Security Engineer (SIEM / EL3 Logging)

PINGWIND INC
United States
12 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$93,000.0 - $128,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Event Logging Identity and Access Management Intrusion Detection and Prevention Microsoft Office Security Information and Event Management Data Logging Plan of Action and Milestones

Job description

The Security Engineer (SIEM / EL3 Logging) is responsible for designing, implementing, and maintaining robust security monitoring, logging, and incident response capabilities for the FSA IAM systems. This role ensures advanced event logging (EL3), Security Event and Incident Management (SIEM), and overall security compliance to protect sensitive identity data and support rapid threat detection., The Security Engineer ensures the IAM solution meets Event Log Management and Advanced Logging (EL3) requirements, proper encryption standards for data at rest (AES-256 with SHA-256) and data in transit (latest TLS protocols), and FISMA compliance. They lead Security Incident Management, manage remediation efforts for security findings, support Ongoing Security Assessments (OSA), and maintain Plan of Action and Milestones (POA&M) in CSAM. Key responsibilities include implementing and enhancing SIEM processes to detect and respond to threats in real time, managing security controls and inheritance statements, addressing Continuous Diagnostics and Monitoring (CDM) results, handling Common Vulnerabilities and Exposures (CVE) findings, tracking remediation efforts, and ensuring the Cybersecurity Framework (CSF) scorecard meets or exceeds required ratings. The role also supports broader compliance activities, including supply chain risk management, data planning, federal records and CUI handling, IT accessibility (Section 508), technology business management reporting, and project, risk, and schedule documentation needed to sustain the Authority to Operate (ATO). They provide security expertise for identity verification, account recovery processes, and overall environment protection.

Requirements

Strong expertise in SIEM tools, advanced logging (EL3), and security event management

  • Deep knowledge of NIST RMF, FISMA, FedRAMP, and CSAM processes
  • Experience with security remediation, POA&M management, and vulnerability tracking
  • Familiarity with data encryption standards (AES-256, TLS) and logging requirements
  • Ability to analyze security events, logs, and alerts for threat detection
  • Excellent documentation and compliance tracking skills
  • Strong problem-solving and analytical abilities under pressure
  • Effective collaboration with security, operations, and development teams
  • Understanding of federal cybersecurity policies and identity management security
  • Proficiency with security tools, Microsoft Office, and compliance platforms

Benefits & conditions

  • Eleven Federal Holidays
  • Paid Time Off accrued each pay period
  • Parental Leave
  • Three medical plan choices with generous employer contribution
  • Dental and Vision Insurance
  • Company paid Short-Term and Long-Term Disability
  • Company paid Life and AD&D Insurance
  • 401k with competitive matching and vesting schedule
  • Continuing education assistance
  • Short Term / Long Term Disability & Life Insurance
  • Medical, Dependent Care and Commuter Flexible Spending Accounts
  • Employee Assistance Program
  • Wellness benefits include Calm Health app and WellHub gym subsidy (formerly GymPass)
  • 529 College Savings Plan
  • Legal Insurance
  • Pet Insurance

Salary Range

$93k-$128K

The pay range for this job is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) job responsibilities, education, certifications, experience, as well as internal equity mapping and alignment with market data, or other applicable laws.

About the company

About PingWind

PingWind is focused on delivering outstanding services to the federal government. We have extensive experience in the fields of cybersecurity, development, IT infrastructure, supply chain management and other professional services such as system design and continuous improvement. PingWind is an SBA certified Service-Disabled Veteran-Owned Small Business (SDVOSB) with offices in Northern Virginia and Huntsville AL. www.PingWind.com

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

2:22 min

Implementing durable execution using event logs and replay

Maxim Fateev Maxim Fateev · World Congress 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

3:09 min

Managing current state with CQRS and data projections

Allard Buijze · World Congress 2021

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

Videos

See all

Related articles

See all