SOC Admin Qradar
Inspira Enterprise
Description
Job Description
SIEM Admin -
Exp Range : 3-5 yrs
Roles & Responsibilities:
-
Develop and implement new correlation rules, detection logic, and alerts based on client-specific security requirements and emerging threat intelligence.
-
Continuously fine-tune existing rules to reduce false positives, improve detection accuracy, and align with evolving business and compliance needs.
-
Configure and maintain SIEM data ingestion pipelines, ensuring accurate parsing and normalization of logs from diverse sources.
-
Manage and update device configurations, data source settings, and field mappings to ensure consistent and reliable log ingestion.
-
Perform daily, weekly, and monthly health checks of the SIEM infrastructure, including log ingestion status, storage utilization, and system performance.
-
Create and maintain Standard Operating Procedures (SOPs) for SIEM administration, ensuring operational consistency and faster issue resolution.
-
Apply software patches, updates, and version upgrades for QRadar and Microsoft Sentinel in accordance with vendor guidelines and change management policies.
-
Conduct periodic configuration reviews and cleanup to maintain system efficiency and performance.
-
Design, develop, and deploy custom parsers to handle non-standard or proprietary log formats.
-
Test and validate custom parsers to ensure proper field extraction, normalization, and mapping for accurate analysis.
-
Work closely with SOC analysts, threat hunters, and incident response teams to enhance detection capabilities.
About Inspira Enterprise
-
