Job Description: QRadar SIEM Architect
Role Summary:
We are seeking an experienced QRadar SIEM Architect to lead the design, implementation, optimization, and governance of IBM QRadar deployments across enterprise or MSSP environments. The role focuses on scalable SIEM architecture, integration, and SOC excellence.
Key Responsibilities:
- Design end-to end SIEM architecture including distributed deployments, HA/DR, EPS sizing, and storage strategy.
- Lead implementation and onboarding of log sources and integrations (network, security, cloud).
- Develop detection use cases aligned with MITRE ATT&CK framework.
- Optimize system performance and manage capacity planning.
- Align SIEM with compliance standards such as ISO, PCI-DSS, GDPR.
- Integrate SOAR platforms to enable automation.
- Establish SOC governance, workflows, and KPIs.
- Support presales and client engagements.
Required Skills:
- Deep expertise in IBM QRadar SIEM architecture.
- Strong knowledge of log management, correlation, and AQL
- Experience with integrations (EDR, firewall, cloud platforms)
- Understanding of SOC operations and incident response.
- Strong architectural and stakeholder management skills.
Qualifications:
Bachelor's degree in IT/Cybersecurity or equivalent. Preferred certifications include IBM QRadar Certification, CISSP, CISM.
Experience:
8 to 12 years in cybersecurity with at least 5+ years in SIEM architecture (QRadar preferred). Experience in MSSP and large-scale deployments is preferred.
Key Deliverables:
- Scalable SIEM deployment
- Optimized EPS utilization
- Improved detection coverage
- False positive reduction
- Successful integrations
- SOC maturity improvements