Senior Associate, Threat Detection, Cyber Risk
hace 2 días
In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of _One team, One Kroll_, you’ll contribute to a supportive and collaborative work environment that empowers you to excel.Kroll’s Cyber Risk team works on over 2,000 cases a year, including some of the most complex and highest profile matters in the world. With experts based around the world, supported by ground-breaking technology, we help protect our client’s data, people, operations and reputation with innovative assessments, investigations, and intelligence. We are the only company in the world with the expertise and resources to deliver global, end-to-end cyber risk management, supporting organizations through every step of their journey toward cyber resilience.Clients count on us for quick and expert support in the event of and in preparation against a cyber incident; from incident response to risk assessments, and complex forensics to breach notification and ID theft remediation we help clients - of all sizes - respond with confidence.This position is remote.RESPONSIBILITIES:- Perform ongoing threat hunting, analysis, containment, and remediation of threats identified through advanced endpoint detection and response (EDR), endpoint prevention (EPP), SIEM, and related security tools.- Collect and review relevant forensic artifacts to identify root cause and understand nature of threats.- Develop written threat reports associated with events.- Assist in ongoing research, development, and testing of enhanced threat detection and response tools, techniques, and indicators.- Support incident engagement teams with active intrusion detection and response tasks.- Conduct threat research, forensic analysis, and basic malware analysis of threats.- Assist with questions regarding threat detections, EDR tools, deployment, and maintenance.REQUIREMENTS:- Bachelor’s degree or higher in Computer Science, Cyber Security, Computer Engineering, or similar technical degree.- Minimum 3 years’ experience in threat hunting, detection, and response or equivalent experience.- Ability to respond rapidly, multi-task, and communicate effectively both verbally and in writing with team members and engagement managers.- Highly motivated, tenacious, assertive problem solver with a desire to analyze root cause and reach effective conclusions to active intrusions and incidents on an ongoing basis both individually and as part of larger response teams.- Solid understanding of Windows operating system fundamentals, architecture (File System, registry, processes, binaries, DLL’s, etc.) and administration concepts. Similar understanding of MacOS and/or Linux a plus.- Prior experience actively using endpoint threat detection and response (EDR) products to investigate threats such as Sentinel One, Crowdstrike Falcon, VMWare Carbon Black, Windows Defender ATP, Cortex XDR, Trend Micro XDR, or others.- Understanding of common threat actor techniques, malware behavior and persistence mechanisms.- Working knowledge of various scripting languages and tools (PowerShell, Python, VB, Yara)- Working knowledge of TCP/IP and related networking concepts.- Prior experience using Splunk or other SIEM solutions, intrusion detection solutions, or related security products.- Relevant cyber security certifications a plus.- Excellent written and verbal communication skills- Availability for occasional after-hours, weekends, and/or holiday work in response to active incidents.- Kroll is committed to equal opportunity and diversity, and recruits people based on merit._LI-CN1LI-Remote
-
Sr Specialist Cyber Security
hace 1 semana
Ciudad de México Nestle A tiempo completoPosition Summary: Under the supervision and guidance of Product Group Manager, the Sr Specialist Cyber Security is responsible for establishing and maintaining security products, platforms and solutions designed to mitigate IS/IT risks across Nestlé Group to ensure that information assets are adequately protected. S/He is responsible for the...
-
Cyber Threat Intelligence Analyst
hace 6 minutos
Ciudad de México Siemens A tiempo completo**Looking for a chance to create a positive impact on our society?** Siemens Cybersecurity Defense is a global organization within Siemens consisting of regionally aligned teams across Germany, Portugal, Spain, United States, Mexico, and China. The mission of the organization is to proactively identify anomalies, respond and remediate Cybersecurity issues...
-
Senior Stellar Cyber Engineer
hace 16 horas
Ciudad de México Nearshore Cyber A tiempo completoSenior Stellar Cyber Engineer**Location**: Mexico (Remote/Work-from-Home)We are seeking an experienced and skilled Senior Stellar Cyber Engineer to join our team. As a Senior Stellar Cyber Engineer, you will be responsible for designing, implementing, and managing our cyber security infrastructure. This is a senior-level role for an individual with 4 to 7...
-
Ciudad de México Thomson Reuters A tiempo completoWe are looking for a Senior Manager, Cyber and Information Security Risk to join us. In this role you will lead delivery role for complex security functions reducing risk, improving defensive capabilities, and mitigating cyber threats to both Thomson Reuters and its customers. **About the Role**: As a Senior Manager, Cyber and Information Security Risk,...
-
Ciudad de México Thomson Reuters A tiempo completoWe are looking for a Senior Manager, Cyber and Information Security Risk to join us. In this role you will lead delivery role for complex security functions reducing risk, improving defensive capabilities, and mitigating cyber threats to both Thomson Reuters and its customers. **About the Role**: As a Senior Manager, Cyber and Information Security Risk,...
-
Cyber Threat Analyst
hace 5 días
Ciudad de México, Ciudad de México Level Blue A tiempo completoAbout LevelBlue (including Trustwave): LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence. As the world's most analyst-recognized and largest pure-play managed security services provider, LevelBlue elevates client outcomes that matter: stronger defense, faster response, and sustained...
-
Offensive Security Consultant
hace 2 semanas
Ciudad de México Echelon Risk + Cyber A tiempo completo**_About us: _**At Echelon Risk + Cyber, we believe in defending basic human rights to security and privacy. We seek a highly skilled and experienced **Senior Offensive Security Consultant** to join our team. In this role, you will lead and execute client engagements that range from penetration testing to advanced adversarial emulation exercises (red teaming...
-
Technology & Cyber Risk: Senior Analyst
hace 2 semanas
Ciudad de México, CDMX Citi A tiempo completo**Responsibilities**: - Supports the review of compliance and technology and cyber policies and procedures, technology and tools, and governance processes to provide credible challenge for minimizing losses from technology and cyber risks. - Assesses technology and cyber risks and evaluates actions to address the root causes that persistently lead to...
-
Offensive Security Associate
hace 2 semanas
Ciudad de México Echelon Risk + Cyber A tiempo completo**_About us: _**At Echelon Risk + Cyber, we believe in defending basic human rights to security and privacy. We are seeking an **Offensive Security Associate**to join our dynamic team at Echelon Risk + Cyber, a leading cybersecurity consulting firm. Our next team member will be ready to roll up their sleeves and identify opportunities for our clients and for...
-
Intelligence Analyst Lead
hace 4 semanas
Ciudad de México Citi A tiempo completoThe Citi Cyber Intelligence Center (CIC) is part of the Global Information Security organization and is responsible for analyzing cyber threat information designed to increase Citi's cyber threat awareness and protection levels. By providing awareness, indications, warnings, and operational readiness, the CIC protects the Citi brand, global business...