29 Sep
|
Protean Staffing
|
Mumbai
29 Sep
Protean Staffing
Mumbai
Role & responsibilities
Manage day-to-day IBM QRadar Log Management and SIEM operations across enterprise infrastructure, applications, cloud, and security platforms.
Onboard and configure current log sources into QRadar using Syslog, APIs, agents/connectors, and other supported integration mechanisms.
Configure and troubleshoot DSM, Log Source Extensions (LSX), custom properties, parsing, normalization, and event mapping.
Monitor log-source health and identify stopped, delayed, intermittent, duplicate, or incorrectly parsed logs.
Troubleshoot end-to-end log ingestion issues involving QRadar, network connectivity, firewalls, applications, servers, databases, and security devices.
Perform regular log-source health checks, coverage validation, and reconciliation to ensure critical assets are continuously reporting.
Manage EPS utilisation, event volumes, retention considerations, and log ingestion performance.
Support QRadar components including Console, Event Collectors, Event Processors, Data
Nodes and App Host, as applicable.
Coordinate with infrastructure, network, application, cloud, database, and security teams for log-source onboarding and troubleshooting.
Maintain and update the log-source inventory,
onboarding tracker, integration documentation, SOPs, and troubleshooting knowledge base.
Handle log-management incidents and service requests through the ITSM platform, ensuring adherence to defined SLA and escalation requirements.
Support SOC and Incident Response teams with log searches, event investigation, historical log retrieval, and troubleshooting during security incidents.
Work with SIEM engineering teams on use-case dependencies, required log sources,
Preferred candidate profile
47 years of cybersecurity/SOC experience with robust hands-on expertise in IBM QRadar SIEM and Log Management.
Robust knowledge of QRadar architecture, DSMs, log sources, protocols, event processing and Ariel searches/AQL.
Hands-on experience onboarding logs from Windows, Linux, Network/Security Devices, Active Directory, Databases, Applications, Cloud and Security platforms.
Good understanding of Syslog, TCP/IP, SNMP, REST APIs, JDBC, WinCollect and common log collection mechanisms.
Experience troubleshooting log ingestion, parsing, timestamp, connectivity and performance issues.
📌 Qradar Log Management Analyst Cybersecurity Mumbai
🏢 Protean Staffing
📍 Mumbai