Our professionals balance analytical skills, deep market insight and independence to deliver solid, defensible analysis and practical advice to our clients. As an organization, we think globally. We create transparency in an opaque world, and we encourage our people to do the same. That means when you take your place on our team, you’ll discover a supportive and collaborative work environment that empowers you to excel. If you’re ready to share your perspective with the world, then you can make a real impact here. This is the Kroll’s difference.
Kroll’s Security Operation’s Center helps firm manage cybersecurity risks at every stage of preparedness by identifying vulnerabilities and readiness through a comprehensive gap analysis and risk assessment; implementing best practices to avoid compromise; and recovering from cybersecurity attacks.
At Kroll, your work will help protect, restore and maximize value for our clients. Join us and together we’ll maximize the value of your career.
Security Operations Analyst
We are seeking candidates for a 24/7 security operations team. Candidate will be responsible for monitoring security events and alerts for potential malicious behaviors and evaluating the type and severity of security events by making use of packet analyses, and an in-depth understanding of exploits and vulnerabilities and providing incident response and escalation to the incident response team.
RESPONSIBILITIES:
Use SIEM technologies and other native tools to perform the monitoring of security events on a 24x7 basis.
Manage inbound requests via the ticketing system, as well as via telephone calls, and provide security notifications via three methods: logging incident tickets, sending emails, and placing telephone calls.
Perform analysis on logs produced by network devices utilized within the infrastructure such as firewalls, content filtering, syslog from various sources/devices, assorted Intrusion Detection capabilities, substantiating vulnerability scanner results, directory services, DHCP logs, Secure Email Gateway logs, and approved applications.
Use the SIEM to monitor security events and perform analysis, while integrating the results and information needed to proactively protect the enterprise.
Provide security events analysis and support to include identifying potential threat, anomalies, and infections, documenting findings, providing recommendations within the incident management system, performing triage of incoming security events, performing preliminary and secondary analysis of those events, and validating the events.
Provide cybersecurity root-cause analysis in support of any tickets for which it fails to meet the Acceptable Quality Levels. This root-cause analysis will include documenting recommendations for corrective action.
REQUIREMENTS:
Bachelor’s degree or equivalent in Computer Science, Systems Engineering, Cybersecurity, Information Technology, or related area.
Minimum 4 years of monitoring experience in Cyber Security Operations Center.
Excellent technical experience and expertise in troubleshooting Microsoft products and Operating system (desirable – knowledge of MAC OS & Linux).
Understanding of basic network services, TCP/IP, IP Routing, attacks, exploits and vulnerabilities.
Experience with VPN, SSL, other encryption methodology / technology a plus.
Working knowledge of policies, procedures, and protocols of Security Operations Center.
Experience using numerous security tools and technologies to include some of the following technologies: SIEM, IDS/IPS, Web application firewalls, Antivirus, Proxy and Url filtering, DLP, Vulnerability scanner.
DESIRED CERTIFICATIONS:
CompTIA Security+
Certified Ethical Hacker (CEH)
GIAC Certified Incident Handler (GCIH)
Certified SOC Analyst (CSA)
Microsoft Certified: Security Operations Analyst Associate
In order to be considered for a position at Kroll, you must formally apply via careers.kroll.com
Kroll is committed to equal opportunity and diversity, and recruits people based on merit.
#LI-TL1
Skills Required
- Bachelor's degree or equivalent in Computer Science, Systems Engineering, Cybersecurity, IT, or related area.
- Minimum 4 years of monitoring experience in a Cyber Security Operations Center.
- Experience monitoring security events using SIEM and performing log analysis.
- Experience with IDS/IPS, web application firewalls, antivirus, proxy/URL filtering, DLP, and vulnerability scanners.
- Ability to perform packet analysis and triage security events; incident response and escalation experience.
- Working knowledge of SOC policies, procedures, and protocols.
- Excellent troubleshooting experience with Microsoft Windows and operating systems.
- Experience managing inbound requests via ticketing systems and providing notifications via tickets, email, and phone.
- Understanding of basic network services, TCP/IP, IP routing, attacks, exploits and vulnerabilities.
- Knowledge of VPN, SSL and encryption technologies.
- Knowledge of macOS and Linux.
- Desired certifications: CompTIA Security+, CEH, GCIH, CSA, Microsoft Certified: Security Operations Analyst Associate.
Kroll Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kroll and has not been reviewed or approved by Kroll.
-
Healthcare Strength — Medical, dental, and vision coverage with HSA/FSA options are part of the U.S. package, alongside life and AD&D. Breadth across core health benefits is positioned as competitive for a large advisory firm.
-
Retirement Support — A 401(k) plan with company match is a core element of the package. Retirement support is consistently highlighted as competitive within total rewards.
-
Leave & Time Off Breadth — Paid holidays, sick leave, and PTO are included, with generous time off and parental/family leave for U.S. roles. Some roles also offer hybrid/WFH flexibility that complements time-off usability.
Kroll Insights
What We Do
Kroll is the world’s premier provider of services and digital products related to valuation, governance, risk and transparency. We work with clients across diverse sectors in the areas of valuation, expert services, investigations, cyber security, corporate finance, restructuring, legal and business solutions, data analytics and regulatory compliance. Our firm has nearly 5,000 professionals in 30 countries and territories around the world. For more information, visit www.kroll.com.









