SOC Admin Qradar
On-sitePune, Maharashtra, India
Job Summary
Develop and implement new correlation rules, detection logic, and alerts based on client-specific security requirements and emerging threat intelligence. Continuously fine-tune existing rules to reduce false positives, improve detection accuracy, and align with evolving business and compliance needs. Configure and maintain SIEM data ingestion pipelines, ensuring accurate parsing and normalization of logs from diverse sources. Manage device configurations, data source settings, and field mappings to ensure consistent and reliable log ingestion. Perform daily, weekly, and monthly health checks of the SIEM infrastructure, including log ingestion status, storage utilization, and system performance. Create and maintain Standard Operating Procedures (SOPs) for SIEM administration, ensuring operational consistency and faster issue resolution. Apply software patches, updates, and version upgrades for QRadar and Microsoft Sentinel in accordance with vendor guidelines and change management policies. Design, develop, and deploy custom parsers to handle non-standard or proprietary log formats. Work closely with SOC analysts, threat hunters, and incident response teams to enhance detection capabilities.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.