Senior Associate, Incident Response
Location
Worldwide
Posted
36 days ago
Salary
$100K - $145K / year
Seniority
Senior
Job Description
Senior Associate, Incident Response
Kroll
Title: Senior Associate, Incident Response Location: United States Department: Cybersecurity remote Job Description: Description In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of One team, One Kroll, you’ll contribute to a supportive and collaborative work environment that empowers you to excel. At Kroll, your work will help deliver clarity to our clients’ most complex governance, risk, and transparency challenges. Apply now to join One team, One Kroll. Kroll’s elite security leaders deliver rapid responses for over 3,000 incidents per year and have the resources and expertise to support the entire incident lifecycle, including litigation demands. Day-to-day Responsibilities - Delivery of strong technical skills in support of cyber defense or incident response assignments. - Supports the Case Manager in the effective running of an assignment through to its closure, providing input to structuring projects, managing resources, presenting findings and providing commercially viable advice to the client. - Monitors quality of own work and that of the assignment team, and ensures value is delivered to the client. - Communicates regularly to senior members of the team, bringing case issues and findings to attention of appropriate personnel for resolution and decision making. - Develop and maintain key client relationships, ensuring Kroll’s high standards of service and integrity are adhered to at all times. - Support the development of junior staff by acting as mentor and ensuring Kroll’s high standards are met at all times. - Ensure Key Performance Indicators (consisting of utilization rates, business generation and personal objectives) are consistently achieved. - Identify own learning needs and opportunities, and continuously seek to improve personal performance. Essential Traits: - We are currently looking for individuals that hold the following skill and expertise: - Incident Response - Computer Forensics - Malware Reverse Engineering - Network Security - Computer Security Audit - The individual must possess excellent project management skills, with ability to communicate effectively and build strong working relationships with both clients and colleagues across Kroll’s network of offices. - As the roles will have an international remit the successful candidates will be required to travel abroad regularly. - Recommended three (3) years incident response experience investigating and remediating cyber breaches, preferably in a consultancy position. - Desired qualifications: CREST IR, CFCE, ENCE, GIAC or other certification(s) would be beneficial (GCFA, GCIH, GREM, GNFA). - Fluency in English is required together with fluency or native capability in the language of the country in which they will be based. Another European or Arabic language would be advantageous. - Extensive experience of managing complex cases and successfully managing resources and budget. - Ability to drive forward and co-ordinate a number of concurrent projects and tasks, managing competing demands. - Clarity of thought and expression to win confidence from key stakeholders and colleagues. - A highly professional and commercial approach to problem solving. - Due to the range of assignments that you will manage across various industry-sectors and country locations, a key interest in global events and markets, with an awareness of working across different cultural and political environments is essential. - Excellent written and verbal communication skills that help represent diverse communities. - Experience working with diverse teams. Your recruiter will be happy to walk you through your U.S.-specific benefits, which include: - Healthcare Coverage: Comprehensive medical, dental, and vision plans. - Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave. - Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection. - Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews. - Retirement Plans: 401(k) plans with company matching. Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position. About Kroll Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll. In order to be considered for a position, you must formally apply via careers.kroll.com. We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability. The current salary range for this position is $100,000 to $145,000 #LI-CN1 #LI-Remote
Related Guides
Related Categories
Related Job Pages
More Incident Response Analyst Jobs
Whether you’re an experienced professional or just getting started, your contributions matter at Fortra. If you’re passionate about tackling meaningful challenges alongside talented team members committed to helping each other succeed, all while having lots of fun, we want to hear from you. We offer competitive benefits and salaries, personal and professional development opportunities, flexibility, and much more! The Response Analyst is a professional with a strategic mindset, responsible for maintaining change management, incident response, and problem management at Fortra. With an established track record in these areas, this role is pivotal in shaping our response strategies, ensuring Fortra and its clients benefit from top-tier, forward-thinking solutions.The individual will also play a key role in strategic meetings with leadership teams.This role emphasizes proactive actions, making recommendations, and then swiftly executing them. With the autonomy to act and the responsibility to immediately advise, the IT Response Analyst is pivotal in shaping Fortra's response strategies for optimal results. WHAT YOU'LL DO - Oversee and manage change management processes to ensure smooth transitions and minimal disruptions. - Evaluate Request for Change (RFCs), ensuring alignment with business strategies and compliance requirements. - Lead incident response efforts, coordinating with various teams to resolve issues swiftly and effectively. - Conduct detailed root cause analysis to address recurring issues and implement preventative measures. - Facilitate postmortem reviews to analyze incidents, identify lessons learned, and drive continuous improvement. - Implement and maintain problem management processes to identify and eliminate systematic IT issues. - Participate in strategic meetings with leadership teams, providing insights and recommendations. - Proactively make recommendations for improvements and execute them promptly. - Advise on response strategies and ensure optimal results through proactive actions QUALIFICATIONS - Bachelor’s Degree in IT or an equivalent qualification. - 3+ years of experience in IT Operations or related roles. - Solid knowledge of ITL frameworks (ITIL Foundation certification is a plus). - Strong interpersonal and communication skills for working with diverse teams and stakeholders - Deep understanding of business alignment. - Ability to work in a fast-paced, customer-focused environment with high service expectations. - Excellent analytical and problem-solving skills. - Strong knowledge in on-premise or Cloud environments. Desired Skills: - Familiarity with project management methodologies (e.g., Agile, Scrum, or PMP certification). - Self-starter with the ability to recommend and act on solutions independently. Experience with ITSM automation tools At Fortra, we’re breaking the attack chain. Ready to join us? Visit our website to learn more about why employees choose to work for Fortra. Remember to connect with us on LinkedIn. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, veteran or disability status.
Incident Response, Lead
Cook Children's Health Care SystemCook Children's Health Care System is headquartered in Fort Worth, Texas and is comprised of numerous centers, hospitals, and practices. Since 1918 as a single
Location: Remote - TX Department: Enterprise Systems Shift: First Shift (United States of America) Standard Weekly Hours: 40 Summary: NOTE: This role carries 24/7 on-call rotation responsibilities and active incident command expectations during major and critical events. The Incident Response Lead works with IT stakeholders across Cook Children's Health Care System to develop policies, procedures, and risk management activities that efficiently contain and minimize the impact of business interruption due to disasters or information system unavailability. This role performs risk and triage analysis to develop incident response plans and runbooks for the most likely and highest-impact events affecting the organization. The Lead also assists IT and business stakeholders in testing response plans through downtime scenarios, tabletop exercises, and other readiness activities. Qualifications: - BS/BA degree in Information Technology, Business Administration, Risk Management or a related field required. In lieu of the BS/BA degree, may accept a high school diploma and 7 years of experience. - 4+ years' experience in incident response management or a related field required. - Strong knowledge of industry standards and frameworks such as ISO 22301 or NIST SP 800-34. - Strong understanding of project management principles and data technologies, expert level knowledge of IT Service Management principles, best practices and frameworks such as ITIL. - Expert-level knowledge of IT Service Management principles, frameworks, and best practices (ITIL) preferred - Expert-level ServiceNow experience — incident workflows, ticket quality, auditing, and reporting preferred - Proven ability to lead live incident response under pressure - On-call availability; experience in 24/7 rotation environments - Strong understanding of project management principles and data technologies preferred Additional Preferred Qualifications: - Experience in healthcare IT environments - ITIL 4 Foundation certification or higher - Hands-on experience building or facilitating DR tabletop exercises - Experience building or auditing runbook libraries - Familiarity with clinical system availability requirements - Strong executive communication and reporting skills ON-CALL & ACTIVE INCIDENT RESPONSIBILITIES This position participates in a 24/7 on-call rotation for major and critical incidents. When a Priority 1 event occurs, this role assumes incident command — coordinating cross-functional bridge calls, driving toward resolution, and maintaining stakeholder communication from onset through post-incident review. Responsibilities during active incidents include: - Assume incident command for major and critical events - Coordinate IS leadership, business stakeholders, and technical resolvers in real time - Draft impact statements and maintain incident timelines - Manage communication cadence through resolution - Enforce ticket discipline during incidents — accuracy, work note quality, and - Post Incident Review resolution documentation standards within ServiceNow SERVICENOW PLATFORM EXPECTATIONS Expert-level ServiceNow experience is highly preferred. This role uses the platform as both an operational tool and a quality assurance mechanism. Key expectations include: - Evaluate incident ticket integrity: classification accuracy, impact/urgency, scoring, resolution notes, and root cause documentation - Build and maintain auditing processes to ensure data quality across the incident lifecycle - Monitor SLA compliance and workflow adherence - Extract trend data and produce dashboards and reports for leadership - Enforce incident workflow standards and drive corrective action where gaps exist Platform competency areas: Incident Management, Ticket Quality Evaluation, Audit & Compliance Workflows, Trend Analysis, SLA Monitoring, platform analytics, Problem Management, Reporting, CMDB Awareness. About Us: Cook Children's Health Care System Cook Children's Health Care System offers a unique approach to caring for children because we are one of the country's leading integrated pediatric health care delivery organizations. Patients benefit from the integrated system because it allows Cook Children's to use all of its resources to treat a patient and allows for easy communication between the various companies by physicians with a focus on caring for children and adolescents. Cook Children’s is an equal opportunity employer. As such, Cook Children’s offers equal employment opportunities without regard to race, color, religion, sex, age, national origin, physical or mental disability, pregnancy, protected veteran status, genetic information, or any other protected class in accordance with applicable federal laws. These opportunities include terms, conditions and privileges of employment, including but not limited to hiring, job placement, training, compensation, discipline, advancement and termination.
Senior Incident Response Analyst
CoalitionCoalition is a cybersecurity company dedicated to partnering with clients to help them prevent and mitigate losses. Coalition helps small and medium-sized businesses around the wor
Lead comprehensive incident response engagements, conduct digital forensics to analyze cyber incidents, and produce detailed forensic reports while collaborating with clients and teams to guide effective remediation strategies.
Law Enforcement Response Associate
ConcentricConcentric is a risk consultancy specializing in delivering strategic security and intelligence services. We provide holistic, intelligent security solutions for private clients and corporations globally. Concentric offers strategic advisory services, risk assessments, physical protection, threat intelligence, open-source monitoring, program audits, secure embedded staffing, and training for security teams and intelligence analysts. Our ultimate goal is to be recognized as the most innovative, capable, and trusted Risk Management partner in the world, and we do this by following these core values: Integrity Collaboration Relationships Excellence Creativity Results Concentric and SPS Global acknowledge the systemic barriers in the security industry and recognize that removing those barriers will require a collaborative and conscious effort. Concentric and SPS Global are committed to programs and initiatives that promote diversity, equity, and inclusion, enhancing our organization and the broader community. We are creating a diverse environment and are proud to be an equal opportunity employer. We encourage people from all backgrounds to apply. All qualified applicants will receive consideration for employment regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. Concentric Advisors and SPS Global are committed to protecting the privacy and security of all applicants who submit personal information to us. You can access our GDPR and CCPA policy by clicking the GDPR button at the bottom of our career page.
Role Description The Law Enforcement Response (LERT) Associate is pivotal in maintaining coordination between client teams, key law enforcement officials, and government agencies. This role drives strategic safety efforts for the client community and coordinates responses with other cross-functional teams. In this role, you will identify safety threats to the client community and take appropriate action by liaising with law enforcement agencies. Additionally, with your tenured experience, you will serve as a mentor to newer associates on the team and be responsible for engaging in highly sensitive case types and process improvement. Responsibilities - Respond to requests from law enforcement and government authorities globally. - Review and assess requests related to critical safety incidents, emergency and emergency-in-progress situations that require timely and accurate response and engagement with Law Enforcement in order to keep the client community safe. - Identify and flag potentially high-risk requests for internal escalation and review to LE Ops management. - Investigate, track, analyze, and accurately respond to a variety of legal requests for user data, working directly with law enforcement authorities, government agencies, and court officials. - Comprehensively document investigation results and decisions. - Maintain high levels of confidentiality and accuracy while performing investigations. - Ability to demonstrate excellent judgment and provide recommendations on the best course of action for responding to requests. - Work with CS, Safety, and Trust teams to develop and refer relevant criminal matters to law enforcement authorities. - Demonstrate great judgment and be open to sharing best practices with your LE Ops colleagues. - Provide guidance and mentorship to other LE Ops associates; participate in the training of new associates. - Ensure that urgent cases are identified, actioned effectively, and handled in accordance with applicable laws and internal community standards and policies. Qualifications - Must be able to legally work in the country where this position is located without visa sponsorship. - 4+ years of relevant experience in legal operations, investigative, or analytical roles. - Skilled in various computer systems, internet technology, and software (MS Office, etc.). - Strong interpersonal and communication skills, both written and verbal. - Analytically minded with strong attention to detail and accuracy. - Advanced knowledge of SQL, Salesforce, and/or an interest in learning more. - Ability to manage and prioritize large ticket volumes. - Confidence in corresponding with law enforcement at all levels in a tactful and considerate manner, ensuring a positive stakeholder experience. - Uses knowledge of how different teams across their function impact the achievement of objectives. - A self-starter who enjoys working in a rapidly changing environment. - Good sense of humor and a love for fun and adventure. - Manages time efficiently and prioritizes deliverables effectively. - Acts as a specialist, providing subject matter expertise and/or guidance to more junior team members. - Works with a high degree of independence and initiative to resolve issues. - A critical thinker with the ability to understand the implications of a given scenario within the business/operational context. - Provides a high level of administrative support and works with highly sensitive and confidential material. - Exchanges complex information and ideas effectively, adapting to a range of audiences. - Contributes to and possibly leads to some process improvement. Requirements - This is a full-time position. The team operates 24 hours per day, seven days per week, and requires regular shift work, including some holidays and weekends. - This position requires up to 10% travel. Benefits - The HSA medical plan covers 100% of the premium for employee-only coverage. - The PPO medical plan requires an employee contribution for employee-only coverage. For both plans, Concentric covers a substantial portion of the premium for dependents. - Concentric also offers an HSA employer contribution. - Medical FSA. - Employer-paid insurance: life, STD, LTD, and AD&D. - 401 (k) including employer match. - 11 paid holidays. - Paid leave (vacation, sick, parental). - Annual Health & Wellness Benefit. - Pet Insurance. - National discount employee program. - Employee Assistance Program for personal needs. - Credentity Protection - Eclipse Digital Protection by Concentric. - Free access to our Risk Intelligence Dashboard and GEAR App. - Dedicated Security and Intelligence Training Programs for Professional Development. - Coaching and Mentoring Opportunities.


