Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
ES

SIEM Platform Engineer

EPAM Systems
๐Ÿ‡จ๐Ÿ‡ฟ Czechia
Hybrid
8 hours ago
  • SIEM
  • Incident Response
  • Threat Intelligence
  • IAM
  • Microsoft Sentinel
  • Splunk
  • Elastic
  • Windows
  • Linux
  • SQL
  • PowerShell
  • Python
  • REST API
  • Git
  • CI/CD
  • IaC
  • IEC
  • CISSP
  • CISM
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

We are looking foraSIEM Platform Engineer to design, operate, and continuously improve enterprise security logging and monitoring capabilities. The role ensures reliable, high-quality telemetry for threat detection, incident response, digital forensics, and compliance, while optimizing platform performance, scalability, and cost.

The role follows a hybrid working model, with three days per week based in the office (Tuesday, Wednesday, Thursday).

Responsibilities

  • Engineer, configure, maintain, and monitor the SIEM platform, collectors, connectors, and supporting infrastructure
  • Onboard security-relevant logs from identity, endpoint, network, cloud, business applications, databases, and other environments
  • Design reliable data pipelines; develop parsing, normalization, transformation, timestamp handling, and contextual enrichment
  • Monitor telemetry health and resolve missing sources, ingestion delays, volume anomalies, schema changes, and connector failures
  • Support detection engineering with required fields, correlation logic, threat intelligence, MITRE ATT&CK mapping, and testing
  • Optimize ingestion, storage tiers, retention, query performance, licensing, and cost without reducing required security visibility
  • Maintain architecture diagrams, log-source inventory, onboarding standards, runbooks, ownership, and configuration records
  • Support SOC investigations, threat hunting, incident response, forensic data extraction, audits, and major incident resolution
  • Coordinate logging requirements and remediation with IT, Cloud, Network, IAM, Application, OT, vendors, and service providers

Requirements

  • Practical experience in SIEM engineering, security monitoring, log management, or security platform engineering
  • Hands-on expertise with an enterprise SIEM, preferably Microsoft Sentinel; Splunk, QRadar, Elastic, or Google SecOps are also relevant
  • Experience with log onboarding and troubleshooting across Windows, Linux, Microsoft Entra ID, cloud, network, endpoint, and application environments
  • Proficiency in KQL/SPL/SQL, or a comparable query language, including analytics and performance troubleshooting
  • Knowledge of syslog, APIs, agents, collectors, event streaming, common schemas, parsing, normalization, and enrichment
  • Scripting or automation experience using PowerShell, Python, REST APIs, Git, CI/CD, or infrastructure-as-code
  • Understanding of detection engineering, incident response, digital forensics, networking, security controls, and data protection
  • Strong analytical, documentation, stakeholder communication, and end-to-end ownership skills; professional English required

Nice to have

  • SIEM and security data lake architecture; SOAR and detection-as-code practices
  • Experience in regulated, critical-infrastructure, energy, or OT environments
  • Knowledge of NIS2, ISO/IEC 27001, IEC 62443, and security log retention requirements
  • Relevant Microsoft, Splunk, GIAC, CISSP, CISM, or equivalent certification

SIEM Platform Engineer ยท EPAM Systems

Auto apply with Likeremote