Incident Response Consultant

3 weeks ago


Chicago, United States Crowe Full time

Your Journey at Crowe Starts Here: At Crowe, you can build a meaningful and rewarding career. With real flexibility to balance work with life moments, you're trusted to deliver results and make an impact. We embrace you for who you are, care for your well-being, and nurture your career. Everyone has equitable access to opportunities for career growth and leadership. Over our 80-year history, delivering excellent service through innovation has been a core part of our DNA across our audit, tax, and consulting groups. That's why we continuously invest in innovative ideas, such as AI-enabled insights and technology-powered solutions, to enhance our services. Join us at Crowe and embark on a career where you can help shape the future of our industry. Job Description: The Incident Response role in Crowe's Consulting Practice, is a position designed for individuals eager to broaden their career in cybersecurity, specifically within the realm of incident response (IR). This role offers a unique opportunity to grow by engaging in the repeatable aspects of incident response, such as forensic collection, console/log review, and basic threat hunting. The successful candidate will work on an IR team to support and enhance our client's cybersecurity posture, ensuring the protection of client data and systems under fire. This position is ideal for those who are passionate about cybersecurity and are looking to develop their skills in a dynamic and supportive environment. As part of the Incident Response (IR) team, your responsibilities will include coordinating with team members to effectively execute and collaborate on incident response engagements. You will review and analyze security events and incidents to identify potential threats and vulnerabilities, as well as assist in the collection of digital forensic evidence to support ongoing investigations. Your role will involve conducting proactive threat hunting activities using Endpoint Detection and Response (EDR) and Security Information and Event Management (SIEM) tools. Additionally, you will be responsible for reviewing and generating detailed reports based on client-provided metrics and investigation findings. When necessary, you will also participate in on-site incident response engagements, working closely with other on-site personnel to address and mitigate security incidents in real-time. Requirements: Excellent problem-solving and analytical skills, with keen attention to detail. Strong communication and interpersonal skills to effectively collaborate with team members and clients. Proven adaptability and a strong drive to learn and master new technologies. Ability to maintain focus and composure in high-stress situations. Willingness to travel up to 5% of the time or more, as required. Commitment to continually expanding skillsets and knowledge, with a proven track record of doing so. Experience in troubleshooting technical issues or investigating security incidents. Understanding of networking, cybersecurity, and IT concepts. Preferred Qualifications: Experience responding to security incidents in a professional setting. Relevant certifications such as CompTIA Network+, Linux+, Security+, CySA+, GIAC Security Essentials, Microsoft Security Operations Analyst, or AWS Certified Security - Specialty. Experience working in a Security Operations Center (SOC) environment. Familiarity with major cloud platforms such as AWS, O365, and Google Workspace. Experience with EDR tools like SentinelOne, CrowdStrike, Carbon Black, or Microsoft Defender for Endpoint. Proficiency in utilizing SIEM or log aggregation tools such as Splunk, Elastic, or Microsoft Sentinel. Understanding of basic scripting and command interpreter usage (e.g., Bash, PowerShell, Python). Education: Currently pursuing a bachelor's or master's degree in: Computer Science Information Technology Management Information Systems Cybersecurity, or equivalent educational experience (such as a bachelor's degree in a related field, or relevant certifications). We expect the candidate to uphold Crowe's values of Care, Trust, Courage, and Stewardship. These values define who we are. We expect all of our people to act ethically and with integrity at all times. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. Crowe is not sponsoring for work authorization at this time. The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Crowe, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $62,000 - $100,000 per year. Our Benefits: Your exceptional people experience starts here. At Crowe, we know that great peopleare what makes a great firm. We care about our people and offer employees a comprehensive total rewards package. Learn more about what working at Crowe can mean for you How You Can Grow: We will nurture your talent in an inclusive culture that values diversity. You will have the chance to meet on a consistent basis with your Career Coach that will guide you in your career goals and aspirations. Learn more about where talent can prosper More about Crowe: Crowe (www.crowe.com) is one of the largest public accounting, consulting and technology firms in the United States. Crowe uses its deep industry expertise to provide audit services to public and private entities while also helping clients reach their goals with tax, advisory, risk and performance services. Crowe is recognized by many organizations as one of the country's best places to work. Crowe serves clients worldwide as an independent member of Crowe Global, one of the largest global accounting networks in the world. The network consists of more than 200 independent accounting and advisory services firms in more than 130 countries around the world. Crowe LLP provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Crowe LLP does not accept unsolicited candidates, referrals or resumes from any staffing agency, recruiting service, sourcing entity or any other third-party paid service at any time. Any referrals, resumes or candidates submitted to Crowe, or any employee or owner of Crowe without a pre-existing agreement signed by both parties covering the submission will be considered the property of Crowe, and free of charge. Crowe will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws. Please visit our webpage to see notices of the various state and local Ban-the-Box laws and Fair Chance Ordinances, where applicable.



  • Chicago, IL, United States eTeam Full time

    Job Description: The Incident Response Team (IRT) Specialist is responsible for identifying, analyzing, and responding to cybersecurity incidents in real time. This role involves investigating alerts, containing threats, mitigating risks, and supporting recovery efforts. The specialist works closely with security operations, IT teams, and external...


  • Chicago, IL, United States eTeam Full time

    Job Description: The Incident Response Team (IRT) Specialist is responsible for identifying, analyzing, and responding to cybersecurity incidents in real time. This role involves investigating alerts, containing threats, mitigating risks, and supporting recovery efforts. The specialist works closely with security operations, IT teams, and external...


  • Chicago, IL, United States eTeam Full time

    Job Description: The Incident Response Team (IRT) Specialist is responsible for identifying, analyzing, and responding to cybersecurity incidents in real time. This role involves investigating alerts, containing threats, mitigating risks, and supporting recovery efforts. The specialist works closely with security operations, IT teams, and external...


  • Chicago, IL, United States Charles River Associates Full time

    Consulting Associate/Cybersecurity & Incident Response Boston, MA, United States; Chicago, IL, United States; Dallas, TX, United States; Houston, TX, United States; Washington, DC, United States About Charles River Associates CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides...


  • Chicago, United States Digital Mint Full time

    A cybersecurity consulting firm is seeking a Cyber Incident Response Associate to assist in handling cyber extortion cases. The role includes gathering information from clients, maintaining documentation, and supporting senior negotiators. Ideal candidates have 1–2 years in client services and a strong attention to detail. This position allows for flexible...


  • Chicago, United States Mullen Coughlin LLC Full time

    As Mullen Coughlin continues to grow, we are always looking to connect with qualified, motivated professionals. Please review our current openings for the next step in a challenging and rewarding career. The Firm’s needs are updated often so if you don’t see the perfect fit, please submit your resume and cover letter to resumes@mullen.law. Thank you for...


  • Chicago, United States Digital Mint Full time

    HQ - Chicago | Position - Remote or HybridJob Summary & ObjectivesDigitalMint is seeking a detail-oriented and proactive Cyber Incident Response Associate to join our team specializing in threat actor negotiation support. In this role, you will be on the front lines of active cyber extortion cases—coordinating new incident intake, managing case...


  • Chicago, United States Apexcybersecurity Full time

    A cybersecurity firm in Chicago is seeking a motivated Jr. Cybersecurity Analyst to enhance, secure, and protect assets and data. This role involves providing incident response support, investigating security events, and collaborating with the team to resolve incidents. The ideal candidate will have a relevant degree and certifications in cybersecurity, with...

  • Senior Cyber Threat

    3 weeks ago


    Chicago, United States Capital One Full time

    A leading financial services firm in Chicago is seeking a Cybersecurity Manager to oversee a team of analysts. Responsibilities include leading incident response efforts, mentoring staff, and improving operational processes. The ideal candidate will have a robust background in cybersecurity with at least four years of experience in SOC and management. This...

  • Remote SOC Analyst

    2 weeks ago


    Chicago, United States Protera Full time

    A leading tech company is seeking an experienced SOC Analyst to maintain cybersecurity posture through monitoring and incident response. Candidates should have at least 4 years of SOC experience and familiarity with EDR and SIEM tools. This role offers remote work options and a dynamic work environment. The ideal candidate possesses strong skills in threat...