Type: Full-time | Compensation: $125,000-$150,000 base salary | Benefits: Medical coverage (employer pays 75% of employee premiums) • 401(k) with 4% company match • Unlimited PTO • Paid holidays
Pay Transparency: The compensation range listed above reflects the good-faith salary range for this role at the time of posting. Actual base pay offered will depend on factors such as the candidate's experience, skills, and location, and may vary where required by applicable state or local pay transparency laws.
Location: Remote - United States, in states where Kalosys is registered as an employer (eligibility confirmed during the hiring process; we are unable to hire residents of California at this time). Travel: occasional client site travel (up to 15%)
Reports to: Chief Information Security Officer
Position Summary
Kalosys is seeking a hands-on Security Engineer who can operate confidently on both sides of our business: hardening and running our own internal security stack, and deploying, configuring, and tuning security tooling inside client environments. This is a dual-mandate engineering role - part platform engineer, part consultant.
The engineer in this seat is responsible for making security tools work correctly, not merely installing them. That means designing sound configurations, validating that telemetry is complete and accurate, tuning out noise, integrating tooling into monitoring and ticketing workflows, and then translating what the tools reveal into written reports that clients and internal leadership can act on. Strong technical execution paired with clear written communication is the core requirement.
You will work across a broad, multi-vendor toolset - endpoint detection and response, SIEM and log pipelines, vulnerability management, email and identity security, and cloud security posture - and you will be expected to become genuinely proficient in each rather than superficially familiar.
Kalosys is an AI-native consulting firm. Automation and AI-assisted analysis are not optional enhancements here; they are how we deliver at the quality and speed our clients expect from a team of our size. You will be expected to use and extend our internal automation and AI tooling in your daily engineering and reporting work, and to apply the same validation discipline to AI-assisted output that you apply to a scanner finding.
Key Responsibilities
Internal Security Tooling
- Deploy, configure, maintain, and upgrade Kalosys internal security platforms across endpoint, network, identity, email, and cloud domains.
- Own tool health: agent coverage, log ingestion continuity, license utilization, integration status, and version currency. Detect and remediate coverage gaps before they become blind spots.
- Build and tune detection content, alert rules, correlation logic, and suppression policies to maximize signal and minimize analyst fatigue.
- Integrate security tooling with the broader operational stack - SIEM, ticketing, asset inventory, identity providers, and notification channels - using native connectors and APIs.
- Administer vulnerability scanning across internal infrastructure: scan configuration, credentialed scanning, authenticated coverage validation, and remediation tracking.
- Harden internal systems against recognized baselines (CIS Benchmarks, vendor hardening guides) and document deviations with compensating controls.
- Automate repetitive engineering and reporting tasks using scripting (PowerShell, Python, or Bash) and vendor APIs.
- Operate in accordance with the Kalosys internal policy set, including the Master Information Security Policy (POL-SEC-001), and contribute revisions where engineering practice and policy diverge.
- Maintain accurate, current runbooks, configuration standards, and architecture documentation for every tool you own.
Client Security Tooling & Delivery
- Serve as the technical implementation lead for client security tooling engagements - scoping, deployment planning, configuration, validation, tuning, and handoff.
- Configure client-side security platforms to Kalosys standards while accommodating legitimate environmental and business constraints; document every deviation and its rationale.
- Onboard client log sources and telemetry into monitoring pipelines and verify end-to-end data quality, parsing accuracy, and detection coverage after onboarding.
- Run vulnerability assessments and configuration reviews in client environments and validate findings before they reach the client to eliminate false positives.
- Participate in client-facing technical calls: requirements gathering, deployment coordination, findings walkthroughs, and remediation guidance. Explain technical risk in terms the client's stakeholders can act on.
- Support client remediation efforts by providing specific, testable, prioritized guidance - not generic vendor advice.
- Deliver engagements sourced through Kalosys channel partners, adapting to partner-defined scope, branding, and communication protocols while holding to Kalosys technical standards.
- Support engagements that intersect the Kalosys Business Resilience practice, ensuring security tooling, monitoring, and recovery architecture are designed as one system rather than in isolation.
- Contribute to delivery quality and repeatability by improving templates, standard configurations, deployment checklists, and reusable automation.
- Track engagement tasks, deliverable status, and time against scope daily, meet the billable utilization target for the role, and escalate risks to schedule or scope early.
Reporting & Documentation
Produce recurring and ad-hoc client deliverables, including:
- Monthly and quarterly security posture and service reports
- Vulnerability assessment and remediation-progress reports
- Tool deployment, configuration, and as-built documentation
- Incident and investigation summaries
- Configuration review and hardening gap assessments
- Write for two audiences in every deliverable: a technical audience that needs precise detail and reproducible evidence, and an executive audience that needs risk, impact, and a clear recommendation.
- Build and maintain dashboards and metrics that make posture, coverage, and remediation velocity visible without manual assembly.
- Ensure every report is accurate, internally consistent, evidence-backed, and free of unvalidated findings. Accuracy is a non-negotiable standard of this role.
- Present findings directly to client technical teams and, where required, to client leadership.
- Contribute to internal knowledge assets: lessons learned, reusable report content, and technical standards.
Required Qualifications
- 3-5 years of hands-on experience in security engineering, security operations, IT infrastructure with a security focus, or a comparable technical security role.
- Demonstrated experience deploying and configuring security tooling in production environments - not solely operating tools that someone else configured.
- Working proficiency across several of the following categories:
- Endpoint detection and response (EDR/XDR)
- SIEM and log management platforms
- Vulnerability management and scanning platforms
- Email security and anti-phishing controls
- Identity and access management, including MFA and conditional access
- Cloud security posture management across at least one major cloud provider
- Solid fundamentals in networking (TCP/IP, DNS, routing, firewalls, proxies) and operating systems (Windows and Linux administration).
- Scripting or automation capability in PowerShell, Python, or Bash, including API-based integration work.
- Practical understanding of vulnerability management concepts: CVSS, exploitability, prioritization, compensating controls, and risk acceptance.
- Strong technical writing skills with a portfolio of documentation or reports you personally authored.
- Comfort in client-facing settings: composed under scrutiny, clear under pressure, and able to say "I will confirm and follow up" rather than improvising an answer.
- Ability to manage concurrent internal and client workstreams and communicate status without prompting.
- Authorization to work in the United States without sponsorship, and the ability to travel to client sites as required.
- Ability to pass a background check and any client-specific screening required for privileged access to client environments.
Preferred Qualifications
- Prior experience at an MSSP, MSP, or security consultancy delivering to multiple concurrent clients.
- Experience with Microsoft security tooling (Defender suite, Sentinel, Entra ID, Intune, Purview) or comparable enterprise stacks.
- Familiarity with recognized frameworks and standards: NIST CSF, NIST 800-53, CIS Controls, ISO 27001, MITRE ATT&CK.
- Exposure to regulated environments and their reporting expectations (HIPAA, PCI DSS, CMMC, SOC 2).
- Working knowledge of Canadian privacy obligations (PIPEDA and provincial equivalents) as they apply to client data handling.
- Infrastructure-as-code or configuration-management experience (Terraform, Ansible, or similar).
- Experience building reporting automation or dashboards from security tool APIs.
- Demonstrated use of AI tooling to accelerate engineering, analysis, or reporting work, with sound judgment about where it is and is not appropriate.
- Certifications such as Security+, CySA+, GSEC, GCIH, GCIA, SSCP, OSCP, or vendor platform certifications.
- Bachelor's degree in a technical field or equivalent demonstrated experience.
Kalosys funds certification and vendor training relevant to the role. Certifications required to maintain partner or platform status are expected to be obtained within the first twelve months.
Core Competencies
- Technical rigor - validates before reporting; does not pass unverified findings to a client.
- Ownership - treats assigned tools and engagements as personally owned, including their gaps.
- Clarity - writes and speaks so the reader knows what happened, why it matters, and what to do next.
- Client judgment - distinguishes between a technically ideal answer and the right answer for the client's constraints.
- Discipline - follows standards and documents deviations rather than quietly improvising.
- Curiosity - actively deepens platform expertise instead of stopping at working configurations.
Success Milestones
First 30 Days
- Onboarded to Kalosys systems, security policies, and delivery standards; completed access provisioning and required training.
- Shadowed at least two active client engagements and one recurring reporting cycle.
- Administering at least one assigned internal security platform under supervision.
First 90 Days
- Fully proficient in the Kalosys internal security stack and able to administer assigned platforms independently.
- Delivered internally reviewed client reports meeting Kalosys quality standards.
- Completed at least one client tooling deployment as implementation lead with oversight.
First Six Months
- Owns configuration and health for a defined set of internal and client security platforms.
- Leads client tooling engagements with minimal oversight, including client-facing calls.
- Delivers recurring client reporting on schedule with high accuracy and no rework.
- Meets the billable utilization target for the role.
- Has measurably improved at least one delivery process, standard configuration, or reporting workflow.
Career Path
This role sits on the Kalosys security engineering track. Progression to Senior Security Engineer is based on demonstrated platform ownership breadth, independent engagement leadership, quality of written deliverables, and contribution to reusable standards and automation - not tenure alone.
Working Conditions
- Primarily standard business hours aligned to client time zones.
- Occasional after-hours work for maintenance windows, deployments, or client incidents.
- Occasional travel to client sites.
Employment Terms & Eligibility
- This position is employed by Kalosys LLC, a Nevada limited liability company operating in the United States.
- Applicants must be authorized to work in the United States. Kalosys LLC does not provide visa sponsorship for this role.
- Employment is contingent on satisfactory completion of a background check and on execution of the Kalosys confidentiality, intellectual property, and non-solicitation agreements.