Senior Manager - SIEM SOAR Engineer
KrollAbout the role
Kroll’s Cyber Data & Resilience practice is building a high-growth CrowdStrike Next Gen SIEM and MDR Enablement practice, and we are seeking a proven technical leader to help shape and scale delivery across detection, automation, and managed response services.
As a Senior Manager / Principal Consultant, you will oversee a team of detection engineers and client delivery professionals deploying and operationalizing CrowdStrike Falcon and LogScale. Your mission: to design repeatable delivery models, ensure operational excellence, and help clients accelerate their detection maturity through Kroll’s modern managed-services framework.
This is a leadership and delivery role—ideal for someone who enjoys bridging technical execution, service development, and client outcomes.
Day-to-Day Responsibilities:
Lead end-to-end delivery of CrowdStrike MDR and Next Gen SIEM (LogScale) implementations for enterprise and mid-market clients.
Define standard operating procedures, playbooks, and delivery frameworks for repeatable, scalable service delivery.
Manage and mentor detection engineers and consultants delivering client projects across CrowdStrike Falcon modules.
Oversee detection logic development, correlation rules, and SOC process optimization.
Partner with Kroll’s incident response and advisory teams to integrate post-incident detection enhancements into ongoing MDR operations.
Develop and maintain CrowdStrike baseline configurations, deployment templates, and automation accelerators (Terraform, Ansible, PowerShell).
Interface directly with client executives and technical stakeholders to translate business risk into detection and response strategies.
Collaborate with technology alliances (CrowdStrike, Microsoft, etc.) on co-developed service offerings and go-to-market enablement.
Track delivery metrics, SLAs, and client satisfaction to continuously improve program maturity and profitability.
Essential Traits:
7–10+ years of experience in cybersecurity delivery, operations, or consulting (preferably within MDR, SOC, or detection engineering programs).
Proven track record leading teams deploying CrowdStrike Falcon and CrowdStrike LogScale technologies.
Strong understanding of SIEM/SOAR operations, detection logic, and threat response workflows.
Experience designing or maturing MDR service models (process, metrics, automation, and reporting).
Proficiency in Terraform, PowerShell, or Python for automation and configuration management.
Deep familiarity with multi-tenant operations, Flight Control, and Azure Lighthouse environments.
Excellent communication and presentation skills—comfortable interfacing with client CISOs and technical teams alike.
Preferred Skills
Experience in security consulting or managed services leadership (Big 4, MSSP, or global cyber provider preferred).
CrowdStrike certifications (CCFA, CCFR, CCSA) or equivalent technical credentials.
Familiarity with Defender Suite integration and hybrid XDR architecture.
Knowledge of ROI modeling, efficiency metrics, and service-based automation frameworks.
Strong business acumen and the ability to link detection and response outcomes to client risk reduction and value realization.
About Kroll
Kroll is the global leader in risk and financial advisory, trusted by clients around the world to protect, detect, and respond to evolving cyber threats. Our Cyber Data & Resilience team combines decades of incident response experience with cutting-edge technologies like CrowdStrike, Microsoft Defender, and AI-driven analytics to help organizations transform from reactive to proactive operations.
We work with global enterprises, private equity portfolio companies, and regulated industries to deliver operational resilience, improved visibility, and
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s