QRadar Log Management Analyst Cybersecurity

Protean Staffing

Mumbai, Bengaluru

On-site

INR 1,500,000 - 2,100,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Protean Staffing seeks a seasoned QRadar SIEM specialist to manage enterprise log management, onboarding log sources via Syslog/APIs, and troubleshoot end-to-end ingestion issues. You will maintain DSM configurations, parsing rules, and event mappings while coordinating with infrastructure, network, and security teams to ensure continuous reporting across on-prem and cloud environments.

Ideal candidates have hands-on QRadar expertise, DNS/LSX mastery, and strong problem-solving skills to support

Qualifications

  • Extensive experience in cybersecurity/SOC with IBM QRadar SIEM.
  • Hands-on expertise in QRadar DSMs, log sources, and event mapping.
  • Experience onboarding logs from Windows, Linux, networks, and cloud.
  • Strong understanding of logging protocols and common collection mechanisms.

Responsibilities

  • Manage day-to-day QRadar operations across enterprise infrastructure and cloud.
  • Onboard and configure new log sources using Syslog, APIs, and agents.
  • Configure DSMs, LSX, parsing, and event mapping; monitor log-source health.
  • Troubleshoot end-to-end log ingestion across devices and applications.
  • Support log-source health checks, retention, and ESP utilization.
  • Coordinate with cross-functional teams for onboarding and troubleshooting.
  • Maintain log-source inventory, SOPs, and troubleshooting knowledge base.
  • Assist SOC and IR teams with log searches and investigations.

Skills

IBM QRadar SIEM
QRadar architecture
DSMs
Log source onboarding
Ariel searches/AQL
Syslog & APIs
Windows/Linux logs
Troubleshooting log ingestion

Tools

QRadar
Syslog
WinCollect
REST APIs
JDBC

Job description

Role & responsibilities

Manage day-to-day IBM QRadar Log Management and SIEM operations across enterprise infrastructure, applications, cloud, and security platforms.

  • Onboard and configure new log sources into QRadar using Syslog, APIs, agents/connectors, and other supported integration mechanisms.
  • Configure and troubleshoot DSM, Log Source Extensions (LSX), custom properties, parsing, normalization, and event mapping.
  • Monitor log-source health and identify stopped, delayed, intermittent, duplicate, or incorrectly parsed logs.
  • Troubleshoot end-to-end log ingestion issues involving QRadar, network connectivity, firewalls, applications, servers, databases, and security devices.
  • Perform regular log-source health checks, coverage validation, and reconciliation to ensure critical assets are continuously reporting.
  • Manage EPS utilisation, event volumes, retention considerations, and log ingestion performance.
  • Support QRadar components including Console, Event Collectors, Event Processors, Data Nodes and App Host, as applicable.
  • Coordinate with infrastructure, network, application, cloud, database, and security teams for log-source onboarding and troubleshooting.
  • Maintain and update the log-source inventory, onboarding tracker, integration documentation, SOPs, and troubleshooting knowledge base.
  • Handle log-management incidents and service requests through the ITSM platform, ensuring adherence to defined SLA and escalation requirements.
  • Support SOC and Incident Response teams with log searches, event investigation, historical log retrieval, and troubleshooting during security incidents.
  • Work with SIEM engineering teams on use-case dependencies, required log sources,
Preferred candidate profile

47 years of cybersecurity/SOC experience with strong hands-on expertise in IBM QRadar SIEM and Log Management.

  • Strong knowledge of QRadar architecture, DSMs, log sources, protocols, event processing and Ariel searches/AQL.
  • Hands-on experience onboarding logs from Windows, Linux, Network/Security Devices, Active Directory, Databases, Applications, Cloud and Security platforms.
  • Good understanding of Syslog, TCP/IP, SNMP, REST APIs, JDBC, WinCollect and common log collection mechanisms.
  • Experience troubleshooting log ingestion, parsing, timestamp, connectivity and performance issues.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Qradar Platform Support
Qradar Platform Support

SISA • Bengaluru

On-site
INR 400,000 - 600,000
Qradar Platform Support
Qradar Platform Support

Sisainfosec • Bengaluru

On-site
INR 400,000 - 640,000
Qradar Admin
Qradar Admin

SISA • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Security Engineer - Integration
Senior Security Engineer - Integration

SecurityHQ Ltd. • Pune District

On-site
INR 1,300,000 - 2,500,000
SOC L1
SOC L1

Sisainfosec • Bengaluru

On-site
INR 600,000 - 1,200,000
L1 SOC Analyst
L1 SOC Analyst

UST • Hyderabad

On-site
INR 700,000 - 1,100,000
Senior Consultant-SOC L3-SIEM Engineering and IR | Experience: 5+ Years
Senior Consultant-SOC L3-SIEM Engineering and IR | Experience: 5+ Years

Aujas Networks Pvt. Ltd. • Bengaluru

On-site
INR 1,200,000 - 1,800,000
SOC Monitoring - IBM Qradar or Sentinel
SOC Monitoring - IBM Qradar or Sentinel

KPMG Assurance and Consulting Services LLP • Mumbai

On-site
INR 700,000 - 900,000
SOC SIEM Security Analyst
SOC SIEM Security Analyst

Infosys • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Siem Engineer
Siem Engineer

Tata Consultancy Services • Ernakulam

On-site
INR 1,500,000 - 3,000,000