SIEM Engineer

Vienna, Czech Republic

Apply by 11 Nov 2026

£400/day

Job Ref.: 57942

Job Type: Contract

Job Description


KEY RESPONSIBILITIES
Engineer, configure, maintain, and monitor the SIEM platform, collectors, connectors, and supporting infrastructure.
Onboard security-relevant logs from identity, endpoint, network, cloud, business applications, databases, and other environments.
Design reliable data pipelines; develop parsing, normalization, transformation, timestamp handling, and contextual enrichment.
Monitor telemetry health and resolve missing sources, ingestion delays, volume anomalies, schema changes, and connector failures.
Support detection engineering with required fields, correlation logic, threat intelligence, MITRE ATT&CK mapping, and testing.
Optimize ingestion, storage tiers, retention, query performance, licensing, and cost without reducing required security visibility.
Maintain architecture diagrams, log-source inventory, onboarding standards, runbooks, ownership, and configuration records.
Support SOC investigations, threat hunting, incident response, forensic data extraction, audits, and major incident resolution.
Coordinate logging requirements and remediation with IT, Cloud, Network, IAM, Application, OT, vendors, and service providers.

REQUIRED EXPERIENCE & SKILLS
Practical experience in SIEM engineering, security monitoring, log management, or security platform engineering.
Hands-on expertise with an enterprise SIEM, preferably Microsoft Sentinel; Splunk, QRadar, Elastic, or Google SecOps are also relevant.
Experience with log onboarding and troubleshooting across Windows, Linux, Microsoft Entra ID, cloud, network, endpoint, and application environments.
Proficiency in KQL, SPL, SQL, or a comparable query language, including analytics and performance troubleshooting.
Knowledge of syslog, APIs, agents, collectors, event streaming, common schemas, parsing, normalization, and enrichment.
Scripting or automation experience using PowerShell, Python, REST APIs, Git, CI/CD, or infrastructure-as-code.
Understanding of detection engineering, incident response, digital forensics, networking, security controls, and data protection.
Strong analytical, documentation, stakeholder communication, and end-to-end ownership skills; professional English required.
PREFERRED QUALIFICATIONS
SIEM and security data lake architecture; SOAR and detection-as-code practices.
Experience in regulated, critical-infrastructure, energy, or OT environments.
Knowledge of NIS2, ISO/IEC 27001, IEC 62443, and security log retention requirements.
Relevant Microsoft, Splunk, GIAC, CISSP, CISM, or equivalent certification.
APPLY NOW

Similar Jobs.

Azure Cloud Engineer
Zürich, Switzerland

For our customer, we are seeking an Azure Cloud Engineer for a project in Zurich. This is a 6 month project with a potential extension or permenant transfer Project Overview:  Location: Onsite, Zurich

Azure Cloud Engineer
Zürich, Switzerland

For our customer, we are seeking an Azure Cloud Engineer for a project in Zurich. This is a 6 month project with a potential extension or permenant transfer Project Overview:  Location: Onsite, Zurich

Azure Cloud Engineer
Zurich, Switzerland

Project Overview: This is an internal role, replacement of one of our colleagues. Location: Onsite, Zurich, Switzerland Contract Duration: August - February 2027, subject to potential extension   This