, Senior Associate, Cyber Risk
In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity-not just answers-in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of One team, One Kroll, you'll contribute to a supportive and collaborative work environment that empowers you to excel.
Kroll's Cyber Risk team works on over 2,000 cases a year, including some of the most complex and highest profile matters in the world. With experts based around the world, supported by ground-breaking technology, we help protect our client's data, people, operations and reputation with innovative assessments, investigations and intelligence. We are the only company in the world with the expertise and resources to deliver global, end-to-end cyber risk management, supporting organizations through every step of their journey toward cyber resilience.
Clients count on us for quick and expert support in the event of and in preparation against a cyber incident; from incident response to risk assessments, and complex forensics to breach notification and ID theft remediation we help clients - of all sizes - respond with confidence.
At Kroll, your work will help deliver clarity to our clients' most complex governance, risk, and transparency challenges. Apply now to join One team, One Kroll. Role
Working within our Security Operations Centre, the focus of this role is the implementation of security monitoring, detection and response technologies across Redscan/Kroll's client base. This involves developing, testing and deploying security content across EDR and SIEM technologies. Responsibilities
Working within our Security Operations Centre as a Detection Engineer, the focus of this role is the implementation of security monitoring, detection and response technologies across Kroll's client base. This involves developing, testing and deploying security content across EDR and SIEM technologies.
- Develop, test and tune detections for various EDR technologies.
- Develop, test and tune both detections and parsers for various SIEM technologies.
- Develop and maintain a detection database in Sigma.
- Be intelligence-led and develop detections to mitigate the latest threats.
- Work with Offensive Security to validate detections and identify gaps in coverage.
- Handle requests for new detections, determine the security value of those requests and clearly explain your decision to stakeholders.
- Be an SME on audit logging and recommend configurations to customers.
- Reduce false positives and improve the computational efficiency of existing content.
- Work with customers to build effective whitelists and blacklists.
- Understand and master data sources across a variety of categories including Windows, Linux, Active Directory, Privileged Access Management, Intrusion Detection/Prevention, Firewalls, Anti-Virus, Endpoint Detection & Response, Cloud Access Security Broking, Network Access Control, Application Control and Productivity Apps.
- Collaborate with key stakeholders across the SOC, Threat Intelligence, Offensive Security, Sales Engineering, Engineering, Project, Product and Sales Teams.
- Create scalable processes through automation.
- Document designs and processes.
Familiar with prevailing threats and how to mitigate them using EDR or SIEM.
- Understanding of Windows or Linux telemetry.
- Experience writing detections for EDR or SIEM technologies.
- Experience writing Regex.
- Familiarity with the Mitre ATT&CK framework.
- Understand security principles and practices.
- Proven capability to learn and deliver to a high standard within deadlines.
- Strong organisational skills and an ability to appropriately prioritise tasks.
- Ability to relay complex technical subject matter to non-technical stakeholders.
- Demonstrable analytical and technical aptitude with focus on identifying and alleviating the root cause of a problem.
- Proven ability to thrive and respond to frequent demands of multiple constituents, both internal and external, in a high demand, customer-centric environment.
- SANS/GIAC certifications preferred.
Kroll offers a flexible working, a great benefits package and excellent opportunities for career and personal development.
In order to be considered for a position at Kroll, you must formally apply via careers.kroll.com
Kroll is committed to equal opportunity and diversity, and recruits people based on merit