Posted on: 25/06/2026
Key Responsibilities :
Security Monitoring & Threat Detection :
- Monitor critical business applications, APIs, connectivity gateways, and enterprise infrastructure for security threats and vulnerabilities.
- Support and maintain UAT and Production SIEM/DAM environments across Data Center (DC) and Disaster Recovery (DR) sites.
- Continuously monitor security events using SIEM, network telemetry, behavioral analytics, and log intelligence platforms.
- Investigate suspicious activities and identify potential threats before they impact business operations.
- Integrate and manage security tools including SIEM, SOAR, XDR, IDS/IPS, UEBA, and threat intelligence platforms.
Threat Intelligence & Incident Response :
- Monitor emerging cyber threats, zero-day vulnerabilities, and Advanced Persistent Threats (APTs).
- Lead incident triage, investigation, containment, eradication, and recovery activities.
- Perform root cause analysis and document lessons learned from security incidents.
- Coordinate security incidents with internal stakeholders and external regulatory bodies when required.
- Participate in cyber drills, incident simulations, red team exercises, and blue team activities.
- Develop recommendations to improve the organization's security posture.
SOC Operations & Platform Optimization :
- Administer and optimize IBM QRadar environments including :
1. Log source onboarding
2. Correlation rule tuning
3. Dashboard creation
4. AQL queries
5. DSM management
6. Offense management
7. Performance optimization
- Develop and maintain security use cases and alerting mechanisms.
- Automate repetitive security processes using SOAR playbooks and custom integrations.
- Work closely with NOC, Infrastructure, Application Support, and Business Continuity teams.
- Ensure log collection, storage, retention, and forensic readiness standards are maintained.
Compliance & Governance :
- Support regulatory compliance and reporting requirements.
- Develop and maintain SOC operational procedures, runbooks, and response playbooks.
- Participate in audits, compliance reviews, and security assessments.
- Drive proactive threat-hunting initiatives across enterprise environments.
- Contribute to SOC maturity enhancement programs and security improvement initiatives.
Required Experience :
- Minimum 7 years of experience in Cyber Security, SIEM, and Security Operations.
- Minimum 6 years of hands-on experience with IBM QRadar.
- Strong expertise in :
1. QRadar Administration
2. Log Parsing
3. AQL Queries
4. DSM Development
5. Correlation Rules
6. Offense Management
7. Dashboard Creation
8. Performance Tuning
- Experience with Guardium DAM and QRadar Network Insights (QNI).
- Hands-on experience with REST API integrations and security tool integrations.
- Experience working with SOAR platforms and security automation.
- Knowledge of IDS/IPS, XDR, UEBA, Threat Intelligence, and Incident Response.
- Experience in threat hunting and forensic investigations.
- Strong understanding of networking protocols, security controls, and enterprise infrastructure.
Technical Skills :
- IBM QRadar SIEM, IBM Guardium, QRadar Network Insights (QNI), SOAR Platforms, REST APIs, IDS/IPS, XDR, UEBA, Linux & Windows Administration, Scripting (Python, Shell, PowerShell).
Preferred Qualifications :
- IBM QRadar Certification.
- CEH, CHFI, CompTIA Security+, CISSP, GIAC or equivalent certifications.
- Experience in financial services, banking, stock exchange, or regulated environments.
- Familiarity with regulatory compliance frameworks and cyber security governance standards.
Key Competencies :
- Security Operations, Threat Detection & Analysis, Incident Management, Problem Solving.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1648426