Position: SIEM Admin
Job ID: SIA_001
Location: Andheri, Mumbai
Your responsibilities as a SIEM Admin:
- Configure, maintain, and troubleshoot QRadar components such as Event Processors, Flow Processors, and Console.
- Plan and execute software upgrades, patches, and version migrations.
- Conduct regular health checks to ensure optimal performance and reliability.
- Integrate devices and custom applications with QRadar for effective log collection.
- Develop and maintain custom parsers and log source extensions.
- Ensure proper log normalization and correlation to facilitate accurate threat detection.
- Create and tune correlation rules to identify security incidents and anomalies effectively.
- Review and optimize existing rules to improve detection accuracy and reduce false positives.
- Collaborate with other IT and security teams to investigate and respond to security incidents identified by the SIEM.
- Provide support during incident response activities, including log analysis and evidence collection.
- Document configurations, procedures, and troubleshooting steps to maintain comprehensive system documentation.
- Provide training and support to junior staff members or other teams as required.
Skill sets we require:
- Proven experience working as a SIEM Administrator, with a focus on IBM QRadar.
- Proficiency in the installation, configuration, and administration of QRadar appliances.
- Strong understanding of log management, event correlation, and threat detection concepts.
- Experience developing and maintaining custom parsers and log source extensions.
- Familiarity with scripting languages such as Python or Bash for automation tasks.
- Excellent analytical and problem-solving skills, with the ability to troubleshoot complex issues independently.
- Effective communication skills, with the ability to collaborate with cross-functional teams.
Pedigree and Experience:
- Bachelor's degree in Computer Science, Information Security or related field.
- Industry certifications such as IBM QRadar Certified Administrator (C2150-624) or equivalent are a plus.
- 2+ years of experience in relevant field.