Senior Manager, SIEM/ SOAR Engineer (CrowdStrike)

Kroll

Northern (KY)

Hybrid

USD 140,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Healthcare coverage
Generous PTO
401(k) with company match

Job summary

Kroll’s Cyber Data & Resilience practice is building a high-growth CrowdStrike MDR and Next Gen SIEM enablement delivery model. As a Senior Manager / Principal Consultant, you will lead a team of detection engineers and consultants deploying CrowdStrike Falcon and LogScale, and drive repeatable delivery and operational excellence for enterprise clients.

You will design repeatable delivery frameworks, mentor staff, partner with incident response and advisory teams, and translate business risk

Qualifications

  • 10+ years in cybersecurity delivery, operations, or consulting.
  • Proven leadership delivering CrowdStrike Falcon and LogScale projects.
  • Strong SIEM/SOAR knowledge and incident response experience.

Responsibilities

  • Lead end-to-end delivery of CrowdStrike MDR and Next Gen SIEM implementations for clients.
  • Define SOPs, playbooks, and delivery frameworks for scalable service delivery.
  • Mentor detection engineers and consultants on projects and best practices.
  • Oversee detection logic, rules, and SOC process optimization.
  • Collaborate with incident response and advisory teams to integrate detections.
  • Develop deployment templates and automation accelerators (Terraform, Ansible, PowerShell).
  • Interface with client executives to translate risk into detection and response strategies.
  • Track delivery metrics, SLAs, and client satisfaction to improve maturity and profitability.

Skills

CrowdStrike Falcon
CrowdStrike LogScale
Automation
Terraform
Ansible
PowerShell
Python
MDR Delivery
SOC Operations

Tools

Terraform
Ansible
PowerShell
Python

Job description

Cybersecurity

Cybersecurity | United States | 21014759

Share This

Kroll’s Cyber Data & Resilience practice is building a high-growth CrowdStrike Next Gen SIEM and MDR Enablement practice, and we are seeking a proven technical leader to help shape and scale delivery across detection, automation, and managed response services.

As a Senior Manager / Principal Consultant, you will oversee a team of detection engineers and client delivery professionals deploying and operationalizing CrowdStrike Falcon and LogScale. Your mission: to design repeatable delivery models, ensure operational excellence, and help clients accelerate their detection maturity through Kroll’s modern managed-services framework. This is a leadership and delivery role—ideal for someone who enjoys bridging technical execution, service development, and client outcomes.

Day-to-Day Responsibilities:
  • Lead end-to-end delivery of CrowdStrike MDR and Next Gen SIEM (LogScale) implementations for enterprise and mid-market clients.
  • Define standard operating procedures, playbooks, and delivery frameworks for repeatable, scalable service delivery.
  • Manage and mentor detection engineers and consultants delivering client projects across CrowdStrike Falcon modules.
  • Oversee detection logic development, correlation rules, and SOC process optimization.
  • Partner with Kroll’s incident response and advisory teams to integrate post-incident detection enhancements into ongoing MDR operations.
  • Develop and maintain CrowdStrike baseline configurations, deployment templates, and automation accelerators (Terraform, Ansible, PowerShell).
  • Interface directly with client executives and technical stakeholders to translate business risk into detection and response strategies.
  • Collaborate with technology alliances (CrowdStrike, Microsoft, etc.) on co-developed service offerings and go-to-market enablement.
  • Track delivery metrics, SLAs, and client satisfaction to continuously improve program maturity and profitability.
  • 7–10+ years of experience in cybersecurity delivery, operations, or consulting (preferably within MDR, SOC, or detection engineering programs).
  • Proven track record leading teams deploying CrowdStrike Falcon and CrowdStrike LogScale technologies.
  • Strong understanding of SIEM/SOAR operations, detection logic, and threat response workflows.
  • Experience designing or maturing MDR service models (process, metrics, automation, and reporting).
  • Proficiency in Terraform, PowerShell, or Python for automation and configuration management.
  • Deep familiarity with multi-tenant operations, Flight Control, and Azure Lighthouse environments.
  • Excellent communication and presentation skills—comfortable interfacing with client CISOs and technical teams alike.
Preferred Skills
  • Experience in security consulting or managed services leadership (Big 4, MSSP, or global cyber provider preferred).
  • CrowdStrike certifications (CCFA, CCFR, CCSA) or equivalent technical credentials.
  • Familiarity with Defender Suite integration and hybrid XDR architecture.
  • Knowledge of ROI modeling, efficiency metrics, and service-based automation frameworks.
  • Strong business acumen and the ability to link detection and response outcomes to client risk reduction and value realization.
  • Healthcare Coverage: Comprehensive medical, dental, and vision plans.
  • Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.
  • Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.
  • Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.
  • Retirement Plans: 401(k) plans with company matching.

Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.

About Kroll

Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting‑off technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll.

We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, SIEM/ SOAR Engineer (CrowdStrike)
Senior Manager, SIEM/ SOAR Engineer (CrowdStrike)

Kroll • United States

On-site
USD 150,000 - 200,000
Healthcare Coverage
Time Off and Leave Policies
Protective Insurances
+2
Manager, Cyber Engineered Defense (CrowdStrike Services)
Manager, Cyber Engineered Defense (CrowdStrike Services)

Kroll • Northern (KY)

Hybrid
USD 150,000 - 200,000
Healthcare Coverage
Generous PTO & Holidays
401(k) with company match
+1
Senior Manager, SIEM/MDR & SOAR Delivery Lead
Senior Manager, SIEM/MDR & SOAR Delivery Lead

Kroll • United States

On-site
USD 150,000 - 200,000
Healthcare Coverage
Time Off and Leave Policies
Protective Insurances
+2
Senior SIEM/MDR Delivery Lead
Senior SIEM/MDR Delivery Lead

Kroll • Northern (KY)

Hybrid
USD 140,000 - 230,000
Healthcare coverage
Generous PTO
401(k) with company match
Sr. Director, Engineering - Next-Gen SIEM (Hybrid)
Sr. Director, Engineering - Next-Gen SIEM (Hybrid)

CrowdStrike • Austin (TX)

Hybrid
USD 235,000 - 350,000
Market leading compensation & equity
Wellness programs
Generous vacation & holidays
+4
Associate Security Engineer (Remote)
Associate Security Engineer (Remote)

CrowdStrike • Town of Texas (WI)

On-site
USD 70,000 - 95,000
Market-leading compensation
Comprehensive wellness programs
Paid time off and holidays
Incident Response Senior Consultant (Remote)
Incident Response Senior Consultant (Remote)

CrowdStrike Holdings, Inc. • California (MO)

Hybrid
USD 95,000 - 140,000
Wellness programs
Vacation & holidays
Parental leave
+3
Incident Response Senior Consultant (Remote)
Incident Response Senior Consultant (Remote)

CrowdStrike Holdings, Inc. • Northern (KY)

Hybrid
USD 95,000 - 140,000
Health insurance
401k
Paid time off
+1
Manager, Platform Professional Resident Services (Remote)
Manager, Platform Professional Resident Services (Remote)

CrowdStrike • California (MO)

On-site
USD 140,000 - 195,000
Market compensation
Wellness programs
Paid time off
+3
CrowdStrike Next-Gen SIEM Resident Consultant (Remote)
CrowdStrike Next-Gen SIEM Resident Consultant (Remote)

CrowdStrike • Arizona

On-site
USD 85,000 - 120,000
Market-leading compensation
Wellness programs
Generous vacation and holidays
+5