Find your next role
Discover amazing opportunities across our network of companies committed to gender equality in the workplace.
IBM
A career in IBM Consulting is rooted by long-term relationships and close collaboration with clients across the globe. You'll work with visionaries across multiple industries to improve the hybrid cloud and AI journey for the most innovative and valuable companies in the world. Your ability to accelerate impact and make meaningful change for your clients is enabled by our strategic partner ecosystem and our robust technology platforms across the IBM portfolio, including Software and Red Hat. Curiosity and a constant quest for knowledge serve as the foundation to success in IBM Consulting. In your role, you'll be encouraged to challenge the norm, investigate ideas outside of your role, and come up with creative solutions resulting in groundbreaking impact for a wide network of clients. Our culture of evolution and empathy centers on long-term career growth and development opportunities in an environment that embraces your unique skills and experience.
· Should have work experience with multiple SIEM solutions and deep understanding of SIEM Architecture and components [Mainly Qradar SIEM].
· Should have design and deployment of SIEM and SOAR solutions, primarily in Qradar SIEM.
· Extensive experience in rebuilding and restoration of SIEM and SOAR solutions and components.
· Should have experience in research and development of new correlation/MITRE based use cases based on new global trends
· Should have extensive hands-on experience in SIEM and SOAR Administration and troubleshooting [Mainly Qradar SIEM].
· Must have extensive knowledge in new SIEM Implementation and deployment with DC-DR, HA setup and configurations [Mainly Qradar SIEM].
· Should coordinate with Engineering Lead and ensure the SIEM projects are delivered on time, and in-line with Customer expectation and best practices.
· Excellent understanding and proven hands-on experience in SIEM concepts such as correlation, aggregation, normalization, and parsing.
· Act as the final escalation point for SIEM-related incidents and operational issues.
· Design, develop, and optimize advanced correlation rules, dashboards, reports, and custom parsers
· Lead investigations of advanced and complex cybersecurity incidents and threats
· Act as an escalation point for L1/L2 analysts for incident triage, analysis, and remediation.
· Experience in SIEM Version Upgrade, Patch Upgrade, WinCollect Version Upgrades.
· Must have proven experience in Log Sources Integration & Troubleshooting [DC and Cloud].
· Strong skill set in custom log sources integration & parser development.
· Should perform regular health checks and maintain the SIEM platform effectively.
· Should have work experience in UBA & Rules and Tuning of UBA app.
· Experience in Use Case conceptualization, configuration & testing.
· Responsible for Apps Installation, Troubleshooting & App host Management.
· Understanding about threat scenarios, threat vectors and logs to arrive at identify new threats.
· Analyse existing SIEM rules to optimize threat detection and minimize false positives.
· Participate in Client SOC strategy and planning, including capacity planning and technology roadmap.
· Ability to multitask and work independently with minimal direction and maximum accountability.
· Coordination skills to collaborate with multiple technical and service delivery team.
· Good to have knowledge in Investigating, documenting, and reporting on any information security (InfoSec) issues as well as emerging trends.
· Good to have experiences in analysis of security incident/alert trend and suggest for fine-tuning.
· Good to have experience in Investigate suspicious activities, contain, and prevent them.
· Minimum 8+ years of experience in IT Cyber Security Industry.
· Minimum 6+ years’ experience in SIEM Administration/Engineering.
SIEM Technology in Qradar SIEM, Palo Alto XSIAM, Microsoft Sentinel
· Should have good understanding of Networking, OSI, TCP/IP concepts.
· Should understand Cybersecurity controls and attack.
· Understanding of MITRE ATT&CK/NIST Framework and attack methods.
· Good to have Cybersecurity certifications [SIEM Administrations, CEH, CompTIA S+]
· Should have good understanding of ITIL process.
In a world where technology never stands still, we understand that, dedication to our clients success, innovation that matters, and trust and personal responsibility in all our relationships, lives in what we do as IBMers as we strive to be the catalyst that makes the world work better.
Being an IBMer means you’ll be able to learn and develop yourself and your career, you’ll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background.
Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do.
Are you ready to be an IBMer?
IBM’s greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world.
Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we’re also one of the biggest technology and consulting employers, with many of the Fortune 500 companies relying on the IBM Cloud to run their business.
At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computing and blockchain. Now it’s time for you to join us on our journey to being a responsible technology innovator and a force for good in the world.
IBM is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, neurodivergence, age, or other characteristics protected by the applicable law. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
When applying to jobs of your interest, we recommend that you do so for those that match your experience and expertise. Our recruiters advise that you apply to not more than 3 roles in a year for the best candidate experience. For additional information about location requirements, please discuss with the recruiter following submission of your application.