Security Engineer

Kalosys, LLC•Las Vegas, NV
•$125,000 - $150,000•Remote

About The Position

Kalosys is seeking a hands-on Security Engineer who can operate confidently on both sides of our business: hardening and running our own internal security stack, and deploying, configuring, and tuning security tooling inside client environments. This is a dual-mandate engineering role — part platform engineer, part consultant. The engineer in this seat is responsible for making security tools work correctly, not merely installing them. That means designing sound configurations, validating that telemetry is complete and accurate, tuning out noise, integrating tooling into monitoring and ticketing workflows, and then translating what the tools reveal into written reports that clients and internal leadership can act on. Strong technical execution paired with clear written communication is the core requirement. You will work across a broad, multi-vendor toolset — endpoint detection and response, SIEM and log pipelines, vulnerability management, email and identity security, and cloud security posture — and you will be expected to become genuinely proficient in each rather than superficially familiar. Kalosys is an AI-native consulting firm. Automation and AI-assisted analysis are not optional enhancements here; they are how we deliver at the quality and speed our clients expect from a team of our size. You will be expected to use and extend our internal automation and AI tooling in your daily engineering and reporting work, and to apply the same validation discipline to AI-assisted output that you apply to a scanner finding.

Requirements

  • 3–5 years of hands-on experience in security engineering, security operations, IT infrastructure with a security focus, or a comparable technical security role.
  • Demonstrated experience deploying and configuring security tooling in production environments — not solely operating tools that someone else configured.
  • Working proficiency across several of the following categories: Endpoint detection and response (EDR/XDR), SIEM and log management platforms, Vulnerability management and scanning platforms, Email security and anti-phishing controls, Identity and access management, including MFA and conditional access, Cloud security posture management across at least one major cloud provider
  • Solid fundamentals in networking (TCP/IP, DNS, routing, firewalls, proxies) and operating systems (Windows and Linux administration).
  • Scripting or automation capability in PowerShell, Python, or Bash, including API-based integration work.
  • Practical understanding of vulnerability management concepts: CVSS, exploitability, prioritization, compensating controls, and risk acceptance.
  • Strong technical writing skills with a portfolio of documentation or reports you personally authored.
  • Comfort in client-facing settings: composed under scrutiny, clear under pressure, and able to say “I will confirm and follow up” rather than improvising an answer.
  • Ability to manage concurrent internal and client workstreams and communicate status without prompting.
  • Authorization to work in the United States without sponsorship, and the ability to travel to client sites as required.
  • Ability to pass a background check and any client-specific screening required for privileged access to client environments.

Nice To Haves

  • Prior experience at an MSSP, MSP, or security consultancy delivering to multiple concurrent clients.
  • Experience with Microsoft security tooling (Defender suite, Sentinel, Entra ID, Intune, Purview) or comparable enterprise stacks.
  • Familiarity with recognized frameworks and standards: NIST CSF, NIST 800-53, CIS Controls, ISO 27001, MITRE ATT&CK.
  • Exposure to regulated environments and their reporting expectations (HIPAA, PCI DSS, CMMC, SOC 2).
  • Working knowledge of Canadian privacy obligations (PIPEDA and provincial equivalents) as they apply to client data handling.
  • Infrastructure-as-code or configuration-management experience (Terraform, Ansible, or similar).
  • Experience building reporting automation or dashboards from security tool APIs.
  • Demonstrated use of AI tooling to accelerate engineering, analysis, or reporting work, with sound judgment about where it is and is not appropriate.
  • Certifications such as Security+, CySA+, GSEC, GCIH, GCIA, SSCP, OSCP, or vendor platform certifications.
  • Bachelor’s degree in a technical field or equivalent demonstrated experience.
  • Kalosys funds certification and vendor training relevant to the role. Certifications required to maintain partner or platform status are expected to be obtained within the first twelve months.

Responsibilities

  • Deploy, configure, maintain, and upgrade Kalosys internal security platforms across endpoint, network, identity, email, and cloud domains.
  • Own tool health: agent coverage, log ingestion continuity, license utilization, integration status, and version currency. Detect and remediate coverage gaps before they become blind spots.
  • Build and tune detection content, alert rules, correlation logic, and suppression policies to maximize signal and minimize analyst fatigue.
  • Integrate security tooling with the broader operational stack — SIEM, ticketing, asset inventory, identity providers, and notification channels — using native connectors and APIs.
  • Administer vulnerability scanning across internal infrastructure: scan configuration, credentialed scanning, authenticated coverage validation, and remediation tracking.
  • Harden internal systems against recognized baselines (CIS Benchmarks, vendor hardening guides) and document deviations with compensating controls.
  • Automate repetitive engineering and reporting tasks using scripting (PowerShell, Python, or Bash) and vendor APIs.
  • Operate in accordance with the Kalosys internal policy set, including the Master Information Security Policy (POL-SEC-001), and contribute revisions where engineering practice and policy diverge.
  • Maintain accurate, current runbooks, configuration standards, and architecture documentation for every tool you own.
  • Serve as the technical implementation lead for client security tooling engagements — scoping, deployment planning, configuration, validation, tuning, and handoff.
  • Configure client-side security platforms to Kalosys standards while accommodating legitimate environmental and business constraints; document every deviation and its rationale.
  • Onboard client log sources and telemetry into monitoring pipelines and verify end-to-end data quality, parsing accuracy, and detection coverage after onboarding.
  • Run vulnerability assessments and configuration reviews in client environments and validate findings before they reach the client to eliminate false positives.
  • Participate in client-facing technical calls: requirements gathering, deployment coordination, findings walkthroughs, and remediation guidance. Explain technical risk in terms the client’s stakeholders can act on.
  • Support client remediation efforts by providing specific, testable, prioritized guidance — not generic vendor advice.
  • Deliver engagements sourced through Kalosys channel partners, adapting to partner-defined scope, branding, and communication protocols while holding to Kalosys technical standards.
  • Support engagements that intersect the Kalosys Business Resilience practice, ensuring security tooling, monitoring, and recovery architecture are designed as one system rather than in isolation.
  • Contribute to delivery quality and repeatability by improving templates, standard configurations, deployment checklists, and reusable automation.
  • Track engagement tasks, deliverable status, and time against scope daily, meet the billable utilization target for the role, and escalate risks to schedule or scope early.
  • Produce recurring and ad-hoc client deliverables, including: Monthly and quarterly security posture and service reports, Vulnerability assessment and remediation-progress reports, Tool deployment, configuration, and as-built documentation, Incident and investigation summaries, Configuration review and hardening gap assessments.
  • Write for two audiences in every deliverable: a technical audience that needs precise detail and reproducible evidence, and an executive audience that needs risk, impact, and a clear recommendation.
  • Build and maintain dashboards and metrics that make posture, coverage, and remediation velocity visible without manual assembly.
  • Ensure every report is accurate, internally consistent, evidence-backed, and free of unvalidated findings. Accuracy is a non-negotiable standard of this role.
  • Present findings directly to client technical teams and, where required, to client leadership.
  • Contribute to internal knowledge assets: lessons learned, reusable report content, and technical standards.

Benefits

  • Medical coverage (employer pays 75% of employee premiums)
  • 401(k) with 4% company match
  • Unlimited PTO
  • Paid holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service