CybersecurityJobs.io
← Back to all jobs

Job Description

Charles River Associates (CRA) is seeking an Associate for its Forensic Services practice, with a focus on cybersecurity and incident response. The role supports security and privacy investigations, digital forensics deliverables, and incident response and cyber security control assessments for client engagements.

Key Responsibilities

  • Execute security and privacy investigations for CRA clients in preparation for and response to data security matters, including ongoing breach detection, threat analysis, incident response, and malware analysis.
  • Provide expert digital forensic support to counsel and clients in connection with data security incidents, such as data breaches or fraud.
  • Assist with drafting forensic reports and affidavits, and testify as an expert in digital forensics and incident response.
  • Perform problem-solving and forensic analysis of digital information using standard evidence handling techniques and computer forensics tools.
  • Identify, research, and organize relevant information to assess the appropriateness and sufficiency of available data for effective data access and analysis.
  • Develop familiarity with analysis inputs, including threat intelligence, logging data, and contextual clues.
  • Recognize relationships across multiple information sources and types to support effective data analysis.
  • Use programming and analysis capabilities, including Python, T-SQL, VBA, Excel, C#, and related technologies, for model building and database administration.
  • Support reliability of analysis and risk management by implementing quality control measures and maintaining documentation.
  • Forensically acquire data and images from identified hosts, locate evidence of compromise, and determine impact through disk, file, memory, and log analysis.
  • Identify artifact and evidence locations to answer adversary-focused questions, including execution, file access, data theft, anti-forensics, and detailed system usage.
  • Detect and hunt unknown live, dormant, and custom malware across an enterprise environment.
  • Create Indicators of Compromise (IOCs) from analysis to strengthen incident response and threat intelligence efforts.
  • Track adversary activity second-by-second on a host through in-depth timeline analysis.
  • Assess evidence to determine malware type used in an attack (including rootkits, backdoors, and Trojan horses), and apply appropriate defensive and response tactics.
  • Identify lateral movement and pivots within client enterprises, including how an adversary moves from system to system without detection.
  • Use physical memory analysis tools to determine adversary activities on a host and other network pivot points.
  • Examine traffic using common network protocols to identify patterns or specific actions requiring further investigation.
  • Identify and track malware beaconing to command and control (C2) channels using memory forensics, registry analysis, and network connections.
  • Provide technical assessment and audit guidance to clients regarding the adequacy of cyber security controls aligned to frameworks including NIST CSF 2.0, HIPAA, ISO 27001 and ISO 27002, SOC 2, and NERC-CIP.
  • Participate in practice-building activities, including recruiting and training.

Requirements

  • Bachelor's or Master's degree with a relevant academic focus (Computer Science, Digital Forensics, Information Security and/or Information Systems).
  • 2-4 years of relevant work experience in financial/economic analysis, preferably in a consulting firm.
  • Digital forensics and incident response training and certifications, including SANS GIAC (GCFA, GCFE, GNFA, GIME), IACIS (CFCE or CIFR), Magnet MCFE, X-ways X-Pert, or similar.
  • Strong understanding of computer operating systems, software, and hardware.
  • Ability to conduct detailed forensic investigations across computers, networks, mobile devices, and removable media.
  • Experience conducting digital forensic analysis using commercial and open source forensic tools, including file system forensics, memory analysis, and network analysis.
  • Experience performing static and dynamic malware analysis in a lab environment and threat hunting in a live environment.
  • Experience in collegiate computer security competitions.
  • Strong understanding of evidence handling procedures and chain of custody.
  • Experience drafting technical and investigative reports and communicating technical findings.
  • Experience utilizing automation tools and scripts to expedite analysis.
  • Understanding of incident handling procedures: preparation, identification, containment, eradication, and recovery.
  • Understanding of common adversary attack techniques used on a victim network to stop further malicious activity.

Technology Stack

  • Python, T-SQL, VBA, Excel, C#
  • NIST CSF 2.0, HIPAA, ISO 27001, ISO 27002, SOC 2, NERC-CIP
  • SANS GIAC (GCFA, GCFE, GNFA, GIME), IACIS (CFCE or CIFR), Magnet MCFE, X-ways X-Pert
  • IOCs, C2 (command and control)

Benefits

  • Superior benefits package
  • Wellness programming to support physical, mental, emotional, and financial well-being
  • In-house immigration support for foreign nationals and international business travelers
  • Medical, dental, and vision insurance
  • 401(k) retirement plan with employer match
  • Life and disability insurance
  • Paid time off (vacation, sick leave, holidays)
  • Paid parental leave
  • Wellness programs and employee assistance resources
  • Commuter benefits
  • 100 hours of training annually

Additional Information

  • This is an immediate opening; current students should apply to campus postings.
  • Recent graduates or individuals without directly relevant experience may be hired into the Analyst title.
  • Individuals interested in international locations should visit CRA’s Careers site to view and apply for available jobs.

Location, Schedule Expectations, and Compensation

  • Location: Chicago, IL (onsite)
  • We expect individuals to work in the office at least 3 to 4 days a week, potentially including travel to another CRA office or client meetings; specific days are coordinated with the practice or team.
  • Salary range (annual base): $92,500 - $105,000 (good-faith estimate).
  • This position may be eligible for additional bonus incentive compensation.

How to Apply

  • Resume: include current address, personal email, and telephone number.
  • Cover letter: describe interest in CRA and how the role matches your goals.
  • Transcript: may be unofficial.

In the United States: Application Considerations

To be considered for a position in the United States, CRA requires additional items as part of the selection process. Details are provided during application.

Career Growth and Training

  • Robust skills development programs with a commitment to offering 100 hours of training annually through formal and informal programs.
  • Ongoing training that includes technical training, presentation skills, internal seminars, and career mentoring with performance coaching from an assigned senior colleague.
  • Additional leadership and collaboration opportunities through internal firm development activities.

Similar Jobs