> Markdown version of [/jobs/ext/3040186-siem-modernization-security-engineer](https://www.wearedevelopers.com/jobs/ext/3040186-siem-modernization-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SIEM Modernization Security Engineer - **Company:** The Informatics Applications Group, Inc. - **Location:** Bethesda, MD, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cloud Computing, System Configuration, Data Normalization, Query Languages, Identity and Access Management, Issue Tracking Systems, Routing, Kusto Query Language, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Data Logging, SC Clearance, Microsoft Sentinel, Splunk, Plan of Action and Milestones - **Published:** September 23, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9184987/siem-modernization-security-engineer ## About the Role * 3-7 years of hands-on experience in cybersecurity engineering, specifically focusing on SIEM engineering, log routing, telemetry validation, and vulnerability management. Operational experience configuring and maintaining enterprise SIEM platforms such as Splunk Enterprise, Splunk Cloud, Microsoft Sentinel, or Google Chronicle. * Proven ability to troubleshoot log transport connectivity, parser failures, agent misconfigurations, and data normalization issues across diverse OS environments. * Hands-on experience developing and deploying configuration artifacts, including deployment scripts, GPOs, and hardened agent configurations. * Working knowledge of Federal and DoD compliance frameworks, including DISA STIGs, Risk Management Framework (RMF), and Zero Trust logging requirements. Demonstrated experience assisting with POA&Ms and patching workflows. * Strong technical writing skills to author operational SOPs, combined with the ability to provide over-the-shoulder mentoring and practical training to Tier 1 operational personnel. * IAT/IAM Level III Certification * Secret Clearance ## Description TIAG is now hiring a SIEM Modernization Security Engineer to support a modernization and transition initiative for a Uniformed Services University (USU) enclave. This position reports to our Bethesda, MD location in a Hybrid capacity. The Security Engineer will work support the direction of the Lead SIEM Architect & provide ground-level engineering, technical enablement, and Tier 2 support to successfully transition approximately 150 on-premise and cloud-hosted servers from a legacy Splunk Enterprise environment to a modern, Government-selected cloud-native SIEM platform. The Engineer will actively enable this transition, validate telemetry, develop technical artifacts, and assist hands-on with implementation tasks where needed to ensure the project stays on track. Primary Responsibilities * Assist the Lead SIEM Architect in auditing the current USU Splunk Enterprise environment to evaluate onboarded log sources, telemetry coverage, ingestion methods, and parser configurations. * Compare Splunk Cloud, Microsoft Sentinel, and Google Chronicle to identify the best SIEM solution for USU's networks, ensuring it properly protects and handles their data. * Implement Security Configuration Baselines on the chosen platform to ensure compliance with DoD cybersecurity requirements, DISA STIG guidance, RMF controls, and Zero Trust principles. * Ensure system vulnerabilities across the SIEM platform and associated infrastructure are proactively identified, tracked, and patched in a timely manner to maintain a secure operating environment. * Assist in navigating the Risk Management Framework (RMF) process, ensuring that the selected SIEM solution and integrated systems align with required RMF controls and USU security policies. * Assist with the development, management, and resolution of Plan of Action and Milestones (POA&Ms) for any identified security deficiencies or configuration gaps discovered during the transition. * Develop, test, and package validated Reference Implementations for all supported OS categories using templates, scripts, Group Policy Objects (GPOs), and agent profiles. * Work alongside GFL administrators to actively assist in the hands-on onboarding of 150+ enterprise assets into the selected cloud-native SIEM environment. * Provide daily Tier 2 technical troubleshooting to resolve ingestion failures, parser inconsistencies, configuration errors, and transport connectivity issues encountered during transition. * Perform structured telemetry validation by testing at least one representative server for each supported operating system flavor to "prove the pipe". * Confirm end-to-end event generation, transport, ingestion, parsing, normalization, and visibility within the selected SIEM platform. * Maintain a structured Tier 2 support process, including centralized ticket tracking, root cause analysis, and issue prioritization. * Author clear, practical, step-by-step Standard Operating Procedures (SOPs) tailored for Tier 1 GFL SIEM administrators covering log onboarding, telemetry validation, and health monitoring. * Document standardized alert tuning processes, threshold configurations, and event categorization guidelines to improve the SOC's signal-to-noise ratio. * Support the Lead Architect in delivering targeted "delta" training on the selected SIEM platform's specific capabilities, such as query languages (KQL or UDM), telemetry management, and search optimization. * Facilitate hands-on operational demonstrations, guided troubleshooting sessions, and practical exercises for GFL administrators to reinforce learning and validate operational readiness. ## Related Videos - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A Technical Introduction to Bitcoin's 2nd Layer- The Lightning Network](https://www.wearedevelopers.com/videos/15-a-technical-introduction-to-bitcoin-s-2nd-layer-the-lightning-network) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)