CybersecurityJobs.io
← Back to all jobs
Charles River Associates

Associate/Cybersecurity & Incident Response (Forensic Services practice)

New York, NY $93k - $105k/yr Full time Posted 5h ago

Job Description

Charles River Associates is seeking an Associate for its Forensic Services practice, supporting cybersecurity and incident response work for CRA clients. The role centers on executing security and privacy investigations, providing expert digital forensic assistance during data security incidents, and turning technical findings into forensic deliverables that support legal and business outcomes.

This onsite position is based in New York, NY and is designed for candidates with hands-on experience in digital forensics, malware analysis, and threat-focused incident work, including evidence handling and control assessments aligned to recognized cybersecurity frameworks.

Role Summary

  • Execute security and privacy investigations related to data security matters, including ongoing breach detection, threat analysis, incident response support, and malware analysis
  • Provide digital forensic support for counsel and clients in cases such as data breaches and fraud
  • Draft forensic reports and affidavits, and testify as an expert in digital forensics and incident response
  • Perform forensic analysis using standard evidence handling techniques and computer forensics tooling
  • Produce technical assessments/audits and guidance on the adequacy of cyber security controls mapped to frameworks including NIST CSF 2.0, HIPAA, ISO 27001 and 27002, SOC 2, and NERC-CIP

Key Responsibilities

  • Acquire data and images from identified hosts, then locate evidence of compromise by analyzing disk, file, memory, and logs
  • Identify artifact and evidence locations to answer questions such as execution, file access, data theft, anti-forensics, and adversary system usage
  • Hunt and detect unknown live, dormant, and custom malware across enterprise environments
  • Create Indicators of Compromise (IOCs) to strengthen incident response and threat intelligence
  • Track adversary activity second-by-second using in-depth timeline analysis
  • Determine malware type (for example, rootkits, backdoors, and Trojan horses) and support appropriate defenses and response tactics
  • Identify lateral movement and pivots within client environments, showing how an adversary moves system to system
  • Use physical memory analysis tools to assess adversary activities on hosts and pivot points across a network
  • Examine traffic using common network protocols to identify patterns of activity and actions warranting investigation
  • Identify and track malware beaconing to command-and-control (C2) using memory forensics, registry analysis, and network connections
  • Assess the appropriateness and sufficiency of available data for access and analysis, including threat intelligence, logging data, and contextual clues
  • Recognize relationships among multiple sources and information types to support effective data analysis
  • Use programming and analysis tools including Python, T-SQL, VBA, Excel, and C# for programming, model building, and database administration
  • Implement quality control measures and documentation to support reliability of analysis and risk management
  • Participate in practice-building activities, including recruiting and training

Requirements

  • Bachelor’s or Master’s degree with a relevant academic focus (Computer Science, Digital Forensics, Information Security and/or Information Systems)
  • 2-4 years of relevant work experience in financial/economic analysis, preferably in a consulting firm; applications accepted from recent graduates and candidates in the workforce
  • Digital forensics/incident response training and certifications, including SANS GIAC (GCFA, GCFE, GNFA, GIME), IACIS (CFCE or CIFR), Magnet MCFE, X-ways X-Pert or similar
  • Strong understanding of computer operating systems, software, and hardware
  • Ability to conduct detailed forensic investigations across computers, networks, mobile devices, and removable media
  • Experience performing digital forensic analysis with commercial and open source tools, including file system forensics, memory analysis, and network analysis
  • Experience with static/dynamic malware analysis in a lab environment, and threat hunting in a live environment
  • Experience with proper evidence handling procedures and chain of custody
  • Experience drafting technical and investigative reports and communicating technical findings
  • Experience using automation tools and scripts to expedite analysis
  • Understanding of incident handling procedures: preparation, identification, containment, eradication, and recovery
  • Understanding of common adversary attack techniques and how to leverage that knowledge to stop further adversary activity
  • Experience in collegiate computer security competitions

Technologies

  • Python, T-SQL, VBA, Excel, C#, SANS GIAC (GCFA, GCFE, GNFA, GIME), IACIS (CFCE or CIFR), Magnet MCFE, X-ways X-Pert
  • NIST CSF 2.0, ISO 27001, ISO 27002, SOC2, NERC-CIP

Compensation and Location

  • Location: New York, NY (onsite)
  • Salary: USD 92,500 - 105,000 per year (good-faith estimate of annual base salary range)
  • Additional compensation: may be eligible for bonus incentive compensation

Benefits

  • 100 hours of training annually through formal and informal programs
  • Comprehensive total rewards program and a superior benefits package
  • Wellness programming supporting physical, mental, emotional, and financial well-being
  • In-house immigration support for foreign nationals and international business travelers
  • Medical, dental, and vision insurance
  • 401(k) retirement plan with employer match
  • Life and disability insurance
  • Paid time off (vacation, sick leave, holidays)
  • Paid parental leave
  • Wellness programs and employee assistance resources
  • Commuter benefits

How to Apply

  • Resume: include current address, personal email, and telephone number
  • Cover letter: describe interest in CRA and how the role matches goals
  • Transcript: may be unofficial

Work Location Flexibility

  • CRA supports in-office time to enable career growth, mentorship, and inclusivity
  • Expect individuals to work in the office at least 3 to 4 days per week, with specific days coordinated with practice or team (may include travel to another CRA office or client meetings)

Similar Jobs