SIEM Engineer
SecurityFull-timeHybridIČO10,500 CZK/MD
I'm interested in this positionGeneral
We are looking for a SIEM Engineer who will be responsible for the design, operation, and continuous development of security logging and monitoring in an enterprise environment. The goal is to provide reliable, high-quality security data for threat detection, incident response, digital forensic analysis, and compliance.
The role also includes optimizing the performance, scalability, and costs of the SIEM platform, as well as collaborating with other IT and security teams to ensure high-quality security telemetry.
Mission
- Design, configure, maintain, and monitor the SIEM platform, collectors, connectors, and related infrastructure.
- Onboard security-relevant logs from identity systems, endpoints, network infrastructure, cloud services, applications, databases, and other environments.
- Design and manage reliable data pipelines, including parsing, normalization, transformation, timestamp handling, and contextual data enrichment.
- Monitor telemetry quality and availability and resolve source outages, ingestion delays, unusual data volumes, schema changes, and connector failures.
- Collaborate on detection engineering, from providing the required data and fields to correlation logic, threat intelligence, MITRE ATT&CK mapping, and testing.
- Optimize ingestion, storage, retention, query performance, licensing, and costs without limiting the required level of security monitoring.
- Maintain architecture documentation, log source inventories, onboarding standards, runbooks, and configuration records.
- Support the SOC with incident investigation, threat hunting, incident response, forensic data acquisition, audits, and major incident resolution.
- Collaborate with IT, Cloud, Network, IAM, Application, and OT teams, as well as vendors and service providers, on logging requirements and issue remediation.
Skills
- Practical experience in SIEM engineering, security monitoring, log management, or security platform engineering.
- Hands-on experience with an enterprise SIEM platform, ideally Microsoft Sentinel. Experience with Splunk, QRadar, Elastic, or Google SecOps is also relevant.
- Experience onboarding and troubleshooting logs from Windows, Linux, Microsoft Entra ID, cloud, network, endpoint, and application environments.
- Knowledge of KQL, SPL, SQL, or a similar query language, including analytics and performance troubleshooting.
- Knowledge of syslog, APIs, agents, collectors, event streaming, common schemas, parsing, normalization, and enrichment.
- Experience with scripting or automation using PowerShell, Python, REST APIs, Git, CI/CD, or Infrastructure as Code.
- Knowledge of detection engineering, incident response, digital forensics, networking, security controls, and data protection.
- Strong analytical and communication skills, the ability to produce high-quality documentation, and the ability to take end-to-end ownership.
- Professional proficiency in English.
Nice to have
- Experience with SIEM and security data lake architecture, SOAR, and detection-as-code approaches.
- Experience in a regulated environment, critical infrastructure, energy, or OT.
- Knowledge of NIS2, ISO/IEC 27001, IEC 62443, and security log retention requirements.
- Relevant Microsoft, Splunk, GIAC, CISSP, CISM, or equivalent certifications.
Benefits
- Great colleagues and a fully flexible working policy
- Career coaching and development
- Flexible working hours
- Technical training and workshops
- Technical equipment for work (Mac / Windows)
- Company parties
- Company psychologist supporting mental well-being
- Multisport card
Take the next step in your career and get in touch.
Send us your CV and tell us a little about yourself. We'd love to learn about your experience, what you're looking for, and where you'd like to take your career next.