
Greathire
Job Overview:
We are seeking an experienced and hands-on SIEM Engineer to manage and optimize our IBM QRadar platform and deliver managed security services to a high-profile State Government client. This is a mission-critical role requiring a strong technical foundation, leadership skills, and deep expertise in security information and event management systems.
Key Responsibilities:
- Serve as the primary QRadar SIEM engineer, overseeing the platform’s day-to-day operations and maintenance.
- Lead interactions with internal project teams, the client’s cybersecurity staff, and SOC analysts to optimize use cases and alerting.
- Perform platform upgrades, manage QRadar sensors and collectors, and ensure continuous performance.
- Integrate and configure new log sources, custom DSMs, alerts, and correlation rules.
- Conduct and analyze Nessus vulnerability scans and support threat detection initiatives.
- Troubleshoot SIEM-related issues including event drops, parsing errors, performance bottlenecks, and unknown events.
- Create and maintain custom QRadar parsers and log source extensions.
- Monitor EPS/FPS metrics, system health, storage usage, and overall performance.
- Develop and maintain QRadar search queries, custom dashboards, and reports to support security operations and compliance.
- Collaborate with Detection & Response teams to align SIEM tuning with broader organizational objectives.
- Provide coaching and guidance to junior team members on QRadar best practices and configurations.
Required Skills & Experience:
- Hands-on expertise with IBM QRadar SIEM, including configuration, use case development, and system upgrades.
- Strong skills in AQL (Ariel Query Language) and QRadar dashboard/report creation.
- Proficiency in Linux (RedHat) system administration and Bash scripting.
- Experience in log source integration, DSM customization, and performance tuning.
- Solid understanding of intrusion detection systems (IDS) and network security protocols.
- Strong grasp of database management, especially PostgreSQL.
- Proficiency in Python and scripting for automation and log parsing.
- Familiarity with ticketing systems and performance monitoring tools.
- Excellent verbal and written communication skills.
- Demonstrated problem-solving skills with the ability to conduct deep-dive analysis.
Preferred Skills:
- Experience with additional security tools such as:
- Palo Alto XSIAM/XDR
- Cribl
- Splunk
- FireEye EDR
- Knowledge of SOAR platforms and automated security workflows.
Understanding of cloud-native and hybrid environments for security event management.
To apply for this job email your details to greathireteam2@gmail.com