Lead Cybersecurity Engineer
K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.
Our four core values define how we show up every day:
- Respect Others - We lead with respect, building trust and connection.
- Internally Driven - We are relentlessly compelled to accomplish our objectives.
- Collaborative Innovation - We create by listening, sharing, and working together.
- Client Success - We hold our clients' mission as our own.
We believe in people who are accountable, curious, and motivated to make an impact that matters.
Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.
Position Summary
Provide technical leadership for the security engineering, SIEM, and enterprise monitoring capabilities that sustain the client’s detection, alerting, and operational visibility. This position owns monitoring platform health, data source onboarding and telemetry validation, detection engineering and tuning, and the engineering baselines that keep monitoring coverage measurable and defensible.
Key Responsibilities
- Administer, configure, sustain, enhance, and optimize SIEM capabilities and associated monitoring functions.
- Onboard and integrate new data sources; normalize and validate telemetry; expand visibility coverage and strengthen correlation logic.
- Provide engineering support for log management, data handling, alert tuning, detection optimization, and operational analytics improvements.
- Identify gaps in visibility, data coverage, or monitoring capability and drive corrective actions to closure.
- Maintain all security tools and detections in a high-signal state through ongoing refinement in coordination with the NOC/SOC — SIEM rules, EDR alerts, and WAF/CDN policies — to reduce false positives and improve detection accuracy.
- Continuously normalize and validate telemetry from existing and new data sources including Zscaler Secure Access Service Edge (SASE) and Microsoft Defender.
- Support configuration management by monitoring and reporting on security control effectiveness over time, identifying and correcting configuration drift in collaboration with the NOC/SOC.
- Develop and maintain monitoring procedures, technical documentation, engineering baselines, and implementation guidance.
- Provide oversight of security engineering staff, monitoring architecture support, and technical improvement activities.
- Support security configuration baseline development for cloud, operating system, network, and application assets against NIST and CIS benchmarks.