Consulting Associate/Recovery Services (Forensic Services practice
Listed on 2026-08-17
-
IT/Tech
Cybersecurity
Consulting Associate/Recovery Services (Forensic Services Practice)
CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strategy and operational issues to become more profitable, and advises governments on the economic impact of policies and regulations. Our two main services – economic and management consulting – are delivered by practice groups that focus on specific areas of expertise or industries.
CRA's Forensic Services practice supports companies' commitment to integrity by assisting them and their counsel in independently responding to allegations of fraud, waste, abuse, misconduct, and non-compliance. We are noted for deploying cross-trained teams of forensic professionals to assist our clients in gaining deeper insights and greater value more quickly. We provide accounting and forensic services as well as cybercrime investigation services.
The Consulting Associate is a hands-on technical responder and forensic analyst who executes the core work streams of incident response and recovery engagements. You will lead forensic collection and analysis, drive containment and eradication actions in hybrid Microsoft environments, and rebuild enterprise identity and infrastructure under time pressure. This role is for a practitioner who is equally comfortable pulling disk images from a compromised ESXi host at 2 AM and walking a general counsel through the findings the next morning.
Key Responsibilities- Execute digital forensic collection and analysis across Windows, Linux, virtualized (VMware, Hyper-V), and cloud (Azure, M365, Google Workspace) environments
- Perform endpoint and identity containment using EDR platforms (Crowd Strike Falcon or equivalent), including real-time response, custom detection logic, and telemetry analysis
- Lead technical recovery work streams in ransomware matters: domain controller rebuild and validation, tiered credential resets, hypervisor and backup restoration, and host checkout against defined gate criteria
- Investigate business email compromise and wire fraud matters, including mail flow reconstruction, tenant log analysis, OAuth and enterprise application audits, and attacker infrastructure attribution
- Analyze and remediate hybrid identity environments:
Active Directory, Entra , Entra Connect, Conditional Access, and privileged access configurations - Develop and maintain Power Shell, Graph SDK, and Python tooling for collection, containment, and recovery automation
- Produce clear, defensible written work product: forensic reports, investigation timelines, containment playbooks, and client status communications
- Support engagement scoping by contributing technical level-of-effort estimates grounded in environment evidence
- Interface directly with client IT teams, counsel, and carrier representatives during active matters
- 3-5 years of hands-on experience in incident response, digital forensics, or a closely related security engineering role
- Demonstrated experience responding to ransomware, BEC, or intrusion matters in enterprise environments
- Deep working knowledge of Active Directory and Entra , including attack paths (Kerberos abuse, shadow credentials, ADCS misconfigurations) and hardening controls
- Proficiency with at least one enterprise EDR platform and its response tooling
- Strong scripting ability in Power Shell;
Python a plus - Excellent written communication; able to produce report-quality prose without heavy editing
- Ability to operate independently under incident conditions and manage competing priorities across concurrent matters
- Industry certifications such as GCFA, GCIH, GNFA, GCFE, EnCE, CISSP, or equivalent
- Experience with virtualization forensics (VMware vSAN, iSCSI, datastore-level acquisition) and backup platform recovery
- Familiarity with Google Workspace forensics and administrative tooling
- Experience working under legal privilege with outside counsel and cyber insurance carriers
- Exposure to OT/ICS environments or regulated industries (healthcare, financial services)
- Incident response work involves surge…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).