Digital Forensics Analysts
Conduct investigations on computer-based crimes establishing documentary or physical evidence, such as digital media and logs associated with cyber intrusion incidents. Analyze digital evidence and investigate computer security incidents to derive information in support of system and network vulnerability mitigation. Preserve and present computer-related evidence in support of criminal, fraud, counterintelligence, or law enforcement investigations.
Median pay (national)
$108,970
$52,650–$176,800 (10th–90th)
Employed (US)
439,380
BLS OEWS, May 2024
Outlook 2024–34
+8.2%
~31,300 openings/yr
Typical entry
Bachelor's degree
What the numbers say
Refit analysis ·Pay for digital forensics analysts shows an unusually wide range: the top 10% earn $176,800 versus $52,650 at the bottom 10% — 3.4x. The median of $108,970 leaves roughly 62% of headroom to the 90th percentile, which is where seniority, specialization, and the skills below tend to pay off.
Refit analysis ·Employment is projected to change +8.2% from 2024 to 2034 — much faster than the 3% average for all occupations. Even so, BLS projects about 31,300 openings a year, mostly to replace workers who retire or change careers.
Refit analysis ·Where you work moves the number a lot. Across the 53 states with released data, Virgin Islands pays the most for this role (median $179,830, +65% vs the national median), while Puerto Rico sits lowest at $42,250 — a 326% spread for the same job title.
Tailor your resume to Digital Forensics Analysts
Honest tailoring
See how your resume lines up with Digital Forensics Analysts
Refit re-angles your real experience toward this role using the skills above — and never invents skills you don't have. A no-fabrication gate checks every change before you see it.
Free. No account needed to see your first re-fit.
What they actually do
Core O*NET tasks for this role.
- Adhere to legal policies and procedures related to handling digital media.
- Analyze log files or other digital information to identify the perpetrators of network intrusions.
- Conduct predictive or reactive analyses on security measures to support cyber security initiatives.
- Create system images or capture network settings from information technology environments to preserve as evidence.
- Develop plans for investigating alleged computer crimes, violations, or suspicious activity.
- Develop policies or requirements for data collection, processing, or reporting.
- Duplicate digital evidence to use for data recovery and analysis procedures.
- Identify or develop reverse-engineering tools to improve system capabilities or detect vulnerabilities.
- Maintain cyber defense software or hardware to support responses to cyber incidents.
- Maintain knowledge of laws, regulations, policies or other issuances pertaining to digital forensics or information privacy.
Tools & technology
- Amazon Web Services AWS software
- Firewall software
- Linux
- Microsoft PowerShell
- MITRE ATT&CK software
- Python
- Splunk Enterprise
- Structured query language SQL
- Ansible software
- Apple iOS
- Apple macOS
- Bash
- Border Gateway Protocol BGP
- C
- C#
- C++