openqareer

SIEM Engineer

EPAM Systems · Praha

# SIEM Engineer **EPAM Systems** · Praha · `On-site` 🕒 **Статус:** *Опубликовано: 5 дней назад* · *Источник: Indeed* --- ### About the Role We are looking for a SIEM Engineer to design, operate, and continuously improve enterprise security logging and monitoring capabilities. The role ensures reliable, high-quality telemetry for threat detection, incident response, digital forensics, and compliance, while optimizing platform performance, scalability, and cost. The role follows a hybrid working model, with three days per week based in the office (Tuesday, Wednesday, Thursday). The remote work option is available to candidates residing and working within the Czech Republic. Responsibilities Engineer, configure, maintain, and monitor the SIEM platform, collectors, connectors, and supporting infrastructure Onboard security-relevant logs from identity, endpoint, network, cloud, business applications, databases, and other environments Design reliable data pipelines; develop parsing, normalization, transformation, timestamp handling, and contextual enrichment Monitor telemetry health and resolve missing sources, ingestion delays, volume anomalies, schema changes, and connector failures Support detection engineering with required fields, correlation logic, threat intelligence, MITRE ATT&CK mapping, and testing Optimize ingestion, storage tiers, retention, query performance, licensing, and cost without reducing required security visibility Maintain architecture diagrams, log-source inventory, onboarding standards, runbooks, ownership, and configuration records Support SOC investigations, threat hunting, incident response, forensic data extraction, audits, and major incident resolution Coordinate logging requirements and remediation with IT, Cloud, Network, IAM, Application, OT, vendors, and service providers Requirements Practical experience in SIEM engineering, security monitoring, log management, or security platform engineering Hands-on expertise with an enterprise SIEM, preferably Microsoft Sentinel; Splunk, QRadar, Elastic, or Google SecOps are also relevant Experience with log onboarding and troubleshooting across Windows, Linux, Microsoft Entra ID, cloud, network, endpoint, and application environments Proficiency in KQL/SPL/SQL, or a comparable query language, including analytics and performance troubleshooting Knowledge of syslog, APIs, agents, collectors, event streaming, common schemas, parsing, normalization, and enrichment Scripting or automation experience using PowerShell, Python, REST APIs, Git, CI/CD, or infrastructure-as-code Understanding of detection engineering, incident response, digital forensics, networking, security controls, and data protection Strong analytical, documentation, stakeholder communication, and end-to-end ownership skills; professional English required Nice to have SIEM and security data lake architecture; SOAR and detection-as-code practices Experience in regulated, critical-infrastructure, energy, or OT environments Knowledge of NIS2, ISO/IEC 27001, IEC 62443, and security log retention requirements Relevant Microsoft, Splunk, GIAC, CISSP, CISM, or equivalent certification We offer Opportunity to work in a fast-paced, agile, software engineering culture Comfortable modern office in Prague 7, with support of hybrid or fully remote mode Benefit program (5 weeks of vacation, paid sick days, paid days off for special occasions, meal vouchers, flexi pass, Prague city public transport annual coupon, multisport cards, optional contribution to pension fund, health insurance for family member) EPAM Employee Stock Purchase Plan (ESPP) (subject to certain eligibility requirements) English language courses Czech language courses upon request Referral bonuses for recommended candidates Mobile Phone Tariff’s program for managerial-level candidates Great learning and development opportunities, including in-house professional training, career advisory and coaching, sponsored professional certifications, well-being programs, LinkedIn Learning Solutions and much more Certain benefits and perks may be subject to eligibility requirements and may be available only after you have passed your probationary period.

Наблюдалась 2026-09-21, впервые 2026-09-16, источник — Indeed.

Открыть у работодателя