Siem Administrator

5 months ago


Pune Maharashtra, India IBM Full time

Introduction

Your Role and Responsibilities

As a SIEM Administrator, your role involves overseeing the implementation, management, and optimization of SIEM solutions within an organization's cybersecurity infrastructure.

**Responsibilities**:

- Install, configure, and maintain SIEM platforms and associated software. This includes setting up data collection agents, configuring data sources, and defining log collection policies.
- Should have knowledge in new SIEM Implementation and deployment with DC-DR, HA setup and configurations [Mainly Qradar SIEM].
- Should coordinate with Engineering Lead and ensure the SIEM projects are delivered on time, and in-line with Customer expectation and best practices.
- Excellent understanding and proven hands-on experience in SIEM concepts such as correlation, aggregation, normalization, and parsing.
- Experience in SIEM Version Upgrade, Patch Upgrade, Win Collect Version Upgrades.
- Must have proven experience in Log Sources Integration & Troubleshooting.
- Strong skill set in custom log sources integration & parser development.
- Should perform regular health checks and maintain the SIEM platform effectively.
- Should have work experience in UBA & Rules and Tuning of UBA app.
- Experience in Use Case conceptualization, configuration & testing.
- Standardizing Use Cases and make it applicable for all customers.
- Responsible for Apps Installation, Troubleshooting & App host Management.
- Understanding about threat scenarios, threat vectors and logs to arrive at identify new threats.

Required Technical and Professional Expertise
- 4+ years of IT experience in security with at least 3+ Years in Security Operation centre with SIEMs and EDR.
- Should have good understanding of Networking, OSI, TCP/IP concepts.
- Should have good understanding of ITIL process.
- Should understand Cybersecurity controls and attack.
- Understanding of MITRE Framework and attack methods.
- Good to have Cybersecurity certifications [SIEM Administrations, CEH, CompTIA S+]
- Should have work experience multiple SIEM solutions and understanding of SIEM Architecture and components [Mainly Qradar SIEM].
- Good to have hands on experience in SIEM Administration and troubleshooting [Mainly Qradar SIEM]
- Analyse existing SIEM rules to optimize threat detection and minimize false positives.
- Participate in Client SOC strategy and planning, including capacity planning and technology roadmap.
- Ability to multitask and work independently with mínimal direction and maximum accountability.
- Coordination skills to collaborate with multiple technical and service delivery team.

Preferred Technical and Professional Expertise
- Certifications: CEH or ECIH or CompTIA security analyst.
- Ambitious individual who can work under their own direction towards agreed targets/goals and with creative approach to work.
- Intuitive individual with an ability to manage change and proven time management.
- Proven interpersonal skills while contributing to team effort by accomplishing related results as needed.
- Up-to-date technical knowledge by attending educational workshops, reviewing publications.
- Any entrant or Professional skill on shell scripting, AIX, Linux or Python.
- Good to have hands on experience with managing SIEM solutions on public/private clouds like Amazon AWS, Microsoft Azure, etc.
- Proven Experience on any of the Security information and event management (SIEM) tools like (Qradar, Splunk, McAfee ESM etc.)
- Data-driven threat hunting using SIEM and other threat hunting tools.
- Experience is SOAR tools such as Qradar Resilient, PaloAlto XSOAR
- Identify quick defence techniques till permanent resolution.
- Recognize successful intrusions and compromises through review and analysis of relevant event detail information.
- Launch and track investigations to resolution. Recognize attacks based on their signatures, differentiates false positives from true intrusion attempts.
- Actively investigates the latest security vulnerabilities, advisories, and incidents.
- Identify the gaps in security environment & suggest the gap closure.
- Drive & Support Change Management.

About Business UnitIBM Consulting is IBM’s consulting and global professional services business, with market leading capabilities in business and technology transformation. With deep expertise in many industries, we offer strategy, experience, technology, and operations services to many of the most innovative and valuable companies in the world. Our people are focused on accelerating our clients’ businesses through the power of collaboration. We believe in the power of technology responsibly used to help people, partners and the planet.

Being an IBMer means you’ll be able to learn and develop yourself and your career, you’ll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background.

Our IB


  • Siem Administrator

    5 months ago


    Pune, India Softenger Full time

    **Job Profile**: - SIEM Administrator**Job Location**: - Pune**Experience Required**: - 2-4 yrs- SIEM Configuration: Configure and maintain the ArcSight SIEM platform to ensure it effectively collects, normalizes, and analyzes security event data.Log Management: Manage and optimize log collection and storage processes to ensure efficient storage and...


  • Pune, Maharashtra, India Teleglobal International Full time

    **Key Responsibilities**: - Install, configure, and maintain the IBM QRadar SIEM platform to ensure efficient log collection, analysis, and threat detection. - Monitor system health, troubleshoot issues, and implement necessary updates and patches. - Analyze security events, incidents, and alerts to provide timely and effective responses. - Play a key role...

  • Administrator - Siem

    2 months ago


    Pune, Maharashtra, India Microland Full time

    **Required Skills**: Behavioral | Aptitude | Communication Technology | Cybersecurity | SOC Alert Management Technology | Cybersecurity | Vulnerability Management Technology | Cybersecurity | SIEM-SOAR Technology | Cybersecurity | End Point Security **Education Qualification**: Any Graduate **Certification Mandatory / Desirable**: Technology | IT Security...

  • Siem Administrator

    3 months ago


    Pune, Maharashtra, India IBM Full time

    Introduction Your Role and Responsibilities As a SIEM Engineer you will be responsible for implementation and deployment of new SIEM projects; and managing and providing SIEM health and operational support, including supporting to architecture changes, tool deployments and advanced detection engineering. **Responsibilities**: - Understand SIEM product...

  • Siem Admin

    5 months ago


    Mumbai, Maharashtra, India IBM Full time

    Introduction Your Role and Responsibilities This is level 2 role and would be responsible to support SIEM Management & content management for SIEM detection use-cases for the program. They would be overlooking technical services delivery for SOC program for your enterprise. If you thrive in a dynamic, reciprocal workplace, IBM provides an environment to...


  • Mumbai, Maharashtra, India Dixit Infotech Services Pvt. Ltd Full time

    JBoss Administration - Logs monitoring. NABARD to provide necessary access and SOP's to Dixit Infotech team to fetch the JBoss logs. TCS & Dixit Infotech will integrate the in-scope JBoss instances to the SIEM tool. - Daily Health check-up of JBoss Application Server Middleware

  • Security Analyst-l2

    3 months ago


    Pune, Maharashtra, India IBM Full time

    Introduction Your Role and Responsibilities - Responsible for Apps Installation, Troubleshooting & App host Management. - Understanding about threat scenarios, threat vectors and logs to arrive at identify new threats. - Analyse existing SIEM rules to optimize threat detection and minimize false positives. - Participate in Client SOC strategy and planning,...


  • Pune, Maharashtra, India IBM Full time

    Introduction Your Role and Responsibilities - Lead and Guide the SIEM Admin Team to deliver all the below tasks - Install, upgrade, configure, administer, and maintain our distributed SIEM QRadar platform. - Monitor and troubleshoot QRadar health issues to ensure optimal performance. - Integrate different devices with SIEM, including API integration and...

  • Security

    6 months ago


    Pune, Maharashtra, India IBM Full time

    Introduction Your Role and Responsibilities This is level 2 role and would be responsible to support SIEM Management & content management for SIEM detection use-cases for the program. They would be overlooking technical services delivery for SOC program for your enterprise. If you thrive in a dynamic, reciprocal workplace, IBM provides an environment to...


  • Pune, Maharashtra, India Microland Full time

    **Required Skills**: Technology | Cybersecurity | End Point Security Technology | Cybersecurity | Vulnerability Management Technology | Cybersecurity | SIEM-SOAR Behavioral | Aptitude | Communication Technology | Cybersecurity | SOC Alert Management **Education Qualification**: Any Graduate **Certification Mandatory / Desirable**: Technology | IT Security...

  • Digital Network

    6 months ago


    Pune, India Microland Full time

    Required Skills Technology | Cybersecurity | End Point Security Technology | Cybersecurity | SOC Alert Management Technology | Cybersecurity | Vulnerability Management Behavioral | Aptitude | Communication Technology | Cybersecurity | SIEM-SOAR Education Qualification : Any Graduate Certification Mandatory / Desirable : Technology | IT Security...


  • Navi Mumbai, Maharashtra, India Capgemini Full time

    Choosing Capgemini means choosing a company where you will be empowered to shape your career in the way you’d like, where you’ll be supported and inspired by a collaborative community of colleagues around the world, and where you’ll be able to reimagine what’s possible. Join us and help the world’s leading organizations unlock the value of...


  • Pune, India Genpact Full time

    Genpact (NYSE: G) is a global professional services and solutions firm delivering outcomes that shape the future. Our 125,000+ people across 30+ countries are driven by our innate curiosity, entrepreneurial agility, and desire to create lasting value for clients. Powered by our purpose – the relentless pursuit of a world that works better for people –...


  • Pune, Maharashtra, India PHH Mortgage Full time

    Job Description:At PHH Mortgage, we are seeking a highly skilled Cyber Security Operations Team Lead to join our team. This is an exciting opportunity for an experienced professional to lead our security operations team and play a key role in ensuring the confidentiality, integrity, and availability of our organization's data.As a Cyber Security Operations...


  • Vikhroli, Mumbai, Maharashtra, India Symphony Tech Solutions Full time

    Greetings of the day! As discussed, we are looking for **Firewall Administrator L2+- at one of IT Company - Vikhroli ( Mumbai) Location.** Please find the JD with Company details for your reference: Specialties:IPO, Rights Issue, Exit Offer, Buyback, Registry, AGM Management (Physical & Virtual), Employee Stock Options (EmPower), Insider Trading (TrackIn),...


  • Pune, Maharashtra, India ITHR 360 Consulting FZE Full time

    Job Responsibilities:Develop and implement comprehensive security strategies for SIEM and Network Security Administration.Identify and mitigate system vulnerabilities through proactive threat hunting and optimization of threat detection tools.Collaborate with the team to ensure consistent and secure operations, including device onboarding and log...


  • Pune, Maharashtra, India Customized Energy Solutions Full time

    About Customized Energy SolutionsWe are a leading service provider of market intelligence and operational support services to companies participating in the retail and wholesale electric and natural gas markets.Job DescriptionWe are seeking a qualified cloud administrator with 2 years of experience to execute administrative tasks on cloud elastic deployments...

  • Threat Intel

    3 months ago


    Pune, Maharashtra, India IBM Full time

    Introduction Your Role and Responsibilities This position serves as a Cyber Threat Analyst in support of a major IBM client. This organization provides services that analyse and produce enhanced cyber security and threat intelligence information to include threats and potential threats to the customer’s personnel, information, and information systems;...


  • Mumbai, Maharashtra, India Kyndryl Full time

    Who We Are At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. The Role As...


  • Pune, India Customized Energy Solutions Full time

    Company Description Customized Energy Solutions (CES), a privately-held company, is a leading service provider of market intelligence and operational support services to companies participating in the retail and wholesale electric and natural gas markets. Utilizing deep know-how developed since the inception of the deregulated energy markets, CES...