SIEM Engineer
Job Location:
Prague - Czech Republic
Monthly Salary:
Not provided by the employer
Posted:
18 September 2026 (Yesterday)
Application Deadline:
16 December 2026
Vacancies:
1 Vacancy
Job Summary
We are looking for a SIEM Engineer to design operate and continuously improve enterprise security logging and monitoring capabilities. The role ensures reliable high-quality telemetry for threat detection incident response digital forensics and compliance while optimizing platform performance scalability and cost.
The role follows a hybrid working model with three days per week based in the office (Tuesday Wednesday Thursday).
Responsibilities
- Engineer configure maintain and monitor the SIEM platform collectors connectors and supporting infrastructure
- Onboard security-relevant logs from identity endpoint network cloud business applications databases and other environments
- Design reliable data pipelines; develop parsing normalization transformation timestamp handling and contextual enrichment
- Monitor telemetry health and resolve missing sources ingestion delays volume anomalies schema changes and connector failures
- Support detection engineering with required fields correlation logic threat intelligence MITRE ATT&CK mapping and testing
- Optimize ingestion storage tiers retention query performance licensing and cost without reducing required security visibility
- Maintain architecture diagrams log-source inventory onboarding standards runbooks ownership and configuration records
- Support SOC investigations threat hunting incident response forensic data extraction audits and major incident resolution
- Coordinate logging requirements and remediation with IT Cloud Network IAM Application OT vendors and service providers
Requirements
- Practical experience in SIEM engineering security monitoring log management or security platform engineering
- Hands-on expertise with an enterprise SIEM preferably Microsoft Sentinel; Splunk QRadar Elastic or Google SecOps are also relevant
- Experience with log onboarding and troubleshooting across Windows Linux Microsoft Entra ID cloud network endpoint and application environments
- Proficiency in KQL/SPL/SQL or a comparable query language including analytics and performance troubleshooting
- Knowledge of syslog APIs agents collectors event streaming common schemas parsing normalization and enrichment
- Scripting or automation experience using PowerShell Python REST APIs Git CI/CD or infrastructure-as-code
- Understanding of detection engineering incident response digital forensics networking security controls and data protection
- Strong analytical documentation stakeholder communication and end-to-end ownership skills; professional English required
Nice to have
- SIEM and security data lake architecture; SOAR and detection-as-code practices
- Experience in regulated critical-infrastructure energy or OT environments
- Knowledge of NIS2 ISO/IEC 27001 IEC 62443 and security log retention requirements
- Relevant Microsoft Splunk GIAC CISSP CISM or equivalent certification
Required Experience:
Senior IC