Senior Associate, Threat Detection, Cyber Risk

hace 3 meses


Ciudad de México CDMX Kroll A tiempo completo

In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of _One team, One Kroll_, you’ll contribute to a supportive and collaborative work environment that empowers you to excel.

Kroll’s Cyber Risk team works on over 2,000 cases a year, including some of the most complex and highest profile matters in the world. With experts based around the world, supported by ground-breaking technology, we help protect our client’s data, people, operations and reputation with innovative assessments, investigations, and intelligence. We are the only company in the world with the expertise and resources to deliver global, end-to-end cyber risk management, supporting organizations through every step of their journey toward cyber resilience.

Clients count on us for quick and expert support in the event of and in preparation against a cyber incident; from incident response to risk assessments, and complex forensics to breach notification and ID theft remediation we help clients - of all sizes - respond with confidence.

This position is remote.

RESPONSIBILITIES:

- Perform ongoing threat hunting, analysis, containment, and remediation of threats identified through advanced endpoint detection and response (EDR), endpoint prevention (EPP), SIEM, and related security tools.
- Collect and review relevant forensic artifacts to identify root cause and understand nature of threats.
- Develop written threat reports associated with events.
- Assist in ongoing research, development, and testing of enhanced threat detection and response tools, techniques, and indicators.
- Support incident engagement teams with active intrusion detection and response tasks.
- Conduct threat research, forensic analysis, and basic malware analysis of threats.
- Assist with questions regarding threat detections, EDR tools, deployment, and maintenance.

REQUIREMENTS:

- Bachelor’s degree or higher in Computer Science, Cyber Security, Computer Engineering, or similar technical degree.
- Minimum 3 years’ experience in threat hunting, detection, and response or equivalent experience.
- Ability to respond rapidly, multi-task, and communicate effectively both verbally and in writing with team members and engagement managers.
- Highly motivated, tenacious, assertive problem solver with a desire to analyze root cause and reach effective conclusions to active intrusions and incidents on an ongoing basis both individually and as part of larger response teams.
- Solid understanding of Windows operating system fundamentals, architecture (File System, registry, processes, binaries, DLL’s, etc.) and administration concepts. Similar understanding of MacOS and/or Linux a plus.
- Prior experience actively using endpoint threat detection and response (EDR) products to investigate threats such as Sentinel One, Crowdstrike Falcon, VMWare Carbon Black, Windows Defender ATP, Cortex XDR, Trend Micro XDR, or others.
- Understanding of common threat actor techniques, malware behavior and persistence mechanisms.
- Working knowledge of various scripting languages and tools (PowerShell, Python, VB, Yara)
- Working knowledge of TCP/IP and related networking concepts.
- Prior experience using Splunk or other SIEM solutions, intrusion detection solutions, or related security products.
- Relevant cyber security certifications a plus.
- Excellent written and verbal communication skills
- Availability for occasional after-hours, weekends, and/or holiday work in response to active incidents.
- Kroll is committed to equal opportunity and diversity, and recruits people based on merit._

LI-CN1

LI-Remote



  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    Cyber Threat Detection Engineer Opportunity at Thomson ReutersWe are seeking a highly skilled Cyber Threat Detection Engineer to join our team. As a Cyber Threat Detection Engineer, you will play a critical role in developing and deploying security measures across the estate while advancing our threat detection program.About the Role:Threat Detection &...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    Thomson Reuters is looking to add a Cyber Threat Detection Engineer to our team.We are seeking an experienced professional to join our cyber defense team as a Jr Cyber Threat Detection Engineer. This role will be responsible for working with the Threat Intelligence and Incident Response teams to develop and deploy security measures across the estate while...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the Role :Deliver high-quality solutions across various cyber security functions, including threat detection, cyber threat intelligence, network security, incident response, insider threat prevention, and defensive platforms engineering.Drive continuous improvement in key cyber defense capabilities by streamlining technology acquisition and deployment,...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the OpportunityThomson Reuters is seeking a skilled Cyber Threat Detection Engineer to join our Cyber defense team.The successful candidate will work closely with Threat Intelligence and Incident Response teams to develop and deploy security measures across the estate, advancing our threat detection program.About YouYou have 2+ years of experience in...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    Cyber Threat Intelligence and Detection SpecialistThomson Reuters is seeking a highly skilled Cyber Threat Intelligence and Detection Specialist to join our Cyber defense team.The successful candidate will work with Threat Intelligence and Incident Response teams to develop and deploy security measures across the estate, advancing our threat detection...

  • Cyber Security Engineer

    hace 4 semanas


    Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    Job DescriptionAbout Us:Thomson Reuters is a leading provider of innovative solutions to the world's most respected businesses and organizations. With over 160 years of experience, we've established ourselves as a trusted partner in helping professionals like you succeed.About the Role:We are seeking an experienced Cyber Security Engineer to join our team!...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    Thomson Reuters is seeking a Cyber Threat Detection Specialist to join our Cyber defense team.We are looking for an individual with expertise in threat intelligence and incident response to develop and deploy security measures across the estate while advancing our threat detection program.About the Role:Threat Detection & Prevention: Act on threat...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the RoleDeliver high-quality solutions across cyber security functions, including threat detection, cyber threat intelligence, network security, incident response, insider threat prevention, defensive platforms and engineering, vulnerability management, and attack surface reduction.Drive continuous improvement in key cyber defense capabilities by...


  • Santiago de Querétaro, Querétaro de Arteaga, México Dana Incorporated A tiempo completo

    **Role Overview**:Dana Incorporated is seeking an experienced Senior Threat Detection & Response Engineer to lead our cybersecurity operations team. This pivotal role offers a unique opportunity for a seasoned professional passionate about Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR).As a key...


  • Ciudad de México, Ciudad de México Nearshore Cyber A tiempo completo

    This is an exceptional opportunity to leverage your skills in digital forensics and cybersecurity to investigate cybercrime incidents and recover critical digital evidence. As a Cyber Threat Investigation Expert, you will play a vital role in uncovering data related to security breaches, cyber-attacks, and other digital crimes.Our team at Nearshore Cyber...


  • Ciudad de México, Ciudad de México SOCRadar A tiempo completo

    About SOCRadarSOCRadar is a leading provider of innovative solutions for enterprise cybersecurity. With a strong focus on innovation, global expansion, and feature-rich multifunctionality, the company has established itself as a trusted partner for organizations seeking to protect their assets and operations from evolving cyber threats.Job SummaryWe are...


  • Ciudad de México, Ciudad de México Trustwave A tiempo completo

    Job OverviewThe Cyber Security Threat Investigator role is a critical part of our Global Threat Operations team at Trustwave Managed Security Services. This position requires a strong technical background and excellent communication skills to interact with customers and internal resources.About UsWe are a leading provider of managed security services,...


  • Ciudad de México, CDMX CyberInt A tiempo completo

    **Cyberint**, the impactful intelligence company, voted company of the year by Frost and Sullivan in 2023 is a market leader in **External Cyber Risk Management**. Cyberint helps organizations accelerate the detection, response and remediation of external cyber threats. We protect our customers from cyber threats beyond their perimeter, providing a **rich...


  • Ciudad de México, Ciudad de México SOCRadar A tiempo completo

    Protecting the Digital World with SOCRadarSOCRadar is a pioneering cybersecurity company that empowers enterprises to stay ahead of evolving cyber threats. With a focus on innovation, global expansion, and feature-rich multifunctionality, our platform enables proactive threat intelligence and automation-enabled visibility into surface, deep, and dark web.As...


  • méxico SOCRadar A tiempo completo

    Build a great career with Socradar! SOCRadar is well positioned for continued success with a focus on innovation, global expansion, and feature-rich multifunctionality. Enterprises around the world are increasingly selecting SOCRadar to get proactive by understanding their attack surface and gaining automation-enabled visibility into surface, deep, and dark...


  • Ciudad de México, Ciudad de México Lyft A tiempo completo

    At Lyft, our mission is to create a safe and reliable transportation experience for our users. As a Cybersecurity Specialist for Threat Detection and Incident Response, you will play a critical role in protecting our systems and data from cyber threats.Key Responsibilities:Swiftly Respond to Security Incidents: Respond promptly to security incidents by...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the RoleAs a Senior Cyber Security Platform Engineer, you will play a critical role in delivering high-quality solutions across various cyber security functions. Your responsibilities will include threat detection, cyber threat intelligence, network security, incident response, insider threat prevention, defensive platforms and engineering,...

  • Cybersecurity Expert

    hace 4 semanas


    Ciudad de México, Ciudad de México HSBC A tiempo completo

    Company Overview:HSBC is a global banking and financial services organization with operations in 64 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper.Salary:We offer an attractive salary of $140,000 per year, commensurate with experience.Job Description:The Cybersecurity Monitoring and Threat...


  • Ciudad de México, CDMX Citi A tiempo completo

    **Responsibilities**: - Supports the review of compliance and technology and cyber policies and procedures, technology and tools, and governance processes to provide credible challenge for minimizing losses from technology and cyber risks. - Assesses technology and cyber risks and evaluates actions to address the root causes that persistently lead to...


  • Ciudad de México, Ciudad de México Google Inc. A tiempo completo

    About the RoleThe Detection team at Google Inc. is responsible for developing and maintaining signals, tools, and infrastructure that help combat sophisticated attackers. As a member of this team, you will be conducting security analysis, threat hunting, malware, and indicator analysis to identify malicious activity on our networks.As the Chief Threat...