QRadar Log Management Analyst – Cybersecurity
QRadar Log Management Analyst – Cybersecurity
22
Mumbai, Maharashtra, India
Job Views:
Created Date: 2026-08-13
End Date:
Salary: 1550000
Industry: Edtech
Openings: 1
Primary Responsibilities :
• Manage day-to-day IBM QRadar Log Management and SIEM operations across enterprise infrastructure, applications, cloud, and security platforms.
• Onboard and configure new log sources into QRadar using Syslog, APIs, agents/connectors, and other supported integration mechanisms.
• Configure and troubleshoot DSM, Log Source Extensions (LSX), custom properties, parsing, normalization, and event mapping.
• Monitor log-source health and identify stopped, delayed, intermittent, duplicate, or incorrectly parsed logs. • Troubleshoot end-to-end log ingestion issues involving QRadar, network connectivity, firewalls, applications, servers, databases, and security devices.
• Perform regular log-source health checks, coverage validation, and reconciliation to ensure critical assets are continuously reporting.
• Manage EPS utilisation, event volumes, retention considerations, and log ingestion performance.
• Support QRadar components including Console, Event Collectors, Event Processors, Data Nodes and App Host, as applicable.
• Coordinate with infrastructure, network, application, cloud, database, and security teams for log-source onboarding and troubleshooting.
• Maintain and update the log-source inventory, onboarding tracker, integration documentation, SOPs, and troubleshooting knowledge base.
• Handle log-management incidents and service requests through the ITSM platform, ensuring adherence to defined SLA and escalation requirements.
• Support SOC and Incident Response teams with log searches, event investigation, historical log retrieval, and troubleshooting during security incidents.
• Work with SIEM engineering teams on use-case dependencies, required log sources, parsing improvements, and data-quality issues.
• Participate in QRadar upgrades, patches, configuration changes, capacity reviews, and platform health activities.
• Prepare operational reports covering log-source availability, onboarding status, failures, EPS trends, SLA performance, and outstanding issues.
Experience Requirements:
Required Skills
• 4–7 years of cybersecurity/SOC experience with strong hands-on expertise in IBM QRadar SIEM and Log Management.
• Strong knowledge of QRadar architecture, DSMs, log sources, protocols, event processing and Ariel searches/AQL.
• Hands-on experience onboarding logs from Windows, Linux, Network/Security Devices, Active Directory, Databases, Applications, Cloud and Security platforms.
• Good understanding of Syslog, TCP/IP, SNMP, REST APIs, JDBC, WinCollect and common log collection mechanisms.
• Experience troubleshooting log ingestion, parsing, timestamp, connectivity and performance issues.
• Understanding of EPS/FPM, licensing, data retention, QRadar health monitoring and capacity considerations.
• Working knowledge of SIEM, SOC operations, Incident Response and security monitoring concepts.
• Basic scripting/automation knowledge using Python, PowerShell or Shell scripting will be advantageous.
• Strong analytical, troubleshooting, documentation, and stakeholder coordination skills.
Preferred Certifications
IBM Certified Analyst – Security QRadar SIEM, IBM QRadar Deployment/Administration certifications, Security+, CySA+, CEH, or equivalent SIEM/SOC certifications.
Key Competencies:
IBM QRadar | Log Management | Log Source Onboarding | DSM | LSX | WinCollect | AQL | EPS Management | Parsing & Normalization | SIEM Operations | Log Health Monitoring | Troubleshooting | SOC
