Automation Tester Cypress

<p>Greetings from TCS!!!</p><p>Role: QRadar SOC Analyst</p><p>Experience: 11 to 15</p><p>Location: Delhi</p><p><strong>Role Summary</strong></p><p>The <strong>QRadar SOC Analyst</strong> is responsible for monitoring, triaging, investigating, and responding to security incidents using <strong>IBM QRadar SIEM</strong>. This role ensures real‑time threat detection, proactive hunting, correlation rule tuning, and end‑to‑end incident lifecycle management. The analyst collaborates with Threat Intelligence, Network, Cloud, and Endpoint teams to maintain a strong cybersecurity posture.</p><p><br></p><p><strong>Key Responsibilities</strong></p><p><strong>1. Monitoring & Offense Management</strong></p><ul><li>Monitor security events and alerts through <strong>QRadar dashboards, consoles, and offense queues</strong>.</li><li>Conduct initial and detailed investigation of offenses, determine true/false positives, and escalate as required.</li><li>Perform log enrichment, event correlation analysis, and offense deep‑dive using QRadar tools.</li></ul><p><strong>2. Investigation & Incident Response</strong></p><ul><li>Investigate suspicious activities (credential misuse, lateral movement, DNS anomalies, exfiltration, malware behavior).</li><li>Perform root‑cause analysis (RCA) for confirmed incidents.</li><li>Document incident timelines, artifacts, and technical findings in SOC case management tools.</li><li>Coordinate containment, eradication, and recovery steps with relevant teams.</li></ul><p><strong>3. AQL Search & Log Analysis</strong></p><ul><li>Use <strong>AQL (Ariel Query Language)</strong> for advanced searches, pivoting, and correlation.</li><li>Analyze logs from Windows/Linux servers, network devices, EDR, cloud services, and applications.</li><li>Build actionable dashboards and custom queries to support threat‑hunting and investigations.</li></ul><p><strong>4. Use Case Management & Rule Tuning</strong></p><ul><li>Review and tune <strong>QRadar correlation rules, building blocks, reference sets, and threat models</strong>.</li><li>Optimize detection rules to reduce false positives and improve alert fidelity.</li><li>Work with Threat Intelligence team to integrate IOCs, threat feeds, and enrichment sources.</li></ul><p><strong>5. Threat Hunting</strong></p><ul><li>Conduct proactive hunts using QRadar events, anomalies, traffic patterns, and baselines.</li><li>Look for MITRE ATT&CK TTPs such as privilege escalation, persistence, lateral movement, and command‑and‑control communication.</li><li>Document hunt hypotheses, results, and recommended improvements.</li></ul><p><strong>6. QRadar Administration Support (as needed)</strong></p><ul><li>Validate log source onboarding and troubleshoot ingestion issues.</li><li>Ensure log sources are normalized, parsed correctly, and categorized appropriately.</li><li>Participate in QRadar patching, upgrades, backup/restore tests, and HA validation (if required).</li></ul><p><strong>7. Reporting & Compliance</strong></p><ul><li>Generate daily, weekly, and monthly security reports.</li><li>Provide data for compliance audits (ISO 27001, PCI‑DSS, RBI, GDPR, internal governance).</li><li>Maintain all SOC documentation, SOPs, and detection playbooks.</li></ul><p><br></p><p><strong>Required Skills & Experience</strong></p><p><strong>Technical Skills</strong></p><ul><li>Hands‑on experience with <strong>IBM QRadar SIEM</strong> (offenses, AQL, rules, reference sets, log sources).</li><li>Strong understanding of: </li><li>TCP/IP, DNS, proxy, firewall logs</li><li>Windows/Linux event logs</li><li>Attack vectors and malware behaviors</li><li>MITRE ATT&CK framework</li><li>Cloud logs (Azure/M365, AWS, GCP) is a plus</li><li>Familiarity with EDR/XDR alerts and forensic triage tools.</li></ul><p><br></p><p><strong>Preferred Certifications</strong></p><ul><li>IBM QRadar certifications (e.g., QRadar SIEM Analyst)</li><li>Security+ / CEH / CySA+</li><li>Splunk/Elastic experience (bonus)</li><li>ISO 27001 / SOC2 exposure (advantage)</li></ul><p></p>

Back to blog

Other Jobs To Apply

No other job posts for this day.