Posted on: 22/07/2026
We are seeking an experienced SME IBM QRadar to join our Cyber Security Operations team.
The ideal candidate will possess deep expertise in IBM QRadar SIEM, threat detection, security monitoring, incident investigation, and log management.
You will play a key role in strengthening the organization's security posture by designing, implementing, and optimizing QRadar solutions while leading incident response initiatives and mentoring security analysts.
This role requires extensive hands-on experience in enterprise SOC environments, SIEM engineering, threat intelligence integration, and cybersecurity best practices.
Key Responsibilities :
- Administer, configure, and maintain IBM QRadar SIEM infrastructure across enterprise environments.
- Design, implement, and optimize QRadar deployments for scalable log collection, event correlation, and threat detection.
- Develop, customize, and fine-tune correlation rules, custom properties, building blocks, reference sets, and offenses.
- Integrate multiple log sources including firewalls, IDS/IPS, endpoint security tools, cloud platforms, operating systems, databases, and network devices.
- Monitor security events, investigate complex incidents, and perform root cause analysis.
- Lead incident response activities and coordinate with internal stakeholders during security incidents.
- Analyze attack patterns, indicators of compromise (IOCs), and emerging cyber threats.
- Develop dashboards, reports, and use cases aligned with organizational security objectives.
- Optimize SIEM performance by reducing false positives and improving detection accuracy.
- Implement threat intelligence feeds and enhance detection capabilities using MITRE ATT&CK and Cyber Kill Chain methodologies.
- Perform log source onboarding, normalization, and event parsing.
- Conduct security assessments, gap analysis, and recommend improvements to monitoring capabilities.
- Support compliance initiatives related to ISO 27001, PCI-DSS, HIPAA, GDPR, or other regulatory standards.
- Work closely with network, infrastructure, cloud, and application teams to improve security visibility.
- Mentor SOC analysts and provide technical leadership on QRadar administration and security operations.
- Prepare documentation, runbooks, SOPs, and knowledge base articles.
Required Skills :
- 8 to 10 years of experience in Cyber Security, Security Operations, or SIEM Engineering.
- Strong hands-on experience with IBM QRadar SIEM administration and engineering.
- Expertise in QRadar Event Collectors, Event Processors, Console management, Data Nodes, and Flow Processors.
- Experience creating QRadar correlation rules, custom DSMs, custom properties, and AQL queries.
- Strong understanding of log management and event correlation.
- Experience integrating security tools such as :
1. Firewalls (Palo Alto, Fortinet, Check Point, Cisco)
2. IDS/IPS
3. Endpoint Detection & Response (CrowdStrike, Microsoft Defender, SentinelOne)
4. Proxy Servers
5. Active Directory
6. DNS
7. VPN
8. Email Security Solutions
- Knowledge of TCP/IP, DNS, HTTP/S, SMTP, DHCP, VPN, and network security concepts.
- Experience with Windows, Linux, and cloud environments (AWS, Azure, or GCP).
- Strong understanding of cybersecurity frameworks including :
1. MITRE ATT&CK
2. NIST Cybersecurity Framework
3. Cyber Kill Chain
4. CIS Controls
- Experience with scripting using Python, Bash, or PowerShell for automation.
- Working knowledge of vulnerability management tools such as Qualys, Nessus, or Rapid7.
- Experience with SOAR integrations is an added advantage.
- Familiarity with threat intelligence platforms and IOC management.
Preferred Qualifications :
- Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related field.
- IBM QRadar SIEM certification is highly preferred.
- Industry certifications such as CEH, CompTIA Security+, CySA+, GCIH, GCIA, CISSP, or CISM are an advantage.
- Experience working in 24x7 SOC or Managed Security Services environments.
Desired Competencies :
- Strong analytical and investigative skills.
- Excellent troubleshooting and problem-solving abilities.
- Ability to handle critical security incidents under pressure.
- Strong communication and stakeholder management skills.
- Ability to mentor junior engineers and lead technical initiatives.
- High attention to detail with a proactive approach to identifying security risks.
- Experience working in Agile and ITIL-based operational environments
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1656693