Lead Cybersecurity Engineer
K2Share LLC · Washington, District of Columbia, United States
IT Services and IT Consulting · 51-200 employees
About the role
The Lead Cybersecurity Engineer will provide technical leadership for security engineering, SIEM administration, and enterprise monitoring capabilities. This role involves optimizing detection engineering, managing telemetry validation, and ensuring security control effectiveness across the organization.
What they look for
Requirements
Candidates must have at least eight years of security engineering experience, including three years specifically in SIEM administration and detection engineering. A bachelor's degree in a relevant field is required, along with professional certifications such as CISSP or equivalent.
Full description
Description
K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.
Our four core values define how we show up every day:
- Respect Others - We lead with respect, building trust and connection.
- Internally Driven - We are relentlessly compelled to accomplish our objectives.
- Collaborative Innovation - We create by listening, sharing, and working together.
- Client Success - We hold our clients' mission as our own.
We believe in people who are accountable, curious, and motivated to make an impact that matters.
Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.
Position Summary
Provide technical leadership for the security engineering, SIEM, and enterprise monitoring capabilities that sustain the client’s detection, alerting, and operational visibility. This position owns monitoring platform health, data source onboarding and telemetry validation, detection engineering and tuning, and the engineering baselines that keep monitoring coverage measurable and defensible.
Key Responsibilities
- Administer, configure, sustain, enhance, and optimize SIEM capabilities and associated monitoring functions.
- Onboard and integrate new data sources; normalize and validate telemetry; expand visibility coverage and strengthen correlation logic.
- Provide engineering support for log management, data handling, alert tuning, detection optimization, and operational analytics improvements.
- Identify gaps in visibility, data coverage, or monitoring capability and drive corrective actions to closure.
- Maintain all security tools and detections in a high-signal state through ongoing refinement in coordination with the NOC/SOC — SIEM rules, EDR alerts, and WAF/CDN policies — to reduce false positives and improve detection accuracy.
- Continuously normalize and validate telemetry from existing and new data sources including Zscaler Secure Access Service Edge (SASE) and Microsoft Defender.
- Support configuration management by monitoring and reporting on security control effectiveness over time, identifying and correcting configuration drift in collaboration with the NOC/SOC.
- Develop and maintain monitoring procedures, technical documentation, engineering baselines, and implementation guidance.
- Provide oversight of security engineering staff, monitoring architecture support, and technical improvement activities.
- Support security configuration baseline development for cloud, operating system, network, and application assets against NIST and CIS benchmarks.
Requirements
- Bachelor's degree in computer science, engineering, cybersecurity, or a related field. Equivalent experience considered in lieu of degree.
- Eight or more years in security engineering, including at least three years leading SIEM administration and detection engineering in an enterprise environment.
- Demonstrated hands-on SIEM engineering depth — Splunk strongly preferred given USAC's documented use of Splunk for threat hunting— including data onboarding, field extraction, normalization, correlation search development, and content lifecycle management.
- Practical engineering experience with Microsoft Defender for Endpoint and for Servers, and with a SASE or ZTNA platform; Zscaler preferred.
- Demonstrated experience tuning EDR and WAF/CDN detection policy to measurable false-positive reduction.
- Experience developing and maintaining security configuration baselines against CIS Benchmarks and NIST guidance, and remediating configuration drift.
- Ability to produce engineering documentation and baselines that withstand audit review.
Preferred Qualifications
- Experience integrating SIEM with SOAR and conditional access platforms.
- Log management design experience aligned to OMB M-21-31 event logging maturity tiers.
- Experience in a 24x7x365 SOC/NOC support model where engineering directly serves shift operations.
Required Certifications
CISSP, ISSEP, ITIL Foundation (latest revision), and/or an equivalent advanced security engineering or architecture certification. Platform certifications — Splunk ES Certified Admin, Microsoft SC-200 or SC-100, Zscaler ZDTA — are valuable differentiators.
Applicants must be willing to take a drug test and submit to a credit and background investigation as part of the selection process.
The U.S. government restricts access by Foreign Nationals to certain types of technology and technical data. Consequently, this posting is intended only for U.S. citizens.
K2United, LLC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or protected Veteran status.
This job description is not an exhaustive list of job responsibilities. K2United management reserves the right to change or alter this job description at any time without notice.