
OCC eDiscovery Forensic Analyst
Grey Consulting
full-time
Posted on:
Location Type: Remote
Location: Remote • 🇺🇸 United States
Visit company websiteJob Level
JuniorMid-Level
Tech Stack
Cloud
About the role
- The OCC requires professional eDiscovery services to support its left-side eDiscovery program.
- Overseeing the provision of eDiscovery identification, preservation, and collection services in alignment with the agency’s caseload.
- Performing hands-on tasks related to identification, preservation, and collection.
- Must assist the OCC with the following activities: eDiscovery Identification Services.
- Must be able to review the current ESI Data Map.
- Must be able to work with IT staff and various business units within the OCC to determine which sources of ESI may be relevant or responsive to a particular legal matter.
- Must be able to work with Chief Counsel’s office staff, IT system owners, and the CCISG to preserve ESI and hard copy documents following OCC preservation policy.
- Assist CCISG with adhering to preservation instructions for OCC technology including MS SharePoint, custodian hard drives, departed custodian hard drives, external media, network drives, MS Outlook, OCC computers, backup tapes, cellular/smart phones, cloud storage or other sources of ESI when necessary.
- Collect-to-preserve highly relevant ESI or technically precarious data, such as from mobile devices, hard drives, network shares or websites.
- Assist the OCC with gathering potentially discoverable ESI and its metadata.
- Ensure that all ESI collected is logged and tracked appropriately.
- Work with technical resources to resolve issues/questions during collection.
- Manage storage by creating, documenting, and cataloging network file shares to support automated and manual collection efforts.
- Coordinate with the OCC eDiscovery COR and ITS resources to identify data that the agency is not required to maintain for records or other purposes.
- Must be able to maintain detailed logging and audit trails to track user activity and system events that align with the OMB Memorandum M 21-31 logging directive.
- Develop and maintain an integrated master schedule (IMS)
- Maintain the IMS in a central Microsoft SharePoint location, under configuration control, and accessible to the COR and ITS.
- Generate a monthly status report that summarizes completed activities for the month and planned activities for the following month.
Requirements
- Minimum 2 years of experience in an eDiscovery role (Required)
- Using mobile forensic tools (i.e. Cellebrite UFED/PA, GrayKey, Oxygen Forensics, Magnet AXIOM, etc.) to perform forensic imaging and analysis from mobile devices. (Required)
- Experience with hard drive imaging and targeted data extraction, using such tools as Encase, FTK Imager, etc., using proper acquisition protocols, including use of write blockers and chain-of-custody procedures. (Required)
- Experience with collaboration and messaging platform data, such as Microsoft Teams, Skype, and Slack
- Experience reviewing, normalizing, and converting exported data files (CSV, JSON, or HTML) for ingestion of such formats into eDiscovery and review platforms, using tools such as Message Crawler. (Required)
- Experience with preparing detailed technical reports for use in investigations, administrative proceedings and court. (Required)
- An active Computer Forensics Examiner certification (such as Cellebrite CCO/CCPA, EnCE, GCFE, CCE, or CFCE.). (Preferred)
- Experience with handling case management tasks, including oversight of case data and ESI preservation. (Preferred)
- Experience with using Litigation Holds software. (Preferred)
- Experience with using preservation tools such as Microsoft Purview. (Preferred)
- Experience with collecting and preserving data from network file shares, using industry standard tools and techniques. (Preferred)
- Experience with cloud data acquisitions from services such as Microsoft 365. (Preferred)
Benefits
- comprehensive medical
- dental
- 401k with a guaranteed match
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
eDiscoveryforensic imagingdata extractiondata normalizationtechnical report preparationmobile forensicshard drive imagingdata collectionpreservation protocolschain-of-custody procedures
Soft skills
coordinationcommunicationorganizationattention to detailproblem-solving
Certifications
Computer Forensics ExaminerCellebrite CCOCellebrite CCPAEnCEGCFECCECFCE