Personal improvement and growth are taken seriously here. The flexibility to work on both proactive and reactive cyber security engagements has greatly expanded my exposure and abilities in serving our clients.
Senior Associate, Cyber Risk
What makes a successful Cyber Security employee at Duff & Phelps? Check out the traits we’re looking for and see if you have the right mix.
- Relationship expertise
- Technologically inquisitive
Duff & Phelps offers many career paths to support your immediate and future success.
Intern leads to Associate, Cyber Risk
Associate, Cyber Risk leads to Senior Associate, Cyber Risk
Senior Associate, Cyber Risk leads to Vice President, Cyber Risk
Vice President, Cyber Risk leads to Senior Vice President, Cyber Risk
Senior Vice President, Cyber Risk leads to Associate Managing Director, Cyber Risk
Associate Managing Director, Cyber Risk ends this path
At Kroll Cyber Risk, I find the collaboration and real sense of teamwork very inspiring. Personal egos are not encouraged! Communication with senior management is also straightforward and responsive. An excellent working environment.
Bill AndersonVice President, APAC Cyber Risk, Singapore
Opportunities for new cyber challenges, knowledge, and career growth are plentiful here. Not only is your success supported through regular professional training, the entire global team also contributes to information sharing via collaboration tools and weekly group presentations. We truly work as a global team and no one ever hesitates to step up and help.
David KloppAMD, Cyber Risk, Singapore
At Kroll you have the opportunity to learn different aspects of cyber security allowing you to develop a set of skills beneficial to your career growth and development. Kroll invests in cyber security and each employee can receive sponsorship for cyber training. In addition, they encourage a work life balance allowing you to do different things for yourself and the team.
Rick LiSenior Associate, Cyber Risk, Hong Kong
The Kroll Cyber team has a great culture. Everyone is down to earth and willing to help each other out. There are no big egos to contend with, which makes for a vibrant and collaborative working environment. One of the significant differences between Kroll Cyber and other places I have worked is how easy it is to work across international teams. There are no bureaucratic processes; all it takes is a quick conversation to organise logistics.
Mark FarleySenior Vice President, EMEA Cyber Risk, London
Working for the group is awesome, from the amazing culture to a diverse range of projects undertaken. The benefits of being in a global team and collaborative knowledge sharing is unparalleled compared to competitors. Everyday can be different, however it typically consists of helping clients improve their cyber security, constant learning and problem solving.
Hassan MahmudAssociate, EMEA Cyber Risk, London
One of the things I appreciate most from being at this company is the feeling of support. Whether that be helping to develop my work product, ensuring I receive sufficient training, or affording me flexibility when life demands it, I always have the sense that Kroll has my back, and that is a valuable thing indeed.
Ben HawkinsSenior Managing Consultant, EMEA Cyber Risk, London
Ongoing training and development opportunities at all levels of the firm through programs such as Duff & Phelps University, The Promote Program and Network of Women.
As a global firm, our benefits vary by country.
Be part of a flexible and diverse team that encourages and supports your personal and professional growth.
DescriptionJob ID 20001699 Sydney, Australia Apply now
Our professionals balance analytical skills, deep market insight and independence to deliver solid, defensible analysis and practical advice to our clients. As an organization, we think globally. We create transparency in an opaque world, and we encourage our people to do the same. That means when you take your place on our team, you’ll discover a supportive and collaborative work environment that empowers you to excel. If you’re ready to share your perspective with the world, then you can make a real impact here. This is the Duff & Phelps difference.
Kroll is the leading global provider of risk solutions. For more than 45 years, Kroll has helped clients make confident risk management decisions about people, assets, operations and security through a wide range of investigations, cyber security, due diligence and compliance, physical and operational security and data and information management services. Kroll is a division of Duff & Phelps, the global advisor that protects, restores and maximizes value for clients in the areas of valuation, corporate finance, investigations, disputes, cyber security, compliance and regulatory matters, and other governance-related issues. We work with clients across diverse sectors, mitigating risk to assets, operations and people. With Kroll, a division of Duff & Phelps since 2018, our firm has nearly 4,000 professionals in 25 countries around the world.
This position is an excellent opportunity for a self-motivated individual to join a fast-growing team of global experts. The successful candidate will have the opportunity to attend leading training as well as further their career through exposure to a diverse caseload alongside some of the best talent in the industry.
As a Forensic Analyst, frequent travel may be required to various locations in Asia and to be involved in a range of investigations which include employee investigations, hacking, fraud, data recovery, theft of sensitive company information, industrial and commercial espionage.
Due to the inherent volatility of investigative response work, you will be expected to discharge various responsibilities assigned, while successfully managing a variable caseload. You will be responsible for integrity in analysis, quality in client deliverables, as well as gathering caseload intelligence.
- Use leading-edge technology and industry standard forensic tools and procedures to provide insight into the cause and effect of suspected Cyber intrusions.
- Follow proper evidence handling procedures and chain of custody protocols.
- Determine programs that have been executed, including finding files that have been changed on disk and in memory. Use timestamps, host and network logs, photographs, and the collection of hash information to develop authoritative timelines of activity.
- Find evidence of deleted files and hidden data. Identify and document case relevant file-system artifacts, including browser histories, account usage, and USB histories.
- Assist with preliminary analysis by tracing an activity to its source and produce documents findings for input and into a forensic report.
- Analyze and assess risk to client’s information technology systems and enterprise environment.
- Take ownership of projects and deliverables.
- Participate in technical reviews including; the evaluation of Windows and Linux systems, database configurations, application auditing, network device
- Conduct research and analysis through the use of in-hours as well as external resources
- Produce accurate, high quality client reports
- Self-motivated and able to demonstrate a passion for this type of work. This will include evidence of research, knowledge of a diverse array of tool-sets, community participation and self-learning beyond commercial training
- Bachelor’s Degree in a technical discipline preferred
- Minimum of 5 years’ experience with digital forensics with a focus on external threat incident response and network forensics
- Forensics related certifications such as GNFA, GCFA, GCFE, GCIH, CFCE, EnCE, X-PERT
- Experience with acquiring or collecting computer artifacts, including malware, user activity, and link files from various systems
- Experience with assessing evidentiary value by triaging electronic devices, correlating forensic findings with network events to further develop an intrusion narrative
- Experience with collecting and documenting system state information, including running processes and network connections prior to imaging
- Experience with performing incident triage from a forensic perspective, including determining of scope, urgency, and potential impact
- Experience with tracking and documenting forensic analysis from initial involvement through final resolution
- Must be able to assist clients in responding rapidly and effectively to computer-related incidents and should consistently exceed expectations while working in a client-facing environment
- Have the capability to quickly identify the source of a security breach and move toward containment is essential
- Have proficiency in conducting live analysis on networks and across multiple platforms is desired. Must possess the ability to articulate well in both written and oral communications
- Must also be able to manage multiple projects on a daily basis Willingness to travel up to 75%
- Candidates with more experience will be considered another level
In order to be considered for a position at Duff & Phelps, you must formally apply via careers.duffandphelps.jobs
Duff & Phelps is committed to equal opportunity and diversity, and recruits people based on merit
Explore Your Potential
Promote Program at Duff & Phelps
From investigations to compliance to cyber security, we provide services for organizations at every stage of their challenges.
How do we give our clients peace of mind? At Duff & Phelps, our disciplined thought process helps us dig deep to challenge assumptions.
Growth and You at Duff & Phelps
Our approach to ongoing education includes formal training curriculum and on-the-job learning.
Network of Women
Since 2012, Duff & Phelps' Network of Women (NOW) attracts, develops and retains women at all levels of the firm.