About the Role
CRA’s Forensic Services practice supports companies’ commitment to integrity by assisting them and their counsel in independently responding to allegations of fraud, waste, abuse, misconduct, and non-compliance. We are noted for deploying cross-trained teams of forensic professionals to assist our clients in gaining deeper insights and greater value more quickly. We provide accounting and forensic services as well as cybercrime investigation services. CRA is seeking a Cybersecurity Consultant (Assessments / Due Diligence / Advisory) to support client engagements focused on evaluating and managing cybersecurity risk. In this role, you will lead and participate in client-facing assessments, including interviews, workshops, and executive readouts, while operating with a high degree of independence and confidence.
Responsibilities
- Translate client discussions into clearly defined engagement scopes and Statements of Work (SOWs), aligning deliverables with frameworks such as the NIST CSF and transaction-specific objectives.
- Assess cybersecurity posture in transaction and investment contexts, distinguish material risks from broader program maturity gaps, and tailor findings to the needs of private equity, legal, and executive stakeholders.
- Execute cyber due diligence and proactive security assessments through documentation review, stakeholder interviews, and control evaluation.
- Support incident readiness reviews, tabletop exercises, and broader cyber resilience assessments to help clients evaluate preparedness, decision-making, and recovery capabilities before or after a cyber event.
- Work closely with CRA’s incident response team to identify recurring risk themes and control gaps from active and recently closed matters, and help translate those observations into follow-on proactive engagements including gap assessments, tabletop exercises, resilience reviews, and broader security uplift efforts.
- Produce high-quality, client-ready reports that include prioritized findings, risk-based recommendations, and executive-level summaries.
- Support senior team members in proposal development and business development efforts, while bridging technical cybersecurity findings into clear business risk narratives for legal, private equity, and executive audiences.
- Contribute to the development of repeatable assessment methodologies, templates, and client-facing deliverables across CRA’s proactive cybersecurity service offerings.
Requirements
- Approximately 5–7 years of experience in cybersecurity consulting, advisory, or due diligence
- Experience supporting cyber resilience assessments, incident readiness reviews, tabletop exercises, or related preparedness-focused engagements is a plus.
- Experience collaborating with incident response, forensic, or crisis management teams to translate post-incident observations into proactive assessment, readiness, or remediation-focused engagements is a plus.
- Comfortable leading discussions with CIOs, IT Directors, and legal stakeholders
- Strong ability to guide conversations, ask structured questions, and manage meetings effectively
- Excellent executive communication skills with clear, concise, and unambiguous delivery
- Experience drafting or contributing to Statements of Work (SOWs), engagement letters, and proposals
- Ability to translate loosely defined client needs into structured deliverables and timelines
- Strong commercial awareness, including understanding scope boundaries and identifying opportunities to expand engagements
- Ability to tailor scopes and findings to transaction, diligence, or investment-focused objectives, including identifying issues that are likely to be material to legal, private equity, or executive decision-makers.
- Impeccable written communication skills, including grammar, structure, and formatting
- Ability to produce logically consistent, defensible findings and recommendations
- Experience delivering polished, client-ready cybersecurity risk reports
- Ability to prioritize findings based on business impact, articulate critical versus lower-priority issues, and develop executive-ready narratives that support practical decision-making.
- NIST Cybersecurity Framework (primary)
- Supporting frameworks such as CIS Benchmarks, ISO 27001, SOC 2 Type II, HIPAA, and HITRUST
- Strong working knowledge of ability to map controls, identify gaps, and translate findings into business risk and impact
- Ability to evaluate how controls operate together across governance, identity, endpoint, cloud, recovery, and monitoring layers as part of a broader security program or resilience assessment.
- Identity & Access Management (e.g., Active Directory, Entra ID)
- Endpoint security (e.g., EDR/MDR solutions such as CrowdStrike)
- Vulnerability management tools (e.g., Tenable, Qualys)
- Backup and recovery strategies (RTO/RPO, immutability)
- Email security (phishing protection, DMARC, MFA)
- Asset inventory, device management, and patch lifecycle practices
- Comfort reviewing supporting documentation such as security policies and standards, architecture diagrams, control evidence, recovery procedures, and technical configurations in order to assess design and operating effectiveness.
- Broad understanding of core cybersecurity domains
- Ability to connect these domains into a comprehensive security program narrative
- Exposure to tools such as CrowdStrike, Tanium, Microsoft 365, Azure/Entra ID, and AWS.
- Ability to evaluate and interpret tooling deployment, configuration, and coverage in an advisory context rather than operate as a dedicated implementation engineer.
- Strong organizational and time management skills, with the ability to manage multiple workstreams simultaneously
- High level of ownership, attention to detail, and ability to deliver work independently with minimal oversight
- Ability to help develop reusable assessment content, templates, and client-ready materials that support scalable proactive service delivery across multiple engagement types.
- Resume – please include current address, personal email and telephone number
Skills
- Cybersecurity consulting
- Advisory
- Due diligence
- Cyber resilience assessments
- Incident readiness reviews
- Tabletop exercises
- Forensic teams
- Crisis management teams
- Client-facing assessments
- Executive readouts
- NIST CSF
- Private equity
- Legal
- Executive stakeholders
- Incident response
- Proposal development
- Business development
- Identity and access management
- Endpoint security
- Vulnerability management
- Backup and recovery
- Email security
- Asset management
- Security program assessment
- Business risk narratives
- CIS Benchmarks
- ISO 27001
- SOC 2 Type II
- HIPAA
- HITRUST
- Active Directory
- Entra ID
- CrowdStrike
- Tenable
- Qualys
- RTO/RPO
- MFA
- DMARC
- Security policies
- Architecture diagrams
- Control evidence
- Recovery procedures
- Technical configurations
- Governance
- Cloud
- Monitoring
- Tanium
- Microsoft 365
- Azure
- AWS
- CISSP
- CISM
- CISA
- PMP
Location
- Canada
Work Type
- Hybrid
Experience Level
- 5-7 years
Salary/Compensations
- CAD$140,000 – $190,000
Benefits
- Robust skills development programs (100 hours of training annually)
- Research and analysis skill building
- Technical training
- Presentation skills
- Internal seminars
- Career mentoring and performance coaching
- Leadership and collaboration opportunities
- Comprehensive total rewards program
- Superior benefits package
- Wellness programming (physical, mental, emotional, and financial well-being)
- In-house immigration support for foreign nationals and international business travelers
- Extended medical, dental, and vision insurance
- ERP with employer contribution
- TFSP
- RESP
- Life and disability insurance
- Paid time off (vacation, sick leave, holidays)
- Paid parental leave
- Wellness programs and employee assistance resources
- Commuter benefits
About the Company
- CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strategy and operational issues to become more profitable, and advises governments on the economic impact of policies and regulations.
- Our two main services – economic and management consulting – are delivered by practice groups that focus on specific areas of expertise or industries.
Equal Opportunity
- Charles River Associates is an equal opportunity employer (EOE). All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, status as a protected veteran, or any other protected characteristic under applicable law.
