An application made for this job — a tailored resume and cover letter that speak straight to the posting.
PingWind is seeking a Security Engineer (SIEM/EL3) to design, implement, and maintain robust monitoring and logging for IAM systems in a remote setup. The role emphasizes EL3 logging, SIEM, and compliance to safeguard sensitive identity data while enabling rapid threat detection.
Required qualifications include expertise in SIEM, NIST RMF, FISMA, cryptographic standards (AES-256, TLS), and POA&Ms management. Collaboration with security, operations, and development teams is essential.
Position Description
The Security Engineer (SIEM / EL3 Logging) is responsible for designing, implementing, and maintaining robust security monitoring, logging, and incident response capabilities for the FSA IAM systems. This role ensures advanced event logging (EL3), Security Event and Incident Management (SIEM), and overall security compliance to protect sensitive identity data and support rapid threat detection.
Location: Remote
Required Clearance: Public Trust
Required Education: Bachelors
Required Experience: 8 years
Position Description
The Security Engineer (SIEM / EL3 Logging) is responsible for designing, implementing, and maintaining robust security monitoring, logging, and incident response capabilities for the FSA IAM systems. This role ensures advanced event logging (EL3), Security Event and Incident Management (SIEM), and overall security compliance to protect sensitive identity data and support rapid threat detection.
Responsibilities
The Security Engineer ensures the IAM solution meets Event Log Management and Advanced Logging (EL3) requirements, proper encryption standards for data at rest (AES-256 with SHA-256) and data in transit (latest TLS protocols), and FISMA compliance. They lead Security Incident Management, manage remediation efforts for security findings, support Ongoing Security Assessments (OSA), and maintain Plan of Action and Milestones (POA&M) in CSAM. Key responsibilities include implementing and enhancing SIEM processes to detect and respond to threats in real time, managing security controls and inheritance statements, addressing Continuous Diagnostics and Monitoring (CDM) results, handling Common Vulnerabilities and Exposures (CVE) findings, tracking remediation efforts, and ensuring the Cybersecurity Framework (CSF) scorecard meets or exceeds required ratings. The role also supports broader compliance activities, including supply chain risk management, data planning, federal records and CUI handling, IT accessibility (Section 508), technology business management reporting, and project, risk, and schedule documentation needed to sustain the Authority to Operate (ATO). They provide security expertise for identity verification, account recovery processes, and overall environment protection.
Required Qualifications