Enter a job title or keyword

SIEM Engineer

EPAM Systems


Job Location:

Prague - Czech Republic

Monthly Salary: Not provided by the employer
Posted: 18 September 2026 (Yesterday)
Application Deadline: 16 December 2026
Vacancies: 1 Vacancy

Job Summary

We are looking for a SIEM Engineer to design operate and continuously improve enterprise security logging and monitoring capabilities. The role ensures reliable high-quality telemetry for threat detection incident response digital forensics and compliance while optimizing platform performance scalability and cost.

The role follows a hybrid working model with three days per week based in the office (Tuesday Wednesday Thursday).

Responsibilities
  • Engineer configure maintain and monitor the SIEM platform collectors connectors and supporting infrastructure
  • Onboard security-relevant logs from identity endpoint network cloud business applications databases and other environments
  • Design reliable data pipelines; develop parsing normalization transformation timestamp handling and contextual enrichment
  • Monitor telemetry health and resolve missing sources ingestion delays volume anomalies schema changes and connector failures
  • Support detection engineering with required fields correlation logic threat intelligence MITRE ATT&CK mapping and testing
  • Optimize ingestion storage tiers retention query performance licensing and cost without reducing required security visibility
  • Maintain architecture diagrams log-source inventory onboarding standards runbooks ownership and configuration records
  • Support SOC investigations threat hunting incident response forensic data extraction audits and major incident resolution
  • Coordinate logging requirements and remediation with IT Cloud Network IAM Application OT vendors and service providers
Requirements
  • Practical experience in SIEM engineering security monitoring log management or security platform engineering
  • Hands-on expertise with an enterprise SIEM preferably Microsoft Sentinel; Splunk QRadar Elastic or Google SecOps are also relevant
  • Experience with log onboarding and troubleshooting across Windows Linux Microsoft Entra ID cloud network endpoint and application environments
  • Proficiency in KQL/SPL/SQL or a comparable query language including analytics and performance troubleshooting
  • Knowledge of syslog APIs agents collectors event streaming common schemas parsing normalization and enrichment
  • Scripting or automation experience using PowerShell Python REST APIs Git CI/CD or infrastructure-as-code
  • Understanding of detection engineering incident response digital forensics networking security controls and data protection
  • Strong analytical documentation stakeholder communication and end-to-end ownership skills; professional English required
Nice to have
  • SIEM and security data lake architecture; SOAR and detection-as-code practices
  • Experience in regulated critical-infrastructure energy or OT environments
  • Knowledge of NIS2 ISO/IEC 27001 IEC 62443 and security log retention requirements
  • Relevant Microsoft Splunk GIAC CISSP CISM or equivalent certification

Required Experience:

Senior IC