For our customer a major Energy & Utilities company we are seeking a SIEM Engineer for a contract
this is ideally based in Prague but with flexible working 6 month contract
KEY RESPONSIBILITIES • Engineer, configure, maintain, and monitor the SIEM platform, collectors, connectors, and supporting infrastructure. • Onboard security-relevant logs from identity, endpoint, network, cloud, business applications, databases, and other environments. • Design reliable data pipelines; develop parsing, normalization, transformation, timestamp handling, and contextual enrichment. • Monitor telemetry health and resolve missing sources, ingestion delays, volume anomalies, schema changes, and connector failures. • Support detection engineering with required fields, correlation logic, threat intelligence, MITRE ATT&CK mapping, and testing. • Optimize ingestion, storage tiers, retention, query performance, licensing, and cost without reducing required security visibility. • Maintain architecture diagrams, log-source inventory, onboarding standards, runbooks, ownership, and configuration records. • Support SOC investigations, threat hunting, incident response, forensic data extraction, audits, and major incident resolution. • Coordinate logging requirements and remediation with IT, Cloud, Network, IAM, Application, OT, vendors, and service providers. REQUIRED EXPERIENCE & SKILLS • Practical experience in SIEM engineering, security monitoring, log management, or security platform engineering. • Hands-on expertise with an enterprise SIEM, preferably Microsoft Sentinel; Splunk, QRadar, Elastic, or Google SecOps are also relevant. • Experience with log onboarding and troubleshooting across Windows, Linux, Microsoft Entra ID, cloud, network, endpoint, and application environments. • Proficiency in KQL, SPL, SQL, or a comparable query language, including analytics and performance troubleshooting. • Knowledge of syslog, APIs, agents, collectors, event streaming, common schemas, parsing, normalization, and enrichment. • Scripting or automation experience using PowerShell, Python, REST APIs, Git, CI/CD, or infrastructure-as-code. • Understanding of detection engineering, incident response, digital forensics, networking, security controls, and data protection. • Strong analytical, documentation, stakeholder communication, and end-to-end ownership skills; professional English required.
By applying for this role, you consent to SGI contacting you by telephone regarding recruitment services, market updates, and relevant business opportunities
We believe in equal opportunity for all and actively encourage applications from diverse backgrounds, experiences, and perspectives. Source Group International Ltd is acting as an Employment Business in relation to this vacancy
Location: London, United Kingdom Industry: Insurance Overview We are seeking an AI Platform Engineer to design, build and operate a secure, scalable AI/ML platform supporting insurance use cases inclu
For our customer a Commodities Trader, we are seeking a Business Analyst with DLP (Purview) experience and NIS2 Compliance 6 month contract remote EU The Business Analyst is needed to support requirem
For our customer, we are seeking an Azure Cloud Engineer for a project in Zurich. This is a 6 month project with a potential extension or permenant transfer Project Overview: Location: Onsite, Zurich
For our customer, we are seeking an Azure Cloud Engineer for a project in Zurich. This is a 6 month project with a potential extension or permenant transfer Project Overview: Location: Onsite, Zurich