Full-Time

Senior Consultant

Red Team, Offensive Security

Kroll

Kroll

5,001-10,000 employees

Global risk management and investigations consulting

No salary listed

London, UK

Remote

Remote within the United Kingdom.

Category
IT & Security (1)
Required Skills
TCP/IP
PowerShell
Microsoft Azure
Python
JavaScript
LDAP
Network Monitoring
Computer Networking
AWS
C/C++
Google Cloud Platform

Get referred to Kroll

See people who can refer or advise you

Requirements
  • 5+ years in offensive cybersecurity, including experience delivering red team, purple team, adversary emulation, or assumed-breach engagements
  • Existing SC clearance, or the ability and willingness to obtain SC clearance
  • A relevant CREST red team certification aligned to CBEST-style delivery, such as CREST Certified Red Team Specialist, formerly CCSAS, or the ability to obtain this within the probation period
  • Strong experience with Windows enterprise environments, Active Directory exploitation, privilege escalation, and lateral movement
  • Experienced and comfortable with performing social engineering techniques in support of red team operations, including email and voice phishing
  • Experience operating command-and-control frameworks such as, Mythic, Cobalt Strike, or similar tooling in authorised client engagements
  • Experience developing, modifying, or extending offensive security tooling, scripts, or payloads
  • Working knowledge of at least one of C, C#, Python, PowerShell, and/or JavaScript, to support offensive security objectives
  • Practical understanding of evasion techniques, endpoint security controls, operational security, and detection-aware tradecraft
  • Strong understanding of networking and web protocols, including TCP/IP, DNS, HTTP, HTTPS, and authentication flows
  • Experience conducting reconnaissance, attack path development, and objective-based testing
  • Excellent written and verbal communication skills, with the ability to explain complex technical issues clearly to technical and non-technical audiences
  • The ability to manage risk during live client engagements and operate within agreed rules of engagement
Responsibilities
  • Deliver red team, purple team, assumed-breach, and adversary emulation engagements for clients across multiple sectors
  • Support engagement planning, including threat-informed scenarios, attack objectives, rules of engagement, operational security considerations, and success criteria
  • Execute hands-on offensive activity across enterprise environments, including Active Directory exploitation, credential access, privilege escalation, lateral movement, and objective-based testing
  • Assess and exploit attack paths across Microsoft Entra ID, Microsoft 365, hybrid identity environments, AWS, Azure, GCP, and other cloud platforms, where in scope
  • Build, adapt, and operate red team infrastructure, command-and-control tooling, payloads, and scripts during authorised client engagements
  • Apply detection-aware tradecraft and understand how EDR, SIEM, identity protection, conditional access, email security, and network monitoring can affect red team operations
  • Support purple team engagements by executing agreed TTPs, working with client security teams, validating detection logic, and helping clients improve response capability
  • Conduct authorised social engineering activity, including reconnaissance, phishing, vishing, pretext development, and controlled initial access scenarios
  • Conduct research and development to improve Kroll’s red team tooling, tradecraft, methodology, and reporting
  • Produce clear, evidence-based reporting that explains attack paths, business impact, detection and response observations, and prioritised remediation actions
  • Present technical findings to security teams and communicate business risk to senior stakeholders
  • Mentor junior consultants, support technical delivery, and contribute to peer review and quality assurance
  • Work collaboratively with Kroll’s wider Cyber Risk teams, including incident response, threat intelligence, cloud security, and detection engineering
Desired Qualifications
  • CREST Certified Red Team Specialist, OSEP, OSCE3, CRTO, CRTL, GPEN, GXPN, or equivalent experience
  • Experience delivering CBEST, STAR-FS, TIBER, DORA-aligned, TLPT, or regulated financial-sector red team engagements
  • Strong working knowledge of Microsoft Entra ID, Microsoft 365, and hybrid identity attack paths
  • Working knowledge of cloud platforms such as AWS, Azure, or GCP, including identity, privilege escalation, misconfiguration abuse, and cloud-native attack paths
  • Experience with exploit development, reverse engineering, malware analysis, or assembly-level debugging
  • Experience with macOS or Linux endpoint tradecraft
  • Experience with Kubernetes, Docker, CI/CD platforms, DevOps environments, or containerised workloads
  • Experience with physical security
  • Experience with employing modern AI tooling to support offensive engagements
  • Threat intelligence, detection engineering, or incident response experience
  • Experience writing blogs, presenting at industry events, publishing research, or contributing to offensive security tooling
  • Experience leading small teams or technical workstreams during complex offensive security engagements

Preparing summary

Company Size

5,001-10,000

Company Stage

N/A

Total Funding

N/A

Headquarters

New York City, New York

Founded

1932

Get referred to Kroll

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Competition cases can expand into multi-member-state claims after national proceedings.
  • Cyber services can bundle breach response, litigation support, and managed security.
  • Financial institutions offer repeat demand for compliance, diligence, and regulatory remediation.

What critics are saying

  • Integrating ABC economics can fail if senior economists leave after closing.
  • Kroll faces reputation-sensitive cyber work where one service failure drives client churn.
  • Confidentiality breaches inside Kroll would damage trust across investigations and diligence mandates.

What makes Kroll unique

  • Kroll combines investigations, cyber, compliance, valuation, and dispute resolution services.
  • Its global team supports cross-border matters in over 50 jurisdictions.
  • ABC economics adds competition-economics and cartel-damages capability in Europe.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

16%

1 year growth

16%

2 year growth

16%
Northampton Chronicle & Echo
Apr 30th, 2026
Claire's in Northampton closes for good as national chain shuts all shops with more than 1,000 job losses.

Claire's in Northampton closes for good as national chain shuts all shops with more than 1,000 job losses. Assistant editor Published 30th Apr 2026, 14:35 BST Northampton Chronicle & Echo Morning Update Thursday 30 April, 2026 A shop in Northampton's Grosvenor Centre has shut for good, as the national chain confirms it has ceased trading and made more than 1,000 redundancies. Claire's, which has 154 standalone stores across the country, hit financial difficulty and in January fell into administration for the second time in just a few months. Kroll - the administrators in charge - have now announced that all shops closed on April 27, with around 1,300 employees notified of redundancy. The store, which was popular with youngsters, was located on the top floor of the Grosvenor Centre and had been displaying '50 percent off' and 'closing down' signs for a number of weeks, while the future of the company hung in the balance. You May Like The jewellery, hair accessories and ear piercing chain reported issues in January this year, after a troubling Christmas period. No saviour deal could be reached.

Brazilian-American Chamber of Commerce
Apr 27th, 2026
Kroll Leadership Recognized in Finance and M&A

April 27, 2026 Kroll leadership recognized in Finance and M&A. The BrazilCham is pleased to share that Alexandre Pierantoni, Managing Director at Kroll, member of the Chamber's Board of Directors, and Chairperson of the Trade & Business Investment Committee, has been recognized by Leaders League as Advisor of The Year: Finance in the Individual Recognition category for M&A. This recognition highlights the depth of expertise, leadership, and strategic advisory capabilities demonstrated by Alexandre through his work at Kroll, as well as the firm's active and valued contribution to the Chamber and the broader Brazil-U.S. business community. Brazilian-American Chamber of Commerce congratulates Alexandre and Kroll on this well-deserved achievement and wishes them continued success. Brought by Chamber Member Leadership Transactions Members News Advisory Firm

Corporate Compliance Insights
Mar 27th, 2026
GRC news roundup: Workiva, Smarsh, TrustCloud, Kroll & more.

GRC news roundup: Workiva, Smarsh, TrustCloud, Kroll & more. GRC technology is one of the fastest-growing segments in enterprise software. Here's the latest from brands across the industry. New products & platforms. If there's a theme in recent GRC product news, it's agentic AI - vendors are racing to move beyond copilots and chatbots toward systems that can act, investigate and remediate with minimal human intervention. Recent announcements reflect that shift across cybersecurity, communications compliance and risk management. * TrustCloud launched a security assurance platform designed to integrate governance, risk and compliance with cybersecurity operations for enterprise CISOs. * Workiva introduced AI-powered capabilities across its GRC platform spanning controls management, audit management and risk management. * Smarsh unveiled a suite of AI agents for legal discovery and communications surveillance, including a discovery agent and an intelligent agent for compliance monitoring. * Relyance AI released Lyo, an autonomous data security tool that monitors how AI agents interact with enterprise data in real time. * Living Security launched an AI-native human risk management platform powered by Livvy, an AI risk intelligence engine. * Keysight Technologies introduced a software bill of materials manager, a platform for generating and managing SBOMs to support compliance with regulations, including the EU Cyber Resilience Act. Partnerships. Across financial crime compliance and identity verification, vendors are increasingly combining capabilities. * Sumsub and ComplyAdvantage announced an integration embedding ComplyAdvantage's Mesh intelligence layer into Sumsub's AML screening platform for KYC, KYB and transaction monitoring workflows. * Socure and Checkr Trust announced a partnership combining Socure's identity verification with Checkr Trust's criminal background data network within Socure's RiskOS platform. * Kroll and Greenboard announced a partnership pairing Kroll's compliance advisory services with Greenboard's AI-native platform for financial services firms.

PR Newswire
Mar 25th, 2026
Kroll partners with Greenboard to launch AI-driven unified compliance platform for financial institutions

Kroll, a financial and risk advisory firm, has partnered with Greenboard, an AI-native compliance technology provider, to deliver a unified compliance platform for financial institutions. The collaboration combines Kroll's regulatory expertise with Greenboard's technology, which integrates archiving, supervision, certifications, marketing review and vendor diligence into a single hub. The platform uses AI and cloud automation to streamline compliance operations and improve transparency whilst eliminating the inefficiencies of managing multiple disconnected tools. Unlike point-solution approaches, it provides holistic compliance management through seamless integration of advanced technology and Kroll's established services. Greenboard currently serves over 500 financial institutions. The partnership aims to help organisations respond to evolving regulatory complexities and adapt quickly to emerging risks and requirements.

PR Newswire
Mar 23rd, 2026
Kroll and Bluprynt partner to scale on-chain risk solutions with Know Your Issuer technology

Kroll, a global risk advisory firm, has partnered with Bluprynt to expand on-chain risk solutions for digital assets. The collaboration will enable financial institutions and regulators to implement Know Your Issuer (KYI) technology, which embeds verified issuer identity, governance parameters and lifecycle status directly into digital assets. The partnership addresses a gap in digital asset infrastructure, which currently verifies customers and transactions but lacks a framework for verifying issuer identity at the token layer. Kroll will support global deployment of Bluprynt's KYI solution, helping institutions validate issuer information and integrate it into compliance programmes. The firms will develop risk frameworks usable across jurisdictions and create solutions for regulators and financial institutions navigating emerging digital asset risks. Bluprynt provides on-chain credentialing infrastructure for compliant issuance and governance in digital finance.