Occupation Details
Digital Forensics Analysts
Conduct investigations on computer-based crimes establishing documentary or physical evidence, such as digital media and logs associated with cyber intrusion incidents. Analyze digital evidence and investigate computer security incidents to derive information in support of system and network vulnerability mitigation. Preserve and present computer-related evidence in support of criminal, fraud, counterintelligence, or law enforcement investigations.
Quick Navigation
Salary & Job Outlook
Starting Salary
$54,820.00
New York StateMedian Salary
$92,750.00
New York StateExperienced Salary
$121,450.00
New York StateNational Average for Comparison
New York State Job Market Outlook
Jobs Right Now (2018)
6,380
professionals in NYFuture Job Growth (2030)
7,280
+90 jobs/yearNew Jobs Every Year
583
new opportunities yearlyGrowth Rate
0.1%
projected increasePreparation: Experience, Training, and Education
The list below outlines the prior educational experience required to perform in this occupation.
Degree Needed - Four-year college
Experience Requirements
A considerable amount of work-related skill, knowledge, or experience is needed for these occupations. For example, an accountant must complete four years of college and work for several years in accounting to be considered qualified.
Education Requirements
Most of these occupations require a four-year bachelor's degree, but some do not.
Training Details
Employees in these occupations usually need several years of work-related experience, on-the-job training, and/or vocational training.
Transferrable Skills and Experience
Many of these occupations involve coordinating, supervising, managing, or training others. Examples include real estate brokers, sales managers, database administrators, graphic designers, conservation scientists, art directors, and cost estimators.
School Programs
The following lists school programs which are applicable to this occupation.
Licensing & Certification
State License and Certifications Requirements are not currently associated with this occupation.
Skills
Skills information is not available for this occupation.
Knowledge
Knowledge information is not available for this occupation.
Work Environment
Work Environment information is not available for this occupation.
Work Styles
Work styles information is not available for this occupation.
Tools & Technology
This list below describes the machines, equipment, tools, software, and information technology that workers in this occupation will use.
Tools
Tool information is not available for this occupation.
Technology
Technology information is not available for this occupation.
Duties
Job duties information is not available for this occupation.
Tasks
The list below outlines specific tasks that a worker in this occupation is called upon to do regularly.
- Adhere to legal policies and procedures related to handling digital media.
- Analyze log files or other digital information to identify the perpetrators of network intrusions.
- Conduct predictive or reactive analyses on security measures to support cyber security initiatives.
- Create system images or capture network settings from information technology environments to preserve as evidence.
- Develop plans for investigating alleged computer crimes, violations, or suspicious activity.
- Develop policies or requirements for data collection, processing, or reporting.
- Duplicate digital evidence to use for data recovery and analysis procedures.
- Identify or develop reverse-engineering tools to improve system capabilities or detect vulnerabilities.
- Maintain cyber defense software or hardware to support responses to cyber incidents.
- Maintain knowledge of laws, regulations, policies or other issuances pertaining to digital forensics or information privacy.
- Perform file signature analysis to verify files on storage media or discover potential hidden files.
- Perform forensic investigations of operating or file systems.
- Perform web service network traffic analysis or waveform analysis to detect anomalies, such as unusual events or trends.
- Preserve and maintain digital forensic evidence for analysis.
- Recommend cyber defense software or hardware to support responses to cyber incidents.
- Recover data or decrypt seized data.
- Write and execute scripts to automate tasks, such as parsing large data files.
- Write cyber defense recommendations, reports, or white papers using research or experience.
- Write reports, sign affidavits, or give depositions for legal proceedings.
- Write technical summaries to report findings.

