
Security Engineer
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Nevada.
• Deploy, configure, maintain, and upgrade Kalosys's internal security platforms across endpoint, network, identity, email, and cloud domains.
• Take ownership of tool health, including agent coverage, log ingestion continuity, license utilization, integration status, and version currency.
• Develop and optimize detection content, alert rules, correlation logic, and suppression policies.
• Integrate security tools with SIEM, ticketing, asset inventory, identity providers, and notification channels using connectors and APIs.
• Manage internal vulnerability scanning and monitor remediation efforts.
• Strengthen internal systems in accordance with CIS Benchmarks and vendor hardening guidelines.
• Automate engineering and reporting tasks utilizing PowerShell, Python, Bash, and vendor APIs.
• Act as the technical implementation lead for client security tooling engagements.
• Onboard client log sources and telemetry, ensuring data quality, parsing accuracy, and detection coverage.
• Conduct vulnerability assessments and configuration reviews within client environments.
• Engage in client-facing technical discussions and provide remediation advice.
• Assist in channel-partner engagements and Business Resilience practice initiatives.
• Enhance templates, configurations, deployment checklists, and reusable automation processes.
• Monitor engagement tasks, deliverables, time, utilization, and scope risks.
• Generate reports on client security posture, vulnerabilities, deployments, incidents, and configuration reviews.
• Create and sustain dashboards and performance metrics.
• Present findings to client technical teams and leadership.
• Contribute insights, reusable report content, and technical standards.
• 3–5 years of practical experience in security engineering, security operations, IT infrastructure with a security focus, or a similar technical security role.
• Proven experience in deploying and configuring security tools in production settings.
• Proficiency across several areas, including Endpoint Detection and Response (EDR/XDR), SIEM and log management platforms, vulnerability management and scanning platforms, email security and anti-phishing controls, identity and access management (including MFA and conditional access), and cloud security posture management with at least one major cloud provider.
• Strong foundational knowledge in networking (TCP/IP, DNS, routing, firewalls, proxies) and operating systems (Windows and Linux administration).
• Scripting or automation skills in PowerShell, Python, or Bash, including work involving API-based integration.
• Solid understanding of vulnerability management concepts: CVSS, exploitability, prioritization, compensating controls, and risk acceptance.
• Excellent technical writing skills with a portfolio of documentation or reports authored personally.
• Comfortable in client-facing environments.
• Capable of managing multiple internal and client workstreams while communicating status proactively.
• Authorization to work in the United States without sponsorship.
• Willingness to travel to client sites as needed.
• Ability to pass a background check and any client-specific screening necessary for privileged access.
• Certifications required for maintaining partner or platform status are expected to be obtained within the first twelve months.
• Employment is contingent upon satisfactory completion of a background check and execution of confidentiality, intellectual property, and non-solicitation agreements.
• Medical coverage with the employer covering 75% of employee premiums.
• 401(k) plan with a 4% company match.
• Unlimited paid time off (PTO).
• Paid holidays.
• Kalosys provides funding for certifications and vendor training relevant to the role.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.