Charles River Associates

Consulting Associate/Recovery Services (Forensic Services practice)

Charles River Associates · Boston, MA, United States; Chicago, IL, United States; Dallas, Texas, United States; Houston, Texas, United States; New York, NY, United States; Oakland, CA, United States; Washington, DC, United States

Posted about a month ago · $100,000 - $126,500

or apply directly on Charles River Associates's site. We never take the application ourselves.

Is this posting real?

This role has been open
33 days
Charles River Associates's roles stay open a median of 45 days
Reposted
No
Salary listed
Yes
82% of Charles River Associates's roles list one
Ghost-job risk at Charles River Associates
high
60 stale, 3 reposted of 82 open
Hiring momentum
101 roles opened in the last 90 days
↑ up vs. the prior 90 days
Last confirmed on the employer's board
2026-09-17

Measured from postings appearing on and disappearing from Charles River Associates's own greenhouse board since 2026-08-03. Full hiring picture for Charles River Associates.

About this role

The Consulting Associate in CRA's Forensic Services practice is responsible for executing digital forensic collection and analysis, particularly in incident response and recovery engagements. This role involves leading technical recovery efforts in ransomware cases, analyzing business email compromise incidents, and developing automation tools while producing clear forensic reports and communicating with clients and legal counsel.

Our read on this posting4.2out of 5
benefits
4/5
freshness
3/5
career value
4/5
role clarity
5/5
pay transparency
5/5

Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of Charles River Associates as an employer.

What you need

  • 3-5 years of hands-on experience in incident response, digital forensics, or a closely related security engineering role
  • Demonstrated experience responding to ransomware, BEC, or intrusion matters in enterprise environments
  • Deep working knowledge of Active Directory and Entra ID, including attack paths and hardening controls
  • Proficiency with at least one enterprise EDR platform and its response tooling
  • Strong scripting ability in PowerShell; Python a plus
  • Excellent written communication; able to produce report-quality prose without heavy editing

Nice to have

  • Industry certifications such as GCFA, GCIH, GNFA, GCFE, EnCE, CISSP, or equivalent
  • Experience with virtualization forensics and backup platform recovery
  • Familiarity with Google Workspace forensics and administrative tooling
  • Experience working under legal privilege with outside counsel and cyber insurance carriers
  • Exposure to OT/ICS environments or regulated industries (healthcare, financial services)

What you get

  • 100 hours of training annually through formal and informal programs
  • Comprehensive total rewards program including a superior benefits package
  • Wellness programming to support physical, mental, emotional and financial well-being
  • In-house immigration support for foreign nationals and international business travelers
  • 401(k) retirement plan with employer match
  • Paid time off (vacation, sick leave, holidays)

Worth weighing

  • Incident response work involves surge periods, including nights and weekends during active engagements
  • Salary range provided is a good-faith estimate and may vary based on various factors

Summarised from Charles River Associates's posting. Read the full original.

Listed by Charles River Associates on their greenhouse job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.

More roles at Charles River Associates

All 82 open roles at Charles River Associates