IT Cybersecurity Project Lead
Job Description
KBR is seeking an IT Cybersecurity Project Lead to help implement, operate, monitor, and continuously improve cybersecurity controls across both IT and OT environments. This onsite role in the United States supports security operations, incident response, vulnerability management, endpoint and identity security, tool administration, compliance support, and recurring reporting.
What you’ll do
- Monitor security events and alerts from security monitoring platforms, investigate suspicious activity, and escalate critical findings.
- Lead incident triage and support containment, eradication, and recovery, including participation in on-call incident response activities where required.
- Support cyber incident response and forensic investigations, maintaining incident records and documenting lessons learned.
- Administer and maintain SIEM platforms, including log source monitoring to ensure adequate security event coverage.
- Develop and tune detection rules and alert thresholds, create use cases and threat detection analytics, and support threat hunting activities.
- Manage and operate EDR/XDR solutions and endpoint protection platforms such as Microsoft Defender, CrowdStrike, Trend Micro, or equivalents.
- Support endpoint threat investigations and ensure security agents remain operational and compliant.
- Perform vulnerability scanning, analyze vulnerability assessment reports, prioritize remediation by risk, and coordinate remediation with infrastructure and application teams.
- Monitor vulnerability closure, produce vulnerability metrics and reporting, and support privileged access management (PAM) including privileged account usage monitoring and access review support.
- Support identity governance activities and apply least-privilege principles, including compliance-aligned operational evidence.
- Administer additional cybersecurity technologies including PAM, vulnerability management platforms, email security solutions, web security gateways, security monitoring platforms, and threat intelligence platforms.
- Maintain health and performance of cybersecurity systems, support technology upgrades and deployment activities, and review threat intelligence feeds for organizational relevance.
- Recommend protective measures and compensating controls, support secure network segmentation initiatives, and assist with design and implementation of cybersecurity policies and standards.
- Support IEC 62443-aligned control implementation, monitor OT security events and vulnerabilities, participate in OT risk assessments, and support cybersecurity monitoring of OT environments.
- Support audits and assessments, maintain operational evidence, and support NIST, ISO 27001, and IEC 62443 requirements.
- Produce operational cybersecurity reports, maintain dashboards and KPI reporting, and provide regular status updates to the Head of Cybersecurity.
Required qualifications
- Bachelor’s Degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline.
- Minimum 3-5 years of cybersecurity operations experience.
- Experience supporting enterprise security technologies.
- Experience investigating cybersecurity incidents.
- Experience with security monitoring and vulnerability management.
Tools and frameworks you may work with
- SIEM: Splunk, QRadar, Microsoft Sentinel
- EDR/XDR & endpoint security: Microsoft Defender XDR, Microsoft Defender, CrowdStrike, Trend Micro
- Vulnerability management: Tenable, Qualys, Rapid7
- PAM & identity: Active Directory, Entra ID (Azure AD)
- Security frameworks: NIST Cybersecurity Framework (CSF), NIST SP 800-53, CIS Critical Security Controls, MITRE ATT&CK Framework, Cyber Kill Chain
- Cloud and platforms: Microsoft Azure, Microsoft 365 Security, AWS Security Fundamentals, Windows Server, Linux Administration
- OT/ICS context: Industrial Control Systems (ICS), SCADA Security
- Standards and OT security alignment: IEC 62443
Preferred certifications
- One or more of: CompTIA Security+, CompTIA CySA+
- One or more of: Microsoft Security Certifications
- One or more of: SC-200 Security Operations Analyst
- One or more of: CISSP Associate, GIAC Certifications (including GSEC), SSCP, CEH
Key skills and deliverables
- Security operations skills: Incident Response, Threat Detection, Threat Hunting, Security Monitoring, Digital Forensics Fundamentals
- Infrastructure security skills: Windows Server, Active Directory, Entra ID (Azure AD), Linux Administration, Network Security, Firewalls, VPN Technologies
- Cloud security skills: Microsoft Azure, Microsoft 365 Security, AWS Security Fundamentals
- OT security skills (preferred): ICS, SCADA Security, IEC 62443, OT Network Security
- Deliverables: Security Incident Reports, Vulnerability Assessment Reports, SIEM Monitoring Dashboards, Threat Intelligence Briefings, Security Control Compliance Reports, Security Monitoring Use Cases, Security Technology Health Reports, Privileged Access Monitoring Reports, and Cybersecurity KPIs and Metrics