Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice) at Charles River Associates | Illinois | Rezi

Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice) at Charles River Associates

Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)

Charles River Associates · Illinois

2 weeks ago

Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)

Charles River Associates · Illinois

15 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

CRA is seeking a Cybersecurity Consultant to support client engagements focused on evaluating and managing cybersecurity risk. This role involves leading client-facing assessments, translating client needs into scopes of work, and assessing cybersecurity posture in transaction and investment contexts. You will also support incident readiness reviews, tabletop exercises, and work with the incident response team to identify risk themes and translate them into proactive engagements.

Responsibilities

  • Lead and participate in client-facing assessments, including interviews, workshops, and executive readouts.
  • Translate client discussions into clearly defined engagement scopes and Statements of Work (SOWs).
  • Assess cybersecurity posture in transaction and investment contexts.
  • Distinguish material risks from broader program maturity gaps.
  • Tailor findings to the needs of private equity, legal, and executive stakeholders.
  • Execute cyber due diligence and proactive security assessments through documentation review, stakeholder interviews, and control evaluation.
  • Support incident readiness reviews, tabletop exercises, and broader cyber resilience assessments.
  • Work closely with CRA’s incident response team to identify recurring risk themes and control gaps.
  • Translate observations into follow-on proactive engagements including gap assessments, tabletop exercises, resilience reviews, and broader security uplift efforts.
  • Produce high-quality, client-ready reports that include prioritized findings, risk-based recommendations, and executive-level summaries.
  • Support senior team members in proposal development and business development efforts.
  • Bridge technical cybersecurity findings into clear business risk narratives for legal, private equity, and executive audiences.
  • Contribute to the development of repeatable assessment methodologies, templates, and client-facing deliverables.

Requirements

  • Approximately 5–7 years of experience in cybersecurity consulting, advisory, or due diligence.
  • Experience supporting cyber resilience assessments, incident readiness reviews, tabletop exercises, or related preparedness-focused engagements is a plus.
  • Experience collaborating with incident response, forensic, or crisis management teams to translate post-incident observations into proactive assessment, readiness, or remediation-focused engagements is a plus.
  • Comfortable leading discussions with CIOs, IT Directors, and legal stakeholders.
  • Strong ability to guide conversations, ask structured questions, and manage meetings effectively.
  • Excellent executive communication skills with clear, concise, and unambiguous delivery.
  • Experience drafting or contributing to Statements of Work (SOWs), engagement letters, and proposals.
  • Ability to translate loosely defined client needs into structured deliverables and timelines.
  • Strong commercial awareness, including understanding scope boundaries and identifying opportunities to expand engagements.
  • Ability to tailor scopes and findings to transaction, diligence, or investment-focused objectives.
  • Impeccable written communication skills, including grammar, structure, and formatting.
  • Ability to produce logically consistent, defensible findings and recommendations.
  • Experience delivering polished, client-ready cybersecurity risk reports.
  • Ability to prioritize findings based on business impact, articulate critical versus lower-priority issues, and develop executive-ready narratives.
  • Strong working knowledge of NIST Cybersecurity Framework.
  • Ability to map controls, identify gaps, and translate findings into business risk and impact.
  • Ability to evaluate how controls operate together across governance, identity, endpoint, cloud, recovery, and monitoring layers.
  • Broad understanding of core cybersecurity domains, including Identity & Access Management, Endpoint security, Vulnerability management tools, Backup and recovery strategies, Email security, and Asset inventory, device management, and patch lifecycle practices.
  • Comfort reviewing supporting documentation such as security policies and standards, architecture diagrams, control evidence, recovery procedures, and technical configurations.
  • Ability to connect these domains into a comprehensive security program narrative.
  • Exposure to tools such as CrowdStrike, Tanium, Microsoft 365, Azure/Entra ID, and AWS is preferred.
  • Ability to evaluate and interpret tooling deployment, configuration, and coverage in an advisory context.
  • Strong organizational and time management skills, with the ability to manage multiple workstreams simultaneously.
  • High level of ownership, attention to detail, and ability to deliver work independently with minimal oversight.
  • Ability to help develop reusable assessment content, templates, and client-ready materials.
  • Certifications such as CISSP, CISM, CISA, PMP, or similar are nice-to-have.
  • Resume including current address, personal email and telephone number.
  • Cover letter describing interest in CRA and how the role matches goals.

Skills

  • Cybersecurity risk assessment
  • Due diligence
  • Advisory services
  • Client-facing communication
  • NIST Cybersecurity Framework
  • CIS Benchmarks
  • ISO 27001
  • SOC 2 Type II
  • HIPAA
  • HITRUST
  • Identity & Access Management
  • Endpoint security
  • Vulnerability management
  • Backup and recovery
  • Email security
  • Asset management
  • Report writing
  • Business risk narrative development
  • Proposal development
  • Incident response support
  • Cyber resilience assessment
  • Tabletop exercises
  • CrowdStrike
  • Tanium
  • Microsoft 365
  • Azure/Entra ID
  • AWS

Location

  • United States
  • Canada

Work Type

  • Hybrid

Experience Level

  • 5-7 years

Salary/Compensations

  • $130,000 - $152,500

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • 401(k) retirement plan with employer match
  • Life insurance
  • Disability insurance
  • Paid time off (vacation, sick leave, holidays)
  • Paid parental leave
  • Wellness programs
  • Employee assistance resources
  • Commuter benefits
  • Robust skills development programs (100 hours annually)
  • Career mentoring and performance coaching
  • Leadership and collaboration opportunities
  • In-house immigration support

About the Company

  • Charles River Associates is a leading global consulting firm that provides economic, financial, and business management expertise to major law firms, corporations and governments around the world.
  • CRA advises clients on economic and financial matters pertaining to litigation and regulatory proceedings, and guides corporations through critical business strategy and performance-related issues.
  • Since 1965, clients have engaged CRA for its combination of industry experience and rigorous, fact-based analysis that provide clients with clear, implementable solutions to complex business concerns.

Equal Opportunity

  • Charles River Associates is an equal opportunity employer (EOE). All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, status as a protected veteran, or any other protected characteristic under applicable law.