Security Delivery Specialist-SIEM Admin

IBM · IN Mumbai

Company

IBM

Location

IN Mumbai

Type

Full Time

Job Description

Introduction
As a Service Delivery Specialist you are the face of IBM for our customers. Your clients’ success depends on your ability to understand their needs and respond to requests for new services. This role is an integral part of both account planning and delivering support strategies working to proactively monitor problems change processes and handle issues to ensure our customers success.

Your Role and Responsibilities
The Security Analyst monitors security events from the various SOC entry channels (SIEM Tickets Email and Phone) based on the security event severity escalate to managed service support teams tier2 information security specialists and/or customer as appropriate to perform further investigation and resolution.

Responsibilities:

  • Good knowledge of SIEM SIEM Architecture SIEM health check.
  • Deployment of SIEM in customer environment.
  • Audit the SIEM in the customer environment.
  • Troubleshoot issues regarding SIEM and other SOC tools.
  • Good verbal/written communication skills.
  • Build of use case for the customer.
  • Data archiving and backup and data purging configuration as per need and compliance.
  • Raising change management tickets for SOC Administration activities like Patch upgrade for SIEM onboarding log sources etc.
  • Helping L2 and L1 with required knowledge base details and basic documentations.
  • Co-ordination with L2 and SOC Monitoring team for troubleshooting issues and highlighting them to clients for further resolution and escalation.
  • High ethics ability to protect confidential information.
  • Troubleshooting at device and connector/agent end to fix the anomaly reported by other team and observed on day to day basis.
  • Building of incident reports advisories and review if SLA has been met for Incident alerting and Incident closure.
  • Update and maintain SOC knowledge base for new security incidents and docs.
  • Proven expertise in handling the daily monitoring of Information Security events on the ArcSight/ QRadar console platform
  • Creation of daily status report sheet and submit to SOC manager for review.
  • Review advisories and make necessary detection measures.
  • Provide analysis and trending of security log data from a large number of security devices.
  • Troubleshooting non-reporting devices fix and maintain device status.
  • Working with OEM (Tool support) in a way to resolve the issue or incident raised.
  • Administration of Windows and Unix servers.
  • Building Parser for the SIEM using regex.
  • Ready to work on 24/7 shifts to support client requirement.


Required Technical and Professional Expertise

  • 2 Years of Experience in SOC and min. 1 years on Qradar Splunk SIEM Engineering
  • Exposure to next generation SOC (2.0)
  • Escalation point for L2 and Soc Monitor team.
  • Ability to drive call and summarizing it post discussion.
  • Handsome experience in SIEM administration and Event flow architecture and different types of logs generated by devices like Windows Proxy Network Devices Database…etc.
  • Good Understanding of Firewall IDP/IPS SIEM functioning (Generalize HLD as well as LLD).
  • Deep understanding on Windows DB Mail cluster VM and Linux commands.
  • Knowledge of network protocols TCP/IP and ports.
  • Team Spirit and working ideas heading to resolution of issues.


Preferred Technical and Professional Expertise

  • Qualifications like CISA CISM CISSP CEH SANS or any other recognized qualification in Cybersecurity (SIEM/Qradar certification) will be preferred.
  • Thorough knowledge in SIEM tool and experience in networking Cloud security experience will be preferred.
Apply Now

Date Posted

11/17/2023

Views

5

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Security Consultant-SIEM Admin L2 - IBM

Views in the last 30 days - 0

The job description highlights the importance of longterm relationships collaboration and innovation in IBM Consulting The role involves managing dayt...

View Details

SIEM Admin L2 - IBM

Views in the last 30 days - 0

The job description highlights the importance of longterm relationships collaboration and innovation in IBM Consulting The role involves managing dayt...

View Details

SIEM Admin L2 - IBM

Views in the last 30 days - 0

IBM Consulting offers a dynamic work environment where youll work with clients to improve their hybrid cloud and AI journey As a Security Services Con...

View Details

Banking Industry Consultant - Infrastructure Specialist- AWS DevOps - IBM

Views in the last 30 days - 0

The text describes a role as an AWS DevOps specialist for Banking Applications in the Mumbai region focusing on ensuring the smooth operation and stab...

View Details

Security Consultant Intelligence and ops - IBM

Views in the last 30 days - 0

The text describes a career opportunity in IBM Consulting focusing on the role of a security specialist The position involves implementing and managin...

View Details

Security Consultant Network Security - IBM

Views in the last 30 days - 0

The job description highlights the importance of longterm relationships collaboration and innovation in IBM Consulting The role of a Network Security ...

View Details