Task statements

  • Develop policies or requirements for data collection, processing, or reporting.
  • Duplicate digital evidence to use for data recovery and analysis procedures.
  • Preserve and maintain digital forensic evidence for analysis.
  • Adhere to legal policies and procedures related to handling digital media.
  • Write reports, sign affidavits, or give depositions for legal proceedings.
  • Perform forensic investigations of operating or file systems.
  • Create system images or capture network settings from information technology environments to preserve as evidence.
  • Maintain knowledge of laws, regulations, policies or other issuances pertaining to digital forensics or information privacy.
  • Write technical summaries to report findings.
  • Perform file signature analysis to verify files on storage media or discover potential hidden files.
  • Recover data or decrypt seized data.
  • Develop plans for investigating alleged computer crimes, violations, or suspicious activity.
  • Analyze log files or other digital information to identify the perpetrators of network intrusions.
  • Maintain cyber defense software or hardware to support responses to cyber incidents.
  • Perform web service network traffic analysis or waveform analysis to detect anomalies, such as unusual events or trends.
  • Write cyber defense recommendations, reports, or white papers using research or experience.
  • Identify or develop reverse-engineering tools to improve system capabilities or detect vulnerabilities.
  • Conduct predictive or reactive analyses on security measures to support cyber security initiatives.
  • Write and execute scripts to automate tasks, such as parsing large data files.
  • Recommend cyber defense software or hardware to support responses to cyber incidents.

Career and skills data: O*NET 31.0 (onetcenter.org). Figures are published survey estimates, not real-time market data.