The ideal candidate demonstrates a strong advisory mindset, the ability to independently manage client conversations, and the capability to connect multiple cybersecurity domains-including identity and access management, endpoint security, vulnerability management, backup and recovery, email security, and asset management-into a cohesive and defensible security program assessment. The role will also work closely with CRA's incident response team to identify recurring risk themes and control gaps from active and recently closed matters, and help translate those observations into follow-on proactive engagements including gap assessments, tabletop exercises, resilience reviews, and broader security uplift efforts.