DL
IBM Qradar
Diverse Lynx India
Location not stated
4 weeks ago
- SIEM
- Configuration Management
- REST API
- AWS
- Python
- PowerShell
4 weeks ago
• Administer and maintain IBM QRadar SIEM infrastructure.
• Integrate and onboard log sources from security devices, servers, applications, cloud platforms, and databases.
• Develop, customize, and tune QRadar correlation rules, use cases, offenses, building blocks, and reference sets.
• Troubleshoot log collection, parsing, normalization, and event correlation issues.
• Create and maintain dashboards, reports, and security monitoring content.
• Support incident investigations, threat hunting, and root cause analysis activities.
• Monitor SIEM health, performance, EPS licensing, and storage utilization.
• Perform SIEM upgrades, patching, backup, and configuration management.
• Develop SOPs, runbooks, and technical documentation for SOC operations.
• Work closely with SOC analysts, infrastructure teams, and security architects to improve detection coverage and reduce false positives.
Required Skills
• 5+ years of experience in SIEM/SOC operations.
• 3+ years of hands-on experience with IBM QRadar SIEM.
• Expertise in log source onboarding, DSM troubleshooting, and event parsing.
• Strong experience in SIEM correlation rule and use case creation.
• Experience with Syslog, WinCollect, REST API integrations, and AWS log onboarding.
• Strong incident analysis and threat detection skills.
• Basic scripting knowledge (Python, PowerShell, Shell) preferred.
Skills: Cyber Security
Experience Required: 6-8
IBM Qradar · Diverse Lynx India