Associate/Cybersecurity & Incident Response (Forensic Services practice) at Charles River Associates | CA | Rezi

Associate/Cybersecurity & Incident Response (Forensic Services practice) at Charles River Associates

Associate/Cybersecurity & Incident Response (Forensic Services practice)

Charles River Associates · CA

3 weeks ago

Associate/Cybersecurity & Incident Response (Forensic Services practice)

Charles River Associates · CA

24 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

CRA is a leading global consulting firm providing independent economic and financial analysis, strategic guidance, and policy impact assessment. The Forensic Services practice supports companies' integrity by responding to allegations of fraud, waste, abuse, misconduct, and non-compliance through accounting, forensic, and cybercrime investigation services.

Responsibilities

  • Execute security and privacy investigations for clients in preparation for and response to data security matters, including breach detection, threat analysis, incident response, and malware analysis.
  • Provide expert digital forensic support for counsel and clients in support of data security incidents.
  • Assist in drafting forensic reports, affidavits, and testifying as an expert in digital forensics and incident response.
  • Engage in problem-solving and forensic analysis of digital information using standard evidence handling techniques and computer forensics tools.
  • Identify, research, and organize information to assess the appropriateness and sufficiency of available data for effective data access and analysis.
  • Develop familiarity with data inputs for analysis, including threat intelligence, logging data, and contextual clues.
  • Recognize relationships among multiple sources and types of information to facilitate effective data analysis.
  • Perform programming, model building, and database administration using Python, T-SQL, VBA, Excel, C#, among others.
  • Ensure reliability of analysis and risk management through implementing quality control measures and documentation.
  • Forensically acquire data and images from identified hosts, locate evidence of compromise, and determine its impact through disk, file, memory, and log analysis.
  • Identify artifact and evidence locations to answer critical questions, including execution, file access, data theft, anti-forensics, and detailed system usage by an adversary.
  • Detect and hunt unknown live, dormant, and custom malware across multiple hosts in an enterprise environment.
  • Create Indicators of Compromise (IOCs) from analysis to strengthen incident response and threat intelligence efforts.
  • Track adversary activity second-by-second on a host via in-depth timeline analysis.
  • Understand the evidence needed to determine the type of malware used in an attack, including rootkits, backdoors, and Trojan horses, and choose appropriate defenses and response tactics.
  • Identify lateral movement and pivots within client enterprises, showing how an adversary transitions between systems undetected.
  • Use physical memory analysis tools to determine an adversary's activities on a host and other pivot points across the network.
  • Examine traffic using common network protocols to identify patterns of activity or specific actions warranting further investigation.
  • Identify and track malware beaconing outbound to its command and control (C2) channel via memory forensics, registry analysis, and network connections.
  • Provide technical assessment/audit and guidance to clients on the adequacy of cyber security controls in accordance with frameworks such as NIST CSF 2.0, HIPAA, ISO 27001 and 27002, SOC2, NERC-CIP.
  • Participate in practice-building activities including recruiting and training.

Requirements

  • Majored in Computer Science, Digital Forensics, Information Security, and/or Information Systems.
  • Knowledge of cybersecurity concepts.
  • Research experience.
  • Quantitative ability.
  • Exceptional written and oral communication skills.
  • High level of initiative.
  • Ability to use data to solve client problems.
  • Ability to work collaboratively with a team.
  • Ability to effectively manage time and prioritize tasks.
  • Pride and ownership in work.
  • Strong understanding of computer operating systems, software, and hardware.
  • Ability to conduct detailed forensic investigations and analysis of computers, networks, mobile devices, and removable media.
  • Experience with conducting digital forensic analysis using commercial and open-source forensic tools, including file system forensics, memory analysis, and network analysis.
  • Experience with conducting static/dynamic malware analysis in a lab environment and threat hunting in a live environment.
  • Experience in collegiate computer security competitions.
  • Strong understanding of proper evidence handling procedures and chain of custody.
  • Experience with drafting technical and investigative reports and communicating technical findings.
  • Experience with utilizing automation tools and scripts to expedite analysis.
  • Understanding of incident handling procedures: preparation, identification, containment, eradication, and recovery to protect enterprise environments.
  • Understanding of common attack techniques used by an adversary on a victim network and leveraging those techniques to stop further adversary activity.
  • Digital forensics/incident response training and certifications, including SANS GIAC (GCFA, GCFE, GNFA, GIME), IACIS (CFCE or CIFR), Magnet MCFE, X-ways X-Pert or similar.

Skills

  • Cybersecurity concepts
  • Research
  • Quantitative analysis
  • Written communication
  • Oral communication
  • Initiative
  • Data analysis
  • Team collaboration
  • Time management
  • Task prioritization
  • Computer operating systems
  • Software
  • Hardware
  • Digital forensic investigations
  • Computer forensics
  • Network forensics
  • Mobile device forensics
  • Removable media forensics
  • Commercial forensic tools
  • Open-source forensic tools
  • File system forensics
  • Memory analysis
  • Network analysis
  • Static malware analysis
  • Dynamic malware analysis
  • Threat hunting
  • Evidence handling procedures
  • Chain of custody
  • Technical report writing
  • Investigative report writing
  • Automation tools
  • Scripting
  • Incident handling procedures
  • Attack techniques
  • SANS GIAC (GCFA, GCFE, GNFA, GIME)
  • IACIS (CFCE or CIFR)
  • Magnet MCFE
  • X-ways X-Pert
  • Python
  • T-SQL
  • VBA
  • Excel
  • C#

Location

  • Canada

Work Type

  • Hybrid

Experience Level

  • 2-4 years

Education Level

  • Bachelor's degree in Computer Science, Digital Forensics, Information Security, or Information Systems

Benefits

  • Superior benefits package
  • Wellness programming to support physical, mental, emotional and financial well-being
  • In-house immigration support for foreign nationals and international business travelers

About the Company

  • CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strategy and operational issues to become more profitable, and advises governments on the economic impact of policies and regulations.
  • CRA’s Forensic Services practice supports companies’ commitment to integrity by assisting them and their counsel in independently responding to allegations of fraud, waste, abuse, misconduct, and non-compliance.
  • We are noted for deploying cross-trained teams of forensic professionals to assist our clients in gaining deeper insights and greater value more quickly.
  • We provide accounting and forensic services as well as cybercrime investigation services.

Equal Opportunity

  • Charles River Associates is an equal opportunity employer (Human Rights Act/Employment Equity Act). All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, status as a protected veteran, or any other protected characteristic under applicable law.