About this role
A Threat Hunter proactively identifies advanced cyber threats within organizational networks that evade traditional detection tools. This role involves hypothesis-driven investigations to uncover hidden adversaries, mitigate risks, and enhance SOC capabilities. Key Responsibilities:
• Develop and test hypotheses based on threat intelligence, anomalies, and attack patterns to proactively hunt for malicious activity.
• Analyze logs, network traffic, endpoints, and telemetry data using tools like SIEM, EDR, and custom scripts to correlate events and detect stealthy attacks.
• Document findings, create repeatable hunt playbooks, and collaborate with detection engineering to automate responses and improve defenses.
• Research emerging threats, malware, and TTPs (tactics, techniques, procedures); generate reports and recommend mitigations.
• Conduct threat hunting campaigns, assess vulnerabilities, and support incident response while optimizing hunting tools and processes.
Required Qualifications:
• Bachelor's degree in Cybersecurity, Computer Science, or related field; advanced certifications like GCTI, CTIA, or OSCP preferred.
• 5+ years in cybersecurity, with hands-on experience in SOC, incident response, and threat hunting.
• Proficiency in tools such as CrowdStrike Falcon, Splunk, Wireshark, YARA, and Python for scripting and automation.
• Strong analytical skills, knowledge of MITRE ATT&CK framework, and understanding of cloud/network security.
In order to be considered for a position at Kroll, you must formally apply via careers.kroll.com Kroll is committed to equal opportunity and diversity, and recruits people based on merit. #LI-AT1