Overview
Security Engineer Jobs in Czechia at Extoom
Title: Security Engineer
Company: Extoom
Location: Czechia
We're hiring a Security Engineer to join a security engineering team that designs, builds and operates SIEM environments at enterprise scale. The role sits where security and platform engineering meet — your time goes into turning logs into useful detections, keeping the platform reliable, and steadily improving how the whole thing runs.
WHAT YOU'LL DO
- Design and develop detection content — translate threats and use-cases into correlation rules, analytics, parsers and dashboards, then keep them tuned as the environment evolves
- Onboard new log sources end-to-end — from collection and parsing through normalization to making the data genuinely usable for detection and investigation
- Operate and harden the SIEM platform — keep ingestion healthy, troubleshoot what breaks, and gradually improve architecture, integrations and automation
- Lead platform projects — stand up new environments, integrate adjacent tooling (EDR, SOAR, identity, cloud), and extend or migrate existing setups
- Apply scripting and automation wherever it saves time — from query languages used inside the SIEM to general scripting against APIs
- Collaborate with security and platform colleagues — engineers, analysts and architects working on the same large-scale environment
WHAT WE EXPECT FROM YOU
- Several years of hands-on experience with security technologies — administering, configuring and implementing tools such as SIEM, EDR, IDS/IPS, identity, email security, vulnerability management or similar; OR senior-level experience as a Linux platform engineer with a clear pull toward security
- Practical experience with at least one SIEM is ideal — meaning you've actually built or maintained content (correlation / analytics rules, parsers, dashboards), onboarded log sources, and understood the data model end-to-end (any SIEM stack is welcome; what matters is what you did with it)
- Solid Linux fundamentals — comfort on the command line and a real understanding of system internals, logs, networking and services
- Familiarity with a query or scripting language is a plus — SQL, KQL, SPL, Python, shell or regex; the more of these you're comfortable with, the better
- Analytical, problem-solving mindset — you can read logs, follow a data flow across systems, and figure out why something isn't behaving as expected
- Good written and spoken English — the working environment is international
- Eligibility to work in the Czech Republic without visa sponsorship — we're unable to support work-permit applications, so you'll need an existing right to work here (Czech / EU citizenship or an equivalent permit)
WHAT WE OFFER
- Deep, focused work on SIEM and detection engineering at enterprise scale
- A senior security engineering team with strong depth across SIEM, EDR, SOAR, threat hunting and security automation to learn from
- Funded certifications and training in security and the platforms you work with
- Modern tooling and meaningful scale — real systems, real data, real impact
- A clear technical career path — from detection engineer toward senior engineer, technical lead, or architect