ForgeApply · Job listing
Incident Response Senior Consultant
Crowe
See all 143 open roles at Crowe →
Tailor your resume for this Crowe job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Crowe's site. Free trial, no card required.
About this role
Your Journey at Crowe Starts Here: At Crowe, you can build a meaningful and rewarding career. With real flexibility to balance work with life moments, you’re trusted to deliver results and make an impact. We embrace you for who you are, care for your well-being, and nurture your career. Everyone has equitable access to opportunities for career growth and leadership. Over our 80-year history, delivering excellent service through innovation has been a core part of our DNA across our audit, tax, and consulting groups. That’s why we continuously invest in innovative ideas, such as AI-enabled insights and technology-powered solutions, to enhance our services. Join us at Crowe and embark on a career where you can help shape the future of our industry.
Job Description: What It Means to Be a Consultant at Crowe Consulting is a dynamic business focused on solving problems for our clients and serving our core markets through innovative solutions. As technology and AI continue to reshape the consulting landscape, we are looking for individuals who are curious, adaptable, and eager to learn. At Crowe, consultants are expected to build both technical and transferable skills, think critically, and use technology to solve real business problems. In this role, you will continuously learn, collaborate across teams, and explore how tools, including emerging AI capabilities, can improve efficiency, insights, and client outcomes. As you grow, you’ll also begin to take ownership of client relationships, contribute to account strategy, and support the delivery of high-impact work.
Developing a sense of account leadership, including understanding client needs, ensuring delivery excellence, and building trusted partnerships, is part of what sets successful consultants apart.
Success in this role comes from a growth mindset, strong communication skills, advanced critical thinking, and the ability to navigate new challenges with confidence.
The Incident Response Senior Staff position at Crowe is a client-facing role designed for professionals in the field of cybersecurity, particularly within incident response (IR). This position requires a higher level of ownership and responsibility compared to entry-level roles, demanding creativity, critical thinking, and the ability to manage complex IR engagements. The successful candidate will engage directly with clients, leading calls and handling deliverables such as analysis and report drafting. This role is ideal for individuals who are passionate about cybersecurity and are eager to apply their expertise in a dynamic, market-facing environment, contributing to the protection and recovery of client systems under attack.
Responsibilities • Interact directly with clients during Incident Response (IR) engagements, providing expert guidance and support. • Coordinate with IR team members and external resources to execute and complete IR engagements effectively. • Investigate security incidents, including Business Email Compromise, Ransomware attacks, and Data breaches. • Assist with on-site incident response engagements, either as the sole on-site resource or in collaboration with other personnel. • Collect and analyze forensic evidence from impacted systems to support investigations. • Conduct threat hunting activities using EDR, SIEM, and application logs to identify and remediate threat actor entry and persistence methods. • Assist with the secure recovery of client environments, ensuring minimal disruption to business operations. • Prepare detailed reports covering the findings of investigations, providing actionable insights and recommendations. • Apply incident response knowledge to enhance ongoing cybersecurity practices and strategies.
Basic Qualifications • Commitment to and proven track record of continually expanding skillsets and knowledge. • Excellent problem-solving and analytical skills, with a strong attention to detail. • Strong communication and interpersonal skills to effectively interact with clients and team members. • Proven adaptability and a drive to learn and master new technologies. • Ability to maintain focus and composure in high-stress situations. • Willingness to travel 15% of the time or more, as required. • 4+ years of experience in Computer Science, Information Technology, or Cybersecurity, or a combination of a minimum of 2 years of experience with equivalent educational experience (such as a bachelor's or higher degree in a related field, or relevant certifications). • Experience utilizing SIEM or other log aggregation tools such as Splunk, Elastic, FortiSIEM, or Microsoft Sentinel. • Experience with EDR tools like SentinelOne, CrowdStrike, Carbon Black, or Microsoft Defender for Endpoint. • Strong understanding of networking, IT, and cybersecurity concepts. • Proficiency in scripting and command interpreter usage (e.g., Bash, PowerShell, Python). • Strong documentation skills.
Preferred Qualifications • Previous incident response experience. • Relevant certifications such as Red Hat Certified Systems Administrator (RHCSA), Linux Foundations Certified Systems Administrator (LFCS), GIAC Certified Incident Handler (GCIH), GIAC Certified Detection Analyst (GCDA), GIAC Public Cloud Security (GPCS), GIAC Cloud Forensics Responder (GCFR), CompTIA Cyber Security Analyst+ (CySA+), CompTIA Advanced Security Practitioner (CASP+), ISC2 Certified Information Systems Security Professional (CISSP), ISC2 Certified Cloud Security Professional (CCSP), EC-Council Certified Incident Handler (ECIH), EC-Council Certified Ethical Hacker (CEH), Cisco Certified Network Professional – Security (CCNP Security), Microsoft Certified Azure Security Engineer Associate (AZ-500), AWS Certified Security – Specialty, or Google Professional Cloud Security Engineer. • Experience writing detailed incident reports. • Experience with hypervisors (ESXI, Microsoft Hyper-V, etc.). • Active Directory administration and buildout experience. • Experience with backup software
Salary insight
The midpoint of this range ($128k) is right around the median disclosed salary for Chicago roles listed on ForgeApply ($128k across 2,187 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Crowe role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Incident Response Analyst — Leidos · Arlington, VA
- Incident Response Security Engineer — Clickhouse · Remote
- Incident Response Engineer — Accenturefederalservices · Arlington, VA
- Incident Response Engineer — Reteam · Remote
- Incident Response Engineer — Reteam · New york
- Incident Response Lead Specialist, Vice President — MUFG · Tempe, AZ
- Senior Analyst - Cyber Incident Respose — Brown Brothers Harriman (BBH) · Boston
- Senior Security Engineer, Incident Response — Airbnb · United States
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)