> Markdown version of [/jobs/ext/2222500-security-engineer-siem-el3-logging](https://www.wearedevelopers.com/jobs/ext/2222500-security-engineer-siem-el3-logging). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer (SIEM / EL3 Logging) - **Company:** PINGWIND INC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $93,000.0 - $128,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Event Logging, Identity and Access Management, Intrusion Detection and Prevention, Microsoft Office, Security Information and Event Management, Data Logging, Plan of Action and Milestones - **Published:** August 25, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9114112/security-engineer-siem-el3-logging ## About the Role Strong expertise in SIEM tools, advanced logging (EL3), and security event management - Deep knowledge of NIST RMF, FISMA, FedRAMP, and CSAM processes - Experience with security remediation, POA&M management, and vulnerability tracking - Familiarity with data encryption standards (AES-256, TLS) and logging requirements - Ability to analyze security events, logs, and alerts for threat detection - Excellent documentation and compliance tracking skills - Strong problem-solving and analytical abilities under pressure - Effective collaboration with security, operations, and development teams - Understanding of federal cybersecurity policies and identity management security - Proficiency with security tools, Microsoft Office, and compliance platforms ## Description The Security Engineer (SIEM / EL3 Logging) is responsible for designing, implementing, and maintaining robust security monitoring, logging, and incident response capabilities for the FSA IAM systems. This role ensures advanced event logging (EL3), Security Event and Incident Management (SIEM), and overall security compliance to protect sensitive identity data and support rapid threat detection., The Security Engineer ensures the IAM solution meets Event Log Management and Advanced Logging (EL3) requirements, proper encryption standards for data at rest (AES-256 with SHA-256) and data in transit (latest TLS protocols), and FISMA compliance. They lead Security Incident Management, manage remediation efforts for security findings, support Ongoing Security Assessments (OSA), and maintain Plan of Action and Milestones (POA&M) in CSAM. Key responsibilities include implementing and enhancing SIEM processes to detect and respond to threats in real time, managing security controls and inheritance statements, addressing Continuous Diagnostics and Monitoring (CDM) results, handling Common Vulnerabilities and Exposures (CVE) findings, tracking remediation efforts, and ensuring the Cybersecurity Framework (CSF) scorecard meets or exceeds required ratings. The role also supports broader compliance activities, including supply chain risk management, data planning, federal records and CUI handling, IT accessibility (Section 508), technology business management reporting, and project, risk, and schedule documentation needed to sustain the Authority to Operate (ATO). They provide security expertise for identity verification, account recovery processes, and overall environment protection. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Is your backend a hodgepodge of queues, event stores and cron jobs? Durable Execution to the Rescue.](https://www.wearedevelopers.com/videos/744-is-your-backend-a-hodgepodge-of-queues-event-stores-and-cron-jobs-durable-execution-to-the-rescue) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)