Lead Cybersecurity Engineer

K2United, LLC.

Washington (District of Columbia)

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

K2United, LLC is seeking a senior security engineering leader in Washington, DC to own SIEM monitoring, telemetry validation, and detection engineering across platforms. You will supervise engineering staff and collaborate with NOC/SOC to improve coverage, reduce false positives, and ensure baseline configurations align with CIS/NIST benchmarks.

The role requires hands-on Splunk experience, Defender for Endpoint/Servers, and preferred exposure to SASE or ZTNA with Zscaler. U.S.

Qualifications

  • Eight+ years in security engineering with 3+ years leading SIEM administration and detection engineering.
  • Hands-on SIEM engineering depth including data onboarding, field extraction, normalization, and content lifecycle management.
  • Proven experience tuning EDR and WAF/CDN detection policies to reduce false positives.

Responsibilities

  • Administer, configure, sustain, and optimize SIEM capabilities and monitoring functions.
  • Onboard data sources, normalize telemetry, expand visibility, and strengthen correlation logic.
  • Provide engineering support for log management, alert tuning, and incident analytics improvements.
  • Maintain security tools and detections with high signal quality in coordination with NOC/SOC.

Skills

SIEM administration
Detection engineering
Data onboarding
Telemetry validation
Engineering leadership
Audit readiness

Education

Bachelor's degree in CS/Engineering

Tools

Splunk
Microsoft Defender
Zscaler

Job description

Description

K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.

Our four core values define how we show up every day:

  • Respect Others - We lead with respect, building trust and connection.
  • Internally Driven - We are relentlessly compelled to accomplish our objectives.
  • Collaborative Innovation - We create by listening, sharing, and working together.
  • Client Success - We hold our clients' mission as our own.

We believe in people who are accountable, curious, and motivated to make an impact that matters.

Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.

Position Summary

Provide technical leadership for the security engineering, SIEM, and enterprise monitoring capabilities that sustain the client's detection, alerting, and operational visibility. This position owns monitoring platform health, data source onboarding and telemetry validation, detection engineering and tuning, and the engineering baselines that keep monitoring coverage measurable and defensible.

Key Responsibilities
  • Administer, configure, sustain, enhance, and optimize SIEM capabilities and associated monitoring functions.
  • Onboard and integrate new data sources; normalize and validate telemetry; expand visibility coverage and strengthen correlation logic.
  • Provide engineering support for log management, data handling, alert tuning, detection optimization, and operational analytics improvements.
  • Identify gaps in visibility, data coverage, or monitoring capability and drive corrective actions to closure.
  • Maintain all security tools and detections in a high-signal state through ongoing refinement in coordination with the NOC/SOC — SIEM rules, EDR alerts, and WAF/CDN policies — to reduce false positives and improve detection accuracy.
  • Continuously normalize and validate telemetry from existing and new data sources including Zscaler Secure Access Service Edge (SASE) and Microsoft Defender.
  • Support configuration management by monitoring and reporting on security control effectiveness over time, identifying and correcting configuration drift in collaboration with the NOC/SOC.
  • Develop and maintain monitoring procedures, technical documentation, engineering baselines, and implementation guidance.
  • Provide oversight of security engineering staff, monitoring architecture support, and technical improvement activities.
  • Support security configuration baseline development for cloud, operating system, network, and application assets against NIST and CIS benchmarks.
Requirements
  • Bachelor's degree in computer science, engineering, cybersecurity, or a related field. Equivalent experience considered in lieu of degree.
  • Eight or more years in security engineering, including at least three years leading SIEM administration and detection engineering in an enterprise environment.
  • Demonstrated hands-on SIEM engineering depth — Splunk strongly preferred given USAC's documented use of Splunk for threat hunting— including data onboarding, field extraction, normalization, correlation search development, and content lifecycle management.
  • Practical engineering experience with Microsoft Defender for Endpoint and for Servers, and with a SASE or ZTNA platform; Zscaler preferred.
  • Demonstrated experience tuning EDR and WAF/CDN detection policy to measurable false-positive reduction.
  • Experience developing and maintaining security configuration baselines against CIS Benchmarks and NIST guidance, and remediating configuration drift.
  • Ability to produce engineering documentation and baselines that withstand audit review.
Preferred Qualifications
  • Experience integrating SIEM with SOAR and conditional access platforms.
  • Log management design experience aligned to OMB M-21-31 event logging maturity tiers.
  • Experience in a 24x7x365 SOC/NOC support model where engineering directly serves shift operations.
Required Certifications

CISSP, ISSEP, ITIL Foundation (latest revision), and/or an equivalent advanced security engineering or architecture certification. Platform certifications — Splunk ES Certified Admin, Microsoft SC-200 or SC-100, Zscaler ZDTA — are valuable differentiators.

Applicants must be willing to take a drug test and submit to a credit and background investigation as part of the selection process.

The U.S. government restricts access by Foreign Nationals to certain types of technology and technical data. Consequently, this posting is intended only for U.S. citizens.

K2United, LLC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or protected Veteran status.

This job description is not an exhaustive list of job responsibilities. K2United management reserves the right to change or alter this job description at any time without notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

K2Share LLC • Washington

On-site
USD 140,000 - 190,000
Senior SIEM & Detection Engineering Lead
Senior SIEM & Detection Engineering Lead

K2United, LLC. • Washington

On-site
USD 150,000 - 190,000
Senior SIEM & Security Monitoring Engineer
Senior SIEM & Security Monitoring Engineer

K2Share LLC • Washington

On-site
USD 140,000 - 190,000
Detection and Response Engineer
Detection and Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 120,000 - 180,000
Paid parental leave
Certification reimbursement
Digital mental health support
+1
Sr. Security Engineer - SIEM, Automation & Elastic Security
Sr. Security Engineer - SIEM, Automation & Elastic Security

Red Lobster, Inc. • Orlando (FL)

On-site
USD 90,000 - 130,000
Cyber Security Engineer
Cyber Security Engineer

empirical Foods • North Sioux City (SD)

On-site
USD 100,000 - 140,000
Health benefits
Dental insurance
Vision insurance
+5
Cyber Security Engineer
Cyber Security Engineer

VetJobs • Dakota Dunes (SD)

On-site
USD 90,000 - 130,000
Health/Dental/Vision
Disability Insurance
Life Insurance
+4
Cyber Security Engineer
Cyber Security Engineer

Empirical-Food • Dakota Dunes (SD)

On-site
USD 95,000 - 120,000
Lead Cybersecurity Engineer – Senior
Lead Cybersecurity Engineer – Senior

Dormont Manufacturing Co • United States

On-site
USD 150,000 - 175,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

TALENT Software Services • Richmond (VA)

On-site
USD 120,000 - 170,000