Associate Principal, Cyber Threat Hunting & Response

Kroll

Manila

On-site

PHP 1,100,000 - 1,300,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Kroll is seeking a skilled security professional in Manila to join our Responder monitoring and response team as an Associate Principal. You will perform threat hunting, investigation, and rapid response using leading EDR/SIEM tools and collaborate with global teams to protect client data and operations.

Ideal candidates have 5+ years in threat hunting and incident response, with strong Windows/Linux fundamentals, scripting skills, and relevant certifications.

Qualifications

  • Bachelor’s degree or higher in Computer Science, Cyber Security, Computer Engineering, or similar technical degree.
  • Minimum 5 years’ experience in threat hunting, detection, and response or equivalent experience.
  • Ability to respond rapidly, multi-task, and communicate effectively both verbally and in writing with customers, team members, and engagement managers.
  • Highly motivated, tenacious, assertive problem solver with a desire to analyze root cause and reach effective conclusions to active intrusions and incidents on an ongoing basis both individually and as part of larger response teams.
  • Solid understanding of Windows operating system fundamentals, architecture (File System, registry, processes, binaries, DLL’s, etc.) and administration concepts. Similar understanding of MacOS and/or Linux a plus.
  • Prior experience actively using endpoint threat detection and response (EDR) products to investigate threats such as SentinelOne, Crowdstrike Falcon, VMWare Carbon Black, Microsoft Defender for Endpoint, Cortex XDR, Trend Micro XDR, or others.
  • Understanding of common threat actor techniques, malware behavior and persistence mechanisms.
  • Working knowledge of various scripting languages and tools (PowerShell, Python, VB, Yara)
  • Working knowledge of TCP/IP and related networking concepts.
  • Prior experience using Splunk or other SIEM solutions, intrusion detection solutions, or related security products.
  • Relevant cyber security certifications including CISSP, GCIA, GCIH, GCFA, GMON, or GREM a plus.
  • Excellent written and verbal communication skills
  • Availability for occasional after-hours, weekends, and/or holiday work in response to active incidents.

Responsibilities

  • Perform ongoing threat hunting, analysis, containment, and remediation of threats identified through advanced endpoint detection and response (EDR), endpoint prevention (EPP), SIEM, and related security tools.
  • Collect and review relevant forensic artifacts to identify root cause and understand nature of threats.
  • Develop and communicate written and verbal threat reports associated with events to customers.
  • Assist in ongoing research, development, and testing of enhanced threat detection and response tools, techniques, and indicators.
  • Support incident engagement teams with active intrusion detection and response tasks.
  • Conduct threat research, forensic analysis, and basic malware analysis of threats.
  • Actively participate in related client meetings and teleconferences.
  • Assist clients with questions regarding threat detections, EDR tools, deployment, and maintenance.

Skills

Threat hunting
Incident response
Threat analytics
Threat reporting
Client communication
Team collaboration
Problem solving
Scripting (PowerShell, Python)
Networking concepts
Windows fundamentals
Linux/macOS familiarity

Education

Bachelor’s degree or higher in Computer Science, Cyber Security, Computer Engineering, or similar technical degree

Tools

SentinelOne
CrowdStrike Falcon
VMware Carbon Black
Microsoft Defender for Endpoint
Cortex XDR
Trend Micro XDR
Splunk
SIEM

Job description

Kroll is seeking a skilled security professional in Manila to join our Responder monitoring and response team as an Associate Principal. You will perform threat hunting, investigation, and rapid response using leading EDR/SIEM tools and collaborate with global teams to protect client data and operations.

Ideal candidates have 5+ years in threat hunting and incident response, with strong Windows/Linux fundamentals, scripting skills, and relevant certifications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Principal, Response Operations, Cyber Risk
Associate Principal, Response Operations, Cyber Risk

Kroll • Manila

On-site
PHP 1,100,000 - 1,300,000
Threat Hunter & Incident Responder - Cybersecurity Pro
Threat Hunter & Incident Responder - Cybersecurity Pro

First Focus AU • Pasig

Hybrid
PHP 900,000 - 1,300,000
Hybrid work arrangements
HMO day 1
Dental cover
+2
Client Associate, Breach Notification
Client Associate, Breach Notification

Kroll • Manila

Hybrid
PHP 60,000 - 80,000
Threat Hunter & Incident Response Specialist — Hybrid
Threat Hunter & Incident Response Specialist — Hybrid

First Focus • Hinoba-an

Hybrid
PHP 600,000 - 1,000,000
Hybrid working arrangements
HMO day 1 including one dependent
Dental cover
+8
SOC Analyst: Threat Hunting & Incident Response
SOC Analyst: Threat Hunting & Incident Response

Continental • Manila

On-site
PHP 600,000 - 900,000
Breach Notification Client Coordinator (Hybrid)
Breach Notification Client Coordinator (Hybrid)

Kroll • Manila

Hybrid
PHP 60,000 - 80,000
Senior Cyber Threat Detection & Incident Response Lead
Senior Cyber Threat Detection & Incident Response Lead

PwC • Manila

On-site
PHP 1,200,000 - 1,800,000
Threat Hunter & Incident Responder - Security MSP
Threat Hunter & Incident Responder - Security MSP

First Focus AU • Muntinlupa

Hybrid
PHP 500,000 - 900,000
Hybrid working arrangements
HMO from Day 1 (incl. one dependent)
Dental cover
+8
Threat Hunter & Incident Responder — MSP Security
Threat Hunter & Incident Responder — MSP Security

First Focus • Manila

Hybrid
PHP 700,000 - 1,000,000
Hybrid work arrangements
HMO + dental cover day 1
Counselling access via Uprise
+4
Security Operations Lead — Detection & Response
Security Operations Lead — Detection & Response

Thumbtack Philippines • Philippines

On-site
PHP 1,200,000 - 2,400,000