Digital Forensics Analyst
IT
Remote
Project Overview
Engagement_duration — estimated three‑month project timeline
Start_timing — anticipated September start, dependent on internal application development progress
Work_location — primarily remote with no formal onsite requirement
Travel_expectations — occasional travel availability to Washington, DC or New York as needed
Core Skills
SQL_expertise — advanced SQL proficiency and experience analyzing large‑scale datasets
Forensic_background — digital‑forensics, investigative, or compliance‑review experience
Code_review — ability to interpret application source code; Shuttle code expected to be moderately simple
Evidence_documentation — experience classifying investigative findings and documenting evidence clearly
Compliance_controls — familiarity with data‑access controls, privacy requirements, aggregation thresholds, and related compliance mechanisms
Ideal SQL Analyst Profile
Advanced_SQL_skills — ability to deconstruct nested queries, joins, subqueries, window functions, CTEs, transformations, and dynamically generated SQL
Complex_query_review — comfortable analyzing extremely large SQL statements, including multi‑thousand‑line queries
Compliance_detection — ability to identify logic designed to bypass aggregation thresholds, manipulate counts, evade controls, or expose granular data
Pattern_analysis — experience performing pattern analysis across large query or template populations
Violation_taxonomy — ability to classify violations and build repeatable taxonomies
Metadata_association — experience linking findings to template authors, execution history, and relevant metadata
Analytical_documentation — strong documentation and evidence‑summarization capabilities
Ideal Code Analyst Profile
Forensic_investigation — digital‑forensic investigation experience
Source_code_comprehension — strong ability to interpret service logic and identify intentional or accidental compliance‑control bypasses
Programming_proficiency — experience with Python; Java, Go, C++, or similar backend languages; and shell scripting
Cross_domain_analysis — ability to move fluidly between SQL, logs, application logic, structured data, and forensic evidence
Manipulation_detection — familiarity with identifying intentional logic manipulation, including artificial value changes meant to evade aggregation rules