4,194 open roles
SIEM Platform Engineer
Job description
We are looking for a SIEM Platform Engineer to design, operate, and continuously improve enterprise security logging and monitoring capabilities. The role ensures reliable, high-quality telemetry for threat detection, incident response, digital forensics, and compliance, while optimizing platform performance, scalability, and cost.
The role follows a hybrid working model, with three days per week based in the office (Tuesday, Wednesday, Thursday).
Responsibilities
Engineer, configure, maintain, and monitor the SIEM platform, collectors, connectors, and supporting infrastructure Onboard security-relevant logs from identity, endpoint, network, cloud, business applications, databases, and other environments Design reliable data pipelines; develop parsing, normalization, transformation, timestamp handling, and contextual enrichment Monitor telemetry health and resolve missing sources, ingestion delays, volume anomalies, schema changes, and connector failures Support detection engineering with required fields, correlation logic, threat intelligence, MITRE ATT&CK mapping, and testing Optimize ingestion, storage tiers, retention, query performance, licensing, and cost without reducing required security visibility Maintain architecture diagrams, log-source inventory, onboarding standards, runbooks, ownership, and configuration records Support SOC investigations, threat hunting, incident response, forensic data extraction, audits, and major incident resolution Coordinate logging requirements and remediation with IT, Cloud, Network, IAM, Application, OT, vendors, and service providers Requirements Practical experience in SIEM engineering, security monitoring, log management, or security platform engineering Hands-on expertise with an enterprise SIEM, preferably Microsoft Sentinel; Splunk, QRadar, Elastic, or Google Sec.
Ops are also relevant Experience with log onboarding and troubleshooting across Windows, Linux, Microsoft Entra ID, cloud, network, endpoint, and application environments Proficiency in KQL/SPL/SQL, or a comparable query language, including analytics and performance troubleshooting Knowledge of syslog, APIs, agents, collectors, event streaming, common schemas, parsing, normalization, and enrichment Scripting or automation experience using Power.
Shell, Python, REST APIs, Git, CI/CD, or infrastructure-as-code Understanding of detection engineering, incident response, digital forensics, networking, security controls, and data protection Strong analytical, documentation, stakeholder communication, and end-to-end ownership skills; professional English required Nice to have SIEM and security data lake architecture; SOAR and detection-as-code practices Experience in regulated, critical-infrastructure, energy, or OT environments Knowledge of NIS2, ISO/IEC 27001, IEC 62443, and security log retention requirements Relevant Microsoft, Splunk, GIAC, CISSP, CISM, or equivalent certification
Description copied from EPAM Systems's careers page. Read the full posting before you apply.
More jobs at EPAM Systems
Senior Full-Stack Engineer (Python+React)
EPAM Systems· Remote (Serbia)Manager/Senior Manager, Delivery Management - Application Security
EPAM Systems· London, England, UKSenior Data Scientist
EPAM Systems· Remote (Argentina; Brazil; Chile; Colombia; Mexico)Senior End-User Support Engineer
EPAM Systems· Warsaw, Masovian Voivodeship, PolandSenior Cloud & Infrastructure Engineer (Azure & Terraform)
EPAM Systems· Remote (Canada)
More jobs in Prague
Brewing Operator
Molson Coors Beverage· Praha, Czech RepublicDelivery Dispatcher Agent
Maersk· Czech Republic, Prague, 186 00Assistant Store Manager - Na Příkopě
Skechers· PragueSecurity & Compliance Manager
ALICE Technologies· Prague, HolešoviceCustomer Success & Delivery Manager
signageOS· Prague