EPAM Systems logo
EPAM Systems

4,194 open roles

SIEM Platform Engineer

Prague, Hlavni mesto Praha, Czech RepublicFull-timePosted Sep 29, 2026

Job description

We are looking for a SIEM Platform Engineer to design, operate, and continuously improve enterprise security logging and monitoring capabilities. The role ensures reliable, high-quality telemetry for threat detection, incident response, digital forensics, and compliance, while optimizing platform performance, scalability, and cost.

The role follows a hybrid working model, with three days per week based in the office (Tuesday, Wednesday, Thursday).

Responsibilities

Engineer, configure, maintain, and monitor the SIEM platform, collectors, connectors, and supporting infrastructure Onboard security-relevant logs from identity, endpoint, network, cloud, business applications, databases, and other environments Design reliable data pipelines; develop parsing, normalization, transformation, timestamp handling, and contextual enrichment Monitor telemetry health and resolve missing sources, ingestion delays, volume anomalies, schema changes, and connector failures Support detection engineering with required fields, correlation logic, threat intelligence, MITRE ATT&CK mapping, and testing Optimize ingestion, storage tiers, retention, query performance, licensing, and cost without reducing required security visibility Maintain architecture diagrams, log-source inventory, onboarding standards, runbooks, ownership, and configuration records Support SOC investigations, threat hunting, incident response, forensic data extraction, audits, and major incident resolution Coordinate logging requirements and remediation with IT, Cloud, Network, IAM, Application, OT, vendors, and service providers Requirements Practical experience in SIEM engineering, security monitoring, log management, or security platform engineering Hands-on expertise with an enterprise SIEM, preferably Microsoft Sentinel; Splunk, QRadar, Elastic, or Google Sec.

Ops are also relevant Experience with log onboarding and troubleshooting across Windows, Linux, Microsoft Entra ID, cloud, network, endpoint, and application environments Proficiency in KQL/SPL/SQL, or a comparable query language, including analytics and performance troubleshooting Knowledge of syslog, APIs, agents, collectors, event streaming, common schemas, parsing, normalization, and enrichment Scripting or automation experience using Power.

Shell, Python, REST APIs, Git, CI/CD, or infrastructure-as-code Understanding of detection engineering, incident response, digital forensics, networking, security controls, and data protection Strong analytical, documentation, stakeholder communication, and end-to-end ownership skills; professional English required Nice to have SIEM and security data lake architecture; SOAR and detection-as-code practices Experience in regulated, critical-infrastructure, energy, or OT environments Knowledge of NIS2, ISO/IEC 27001, IEC 62443, and security log retention requirements Relevant Microsoft, Splunk, GIAC, CISSP, CISM, or equivalent certification

Description copied from EPAM Systems's careers page. Read the full posting before you apply.

More jobs at EPAM Systems

See all openings at EPAM Systems

More jobs in Prague

See all jobs in Prague