Kraft Kennedy

Kraft Kennedy

Kraft Kennedy is a leading technology consulting firm with 30 years of experience, specializing in IT solutions for law firms, legal departments, and financial services. Their expert team provides personalized attention and custom solutions to meet cli...

Internet Software & Services
51-250
Founded 1988

Description

  • Administer and maintain the enterprise SIEM platform, ensuring system health, performance, storage, availability, updates, patching, and backups.
  • Onboard and integrate new log sources with internal and client teams, ensuring accurate data collection, parsing, and normalization.
  • Create, tune, and manage SIEM content including correlation rules, exclusions, alerts, dashboards, and reports to improve detections and reduce false positives.
  • Monitor and analyze SIEM performance metrics and implement improvements to support scalability and high-speed querying.
  • Perform in-depth analysis and investigation of security incidents and collaborate with SOC analysts to escalate and resolve advanced threats.
  • Generate and maintain documentation and reports for SIEM architecture, processes, system health, performance, and compliance.
  • Assess client security needs, recommend tailored solutions aligned with Kraft Kennedy SOC standards, and help develop/implement security policies.
  • Provide technical guidance and troubleshooting for SOC staff and resolve SIEM-related issues in a timely manner.
  • Stay current with emerging threats, trends, and technologies to proactively safeguard client environments.

Requirements

  • Must reside in one of the specified US states or DC for this remote role (CT, DE, FL, GA, IL, MD, MA, NY, SC, NC, TN, TX, UT, VA, VT, DC, KY, PA, OH, WA).
  • Minimum of 3 years of experience in IT Security or a related field.
  • Availability to be on call outside normal business hours for emergencies and ability to manage multiple priorities in a fast-paced environment.
  • Deep understanding of enterprise SIEM platforms (e.g., ConnectWise SIEM): log formats, collection methodologies, data normalization, and content creation.
  • Hands-on Linux and Windows system administration and command-line experience.
  • Proficiency in scripting (Python, PowerShell) and query languages such as KQL.
  • Experience with security monitoring tools, vulnerability scanning, EDR, mail hygiene, Zero Trust, and vulnerability management tools.
  • Knowledge of security frameworks and incident response processes (MITRE ATT&CK, NIST, CIS) and hands-on incident handling experience.
  • Excellent verbal and written communication skills and strong troubleshooting/analytical abilities.
  • Must hold or be able to obtain within one working year Microsoft AZ-500 and SC-200 certifications; additional security certs (CISSP, GCIA, GCIH, GCFA, GCFE) are a plus; familiarity with the Kraft Kennedy SOC stack is preferred.

Benefits

  • Base salary range $65,000–$80,000 (actual offer based on qualifications, experience, and location); some positions eligible for bonuses or commissions.
  • Medical, dental, life, and disability insurance.
  • 401(k) with company match.
  • Paid holidays, vacation, and sick days.
  • Cutting-edge training on the latest technologies and professional development opportunities.
  • Employee referral bonus program.
  • Phone reimbursement.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

SOC Analyst (L2)

Protera 251-1K IT Services

Protera Technologies is hiring a remote SOC Analyst to provide 24x7 monitoring, detection, and incident response for the company’s cybersecurity environment—focusing on maintaining and improving the organization’s security posture through detection, response, and automation.

AWS Azure Elasticsearch HIPAA SIEM Splunk
1 month ago

Intelligence Analyst (Night Shift)

Everbridge 1K-5K Internet Software & Services

Everbridge is hiring an Intelligence Analyst to join its International Monitoring Center (remote, anywhere in Hungary) to monitor overnight risk events, produce timely real-time reports, and provide operational support to clients.

1 month ago

Information Security Data and Risk Analyst

Ivanti 1K-5K Internet Software & Services

Ivanti is hiring a Security Data and Risk Analyst to own and drive enterprise visibility of security risk by developing KPIs/KRIs, automating data pipelines and presenting executive-ready insights to reduce risk across products and corporate environments.

Cybersecurity Go Python SIEM SOC
1 month ago

Third Party Information Security Assessment Lead Assessor

SoFi 1K-5K Capital Markets

Third Party Information Security Assessment Lead Assessor at SoFi responsible for owning and executing an ongoing book of third‑party information security assessments to evaluate control design and operational effectiveness and drive remediation and governance across the organization.

Cybersecurity
1 month ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers