Consulting Associate/Recovery Services (Forensic Services practice)
Charlesriverassociates
·Today
- Salary
- $100k – $127k
- Location
- Boston, MA, United States; Chicago, IL, United States; Dallas, Texas, United States; Houston, Texas, United States; New York, NY, United States; Oakland, CA, United States; Washington, DC, United States · Boston, MA, United States · Chicago, IL, United States · Dallas, Texas, United States · Houston, Texas, United States · New York, NY, United States · Oakland, CA, United States · Washington, DC, United States
- Workplace
- Remote, Hybrid
- Department
- Forensic Services
- Seniority
- Entry
- Source
- Greenhouse
Description
About Charles River Associates
CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strategy and operational issues to become more profitable, and advises governments on the economic impact of policies and regulations. Our two main services – economic and management consulting – are delivered by practice groups that focus on specific areas of expertise or industries. Click here to learn how CRA can help you launch your career.
Position Overview
CRA’s Forensic Services practice supports companies’ commitment to integrity by assisting them and their counsel in independently responding to allegations of fraud, waste, abuse, misconduct, and non-compliance. We are noted for deploying cross-trained teams of forensic professionals to assist our clients in gaining deeper insights and greater value more quickly. We provide accounting and forensic services as well as cybercrime investigation services.
The Consulting Associate is a hands-on technical responder and forensic analyst who executes the core workstreams of incident response and recovery engagements. You will lead forensic collection and analysis, drive containment and eradication actions in hybrid Microsoft environments, and rebuild enterprise identity and infrastructure under time pressure. This role is for a practitioner who is equally comfortable pulling disk images from a compromised ESXi host at 2 AM and walking a general counsel through the findings the next morning.
Key Responsibilities
- Execute digital forensic collection and analysis across Windows, Linux, virtualized (VMware, Hyper-V), and cloud (Azure, M365, Google Workspace) environments
- Perform endpoint and identity containment using EDR platforms (CrowdStrike Falcon or equivalent), including real-time response, custom detection logic, and telemetry analysis
- Lead technical recovery workstreams in ransomware matters: domain controller rebuild and validation, tiered credential resets, hypervisor and backup restoration, and host checkout against defined gate criteria
- Investigate business email compromise and wire fraud matters, including mail flow reconstruction, tenant log analysis, OAuth and enterprise application audits, and attacker infrastructure attribution
- Analyze and remediate hybrid identity environments: Active Directory, Entra ID, Entra Connect, Conditional Access, and privileged access configurations
- Develop and maintain PowerShell, Graph SDK, and Python tooling for collection, containment, and recovery automation
- Produce clear, defensible written work product: forensic reports, investigation timelines, containment playbooks, and client status communications
- Support engagement scoping by contributing technical level-of-effort estimates grounded in environment evidence
- Interface directly with client IT teams, counsel, and carrier representatives during active matters
Desired Qualifications
- 3-5 years of hands-on experience in incident response, digital forensics, or a closely related security engineering role
- Demonstrated experience responding to ransomware, BEC, or intrusion matters in enterprise environments
- Deep working knowledge of Active Directory and Entra ID, including attack paths (Kerberos abuse, shadow credentials, ADCS misconfigurations) and hardening controls
- Proficiency with at least one enterprise EDR platform and its response tooling
- Strong scripting ability in PowerShell; Python a plus
- Excellent written communication; able to produce report-quality prose without heavy editing
- Ability to operate independently under incident conditions and manage competing priorities across concurrent matters
Preferred Qualifications
- Industry certifications such as GCFA, GCIH, GNFA, GCFE, EnCE, CISSP, or equivalent
- Experience with virtualization forensics (VMware vSAN, iSCSI, datastore-level acquisition) and backup platform recovery
- Familiarity with Google Workspace forensics and administrative tooling
- Experience working under legal privilege with outside counsel and cyber insurance carriers
- Exposure to OT/ICS environments or regulated industries (healthcare, financial services)
Work Environment
- Incident response work involves surge periods, including nights and weekends during active engagements.
To Apply
To be considered for a position in the United States, we require the following:
- Resume – please include current address, personal email and telephone number;
- Cover letter (optional) – please describe your interest in CRA and how this role matches your goals.
If you are interested in applying for one of our international locations, please visit our Careers site to view and apply for available jobs.
Career Growth and Benefits
- CRA’s robust skills development programs, including a commitment to offering 100 hours of training annually through formal and informal programs, encourage you to thrive as an individual and team member. Beginning with research and analysis skill building, training continues with technical training, presentation skills, internal seminars, and career mentoring and performance coaching from an assigned senior colleague. Additional leadership and collaboration opportunities exist through internal firm development activities.
- We offer a comprehensive total rewards program including a superior benefits package, wellness programming to support physical, mental, emotional and financial well-being, and in-house immigration support for foreign nationals and international business travelers.
Work Location Flexibility
CRA creates a work environment that enables our colleagues to benefit from being together in the office to best deliver on our promise of career growth, mentorship and inclusivity. At the same time, we recognize that individuals realize a range of benefits when working from home periodically. We currently expect that individuals spend at least 3 to 4 days a week working in the office (which may include traveling to another CRA office or to client meetings), with specific days determined in coordination with your practice or team.
Our Commitment to Equal Employment Opportunity
Charles River Associates is an equal opportunity employer (EOE). All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, status as a protected veteran, or any other protected characteristic under applicable law.
Salary and other compensation
A good-faith estimate of the annual base salary range for this position is $100,000 - $126,500. Stating pay within this range may vary based on factors such as education level, experience, skills, geographic location, market conditions, and other qualifications of the successful candidate. This position may be eligible for additional bonus incentive compensation.
CRA offers a comprehensive benefits package, subject to eligibility requirements, which may include: medical, dental, and vision insurance; 401(k) retirement plan with employer match; life and disability insurance; paid time off (vacation, sick leave, holidays); paid parental leave; wellness programs and employee assistance resources; and commuter benefits.