity with federal, state, and municipal laws regarding privacy, records retention, and electronic discovery.Work Environment
This role resides in the Information Security Office and works closely with HR, Legal, Internal Audit, and Law Enforcement.Investigations may be high-profile and involve sensitive material; discretion, emotional resilience, and professional judgment are critical.The position requires occasional on-call response to incidents, as well as availability for urgent investigative requests.J-18808-Ljbffr