Associate Principal, Response Operations, Cyber Risk

Kroll

Manila

On-site

PHP 1,100,000 - 1,300,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Kroll is seeking a skilled security professional in Manila to join our Responder monitoring and response team as an Associate Principal. You will perform threat hunting, investigation, and rapid response using leading EDR/SIEM tools and collaborate with global teams to protect client data and operations.

Ideal candidates have 5+ years in threat hunting and incident response, with strong Windows/Linux fundamentals, scripting skills, and relevant certifications.

Qualifications

  • Bachelor’s degree or higher in Computer Science, Cyber Security, Computer Engineering, or similar technical degree.
  • Minimum 5 years’ experience in threat hunting, detection, and response or equivalent experience.
  • Ability to respond rapidly, multi-task, and communicate effectively both verbally and in writing with customers, team members, and engagement managers.
  • Highly motivated, tenacious, assertive problem solver with a desire to analyze root cause and reach effective conclusions to active intrusions and incidents on an ongoing basis both individually and as part of larger response teams.
  • Solid understanding of Windows operating system fundamentals, architecture (File System, registry, processes, binaries, DLL’s, etc.) and administration concepts. Similar understanding of MacOS and/or Linux a plus.
  • Prior experience actively using endpoint threat detection and response (EDR) products to investigate threats such as SentinelOne, Crowdstrike Falcon, VMWare Carbon Black, Microsoft Defender for Endpoint, Cortex XDR, Trend Micro XDR, or others.
  • Understanding of common threat actor techniques, malware behavior and persistence mechanisms.
  • Working knowledge of various scripting languages and tools (PowerShell, Python, VB, Yara)
  • Working knowledge of TCP/IP and related networking concepts.
  • Prior experience using Splunk or other SIEM solutions, intrusion detection solutions, or related security products.
  • Relevant cyber security certifications including CISSP, GCIA, GCIH, GCFA, GMON, or GREM a plus.
  • Excellent written and verbal communication skills
  • Availability for occasional after-hours, weekends, and/or holiday work in response to active incidents.

Responsibilities

  • Perform ongoing threat hunting, analysis, containment, and remediation of threats identified through advanced endpoint detection and response (EDR), endpoint prevention (EPP), SIEM, and related security tools.
  • Collect and review relevant forensic artifacts to identify root cause and understand nature of threats.
  • Develop and communicate written and verbal threat reports associated with events to customers.
  • Assist in ongoing research, development, and testing of enhanced threat detection and response tools, techniques, and indicators.
  • Support incident engagement teams with active intrusion detection and response tasks.
  • Conduct threat research, forensic analysis, and basic malware analysis of threats.
  • Actively participate in related client meetings and teleconferences.
  • Assist clients with questions regarding threat detections, EDR tools, deployment, and maintenance.

Skills

Threat hunting
Incident response
Threat analytics
Threat reporting
Client communication
Team collaboration
Problem solving
Scripting (PowerShell, Python)
Networking concepts
Windows fundamentals
Linux/macOS familiarity

Education

Bachelor’s degree or higher in Computer Science, Cyber Security, Computer Engineering, or similar technical degree

Tools

SentinelOne
CrowdStrike Falcon
VMware Carbon Black
Microsoft Defender for Endpoint
Cortex XDR
Trend Micro XDR
Splunk
SIEM

Job description

In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of One team, One Kroll, you’ll contribute to a supportive and collaborative work environment that empowers you to excel.

Kroll’s Cyber Risk team works on over 2,000 cases a year, including some of the most complex and highest profile matters in the world. With experts based around the world, supported by ground-breaking technology, we help protect our client’s data, people, operations and reputation with innovative assessments, investigations, and intelligence. We are the only company in the world with the expertise and resources to deliver global, end-to-end cyber risk management, supporting organizations through every step of their journey toward cyber resilience.

Clients count on us for quick and expert support in the event of and in preparation against a cyber incident; from incident response to risk assessments, and complex forensics to breach notification and ID theft remediation we help clients – of all sizes – respond with confidence.

Day To Day RESPONSIBILITIES

We are looking for bright, motivated, and inquisitive minds to join our Kroll Responder monitoring and response team who are experienced in and passionate about modern cyber threat hunting and active response. Our Associate Principals use leading endpoint detection and response tools to rapidly identify, investigate, and respond to threats and threat actors impacting systems and networks around the globe every day.

  • Perform ongoing threat hunting, analysis, containment, and remediation of threats identified through advanced endpoint detection and response (EDR), endpoint prevention (EPP), SIEM, and related security tools.
  • Collect and review relevant forensic artifacts to identify root cause and understand nature of threats.
  • Develop and communicate written and verbal threat reports associated with events to customers.
  • Assist in ongoing research, development, and testing of enhanced threat detection and response tools, techniques, and indicators.
  • Support incident engagement teams with active intrusion detection and response tasks.
  • Conduct threat research, forensic analysis, and basic malware analysis of threats.
  • Actively participate in related client meetings and teleconferences.
  • Assist clients with questions regarding threat detections, EDR tools, deployment, and maintenance.
Essential Traits
  • Bachelor’s degree or higher in Computer Science, Cyber Security, Computer Engineering, or similar technical degree.
  • Minimum 5 years’ experience in threat hunting, detection, and response or equivalent experience.
  • Ability to respond rapidly, multi-task, and communicate effectively both verbally and in writing with customers, team members, and engagement managers.
  • Highly motivated, tenacious, assertive problem solver with a desire to analyze root cause and reach effective conclusions to active intrusions and incidents on an ongoing basis both individually and as part of larger response teams.
  • Solid understanding of Windows operating system fundamentals, architecture (File System, registry, processes, binaries, DLL’s, etc.) and administration concepts. Similar understanding of MacOS and/or Linux a plus.
  • Prior experience actively using endpoint threat detection and response (EDR) products to investigate threats such as SentinelOne, Crowdstrike Falcon, VMWare Carbon Black, Microsoft Defender for Endpoint, Cortex XDR, Trend Micro XDR, or others.
  • Understanding of common threat actor techniques, malware behavior and persistence mechanisms.
  • Working knowledge of various scripting languages and tools (PowerShell, Python, VB, Yara)
  • Working knowledge of TCP/IP and related networking concepts.
  • Prior experience using Splunk or other SIEM solutions, intrusion detection solutions, or related security products.
  • Relevant cyber security certifications including CISSP, GCIA, GCIH, GCFA, GMON, or GREM a plus.
  • Excellent written and verbal communication skills
  • Availability for occasional after-hours, weekends, and/or holiday work in response to active incidents.

Kroll is committed to creating an inclusive work environment. We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate, Cyber Risk
Associate, Cyber Risk

Kroll • Manila

On-site
PHP 240,000 - 360,000
Security Analyst, InfoSec
Security Analyst, InfoSec

Kroll • Manila

On-site
Senior Associate, Security Engineer
Senior Associate, Security Engineer

Kroll Global Solutions Inc. • Manila

On-site
PHP 700,000 - 1,100,000
Senior Associate, Security Engineer
Senior Associate, Security Engineer

Kroll • Manila, Hinoba-an

On-site
PHP 1,100,000 - 1,700,000
Associate Principal, Cyber Threat Hunting & Response
Associate Principal, Cyber Threat Hunting & Response

Kroll • Manila

On-site
PHP 1,100,000 - 1,300,000
Client Associate, Breach Notification
Client Associate, Breach Notification

Kroll • Manila

Hybrid
PHP 60,000 - 80,000
Consulting_Cyber Detection & Response IRR Senior
Consulting_Cyber Detection & Response IRR Senior

EY • Taguig

On-site
PHP 900,000 - 1,200,000
Health and wellness packages
Opportunities for continuous learning
Access to cutting-edge technologies
Consulting_Cyber Detection And Response IRR Senior
Consulting_Cyber Detection And Response IRR Senior

EY • Philippines

On-site
PHP 800,000 - 1,200,000
Flexible environment
Professional development
Premium benefits
Senior Data Engineer
Senior Data Engineer

Kroll • Manila

On-site
PHP 1,000,000 - 1,400,000
Cybersecurity Operations Analyst
Cybersecurity Operations Analyst

UL Solutions • Makati

On-site
PHP 600,000 - 900,000