Consulting Associate/Recovery Services (Forensic Services practice)

Charles River Associates - Chicago, IL

Hiring: Consulting Associate/Recovery Services (Forensic Services practice) Company: Charles River Associates Location: Chicago, IL Job Posted Time: 2026-09-10 15:07:22 Employment Type: Hybrid Target Skills & Keywords : Azure, Linux, OAuth, PowerShell, Python About the job Experience: •3-5 years of hands-on experience in incident response, digital forensics, or a closely related security engineering role •5 years of hands-on experience in incident response, digital forensics, or a closely related security engineering role Required Skills: •Execute digital forensic collection and analysis across Windows, Linux, virtualized (VMware, Hyper-V), and cloud (Azure, M365, Google Workspace) environments •Perform endpoint and identity containment using EDR platforms (CrowdStrike Falcon or equivalent), including real-time response, custom detection logic, and telemetry analysis •Lead technical recovery workstreams in ransomware matters: domain controller rebuild and validation, tiered credential resets, hypervisor and backup restoration, and host checkout against defined gate criteria •Investigate business email compromise and wire fraud matters, including mail flow reconstruction, tenant log analysis, OAuth and enterprise application audits, and attacker infrastructure attribution •Analyze and remediate hybrid identity environments: Active Directory, Entra ID, Entra Connect, Conditional Access, and privileged access configurations •Develop and maintain PowerShell, Graph SDK, and Python tooling for collection, containment, and recovery automation •Produce clear, defensible written work product: forensic reports, investigation timelines, containment playbooks, and client status communications •Support engagement scoping by contributing technical level-of-effort estimates grounded in environment evidence Qualifications: •Demonstrated experience responding to ransomware, BEC, or intrusion matters in enterprise environments •Deep working knowledge of Active Directory and Entra ID, including attack paths (Kerberos abuse, shadow credentials, ADCS misconfigurations) and hardening controls •Proficiency with at least one enterprise EDR platform and its response tooling •Strong scripting ability in PowerShell; Python a plus •Excellent written communication; able to produce report-quality prose without heavy editing •Demonstrated capacity to operate independently under incident conditions and manage competing priorities across concurrent matters •Industry certifications such as GCFA, GCIH, GNFA, GCFE, EnCE, CISSP, or equivalent •Operational familiarity with Google Workspace forensics and administrative tooling •Exposure to OT/ICS environments or regulated industries (healthcare, financial services) •Incident response work involves surge periods, including nights and weekends during active engagements. Compensation: •Flexible work environment (work from home / hybrid options) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!