Consulting Associate/Recovery Services (Forensic Services practice)
About the Role
CRA’s Forensic Services practice supports companies’ commitment to integrity by assisting them and their counsel in independently responding to allegations of fraud, waste, abuse, misconduct, and non-compliance. We deploy cross-trained teams of forensic professionals to assist clients in gaining deeper insights and greater value quickly. The Consulting Associate is a hands-on technical responder and forensic analyst who executes core workstreams of incident response and recovery engagements. This role is for a practitioner comfortable with both technical execution and client communication under pressure.
Responsibilities
- Execute digital forensic collection and analysis across Windows, Linux, virtualized (VMware, Hyper-V), and cloud (Azure, M365, Google Workspace) environments
- Perform endpoint and identity containment using EDR platforms (e.g., CrowdStrike Falcon), including real-time response, custom detection logic, and telemetry analysis
- Lead technical recovery workstreams in ransomware matters: domain controller rebuild and validation, tiered credential resets, hypervisor and backup restoration, and host checkout against defined gate criteria
- Investigate business email compromise and wire fraud matters, including mail flow reconstruction, tenant log analysis, OAuth and enterprise application audits, and attacker infrastructure attribution
- Analyze and remediate hybrid identity environments: Active Directory, Entra ID, Entra Connect, Conditional Access, and privileged access configurations
- Develop and maintain PowerShell, Graph SDK, and Python tooling for collection, containment, and recovery automation
- Produce clear, defensible written work product: forensic reports, investigation timelines, containment playbooks, and client status communications
- Support engagement scoping by contributing technical level-of-effort estimates grounded in environment evidence
- Interface directly with client IT teams, counsel, and carrier representatives during active matters
Requirements
- 3-5 years of hands-on experience in incident response, digital forensics, or a closely related security engineering role
- Demonstrated experience responding to ransomware, business email compromise (BEC), or intrusion matters in enterprise environments
- Deep working knowledge of Active Directory and Entra ID, including attack paths (Kerberos abuse, shadow credentials, ADCS misconfigurations) and hardening controls
- Proficiency with at least one enterprise EDR platform and its response tooling
- Strong scripting ability in PowerShell; Python a plus
- Excellent written communication; ability to produce report-quality prose without heavy editing
- Ability to operate independently under incident conditions and manage competing priorities across concurrent matters
Preferred Qualifications
- Industry certifications such as GCFA, GCIH, GNFA, GCFE, EnCE, CISSP, or equivalent
- Experience with virtualization forensics (VMware vSAN, iSCSI, datastore-level acquisition) and backup platform recovery
- Familiarity with Google Workspace forensics and administrative tooling
- Experience working under legal privilege with outside counsel and cyber insurance carriers
- Exposure to OT/ICS environments or regulated industries (healthcare, financial services)
Work Environment
Incident response work involves surge periods, including nights and weekends during active engagements.
Career Growth and Benefits
- 100 hours of training annually through formal and informal programs, including technical training, presentation skills, internal seminars, and career mentoring
- Comprehensive total rewards program, including superior benefits package, wellness programming, and in-house immigration support
- Leadership and collaboration opportunities through internal firm development activities
Work Location Flexibility
Individuals are expected to spend at least 3 to 4 days a week working in the office, with specific days determined in coordination with your practice or team.
Pay
Annual base salary range for this position is $100,000 - $126,500. This position may be eligible for additional bonus incentive compensation. Benefits include medical, dental, and vision insurance; 401(k) retirement plan with employer match; life and disability insurance; paid time off (vacation, sick leave, holidays); paid parental leave; wellness programs; and commuter benefits.