CyberGate Defense is hiring! We are looking for a highly skilled SIEM Admin IBM QRadar/ Splunk to join our technical team in Dubai. If you are passionate about high-performance log orchestration, advanced use case engineering, and scaling multi-tenant security architectures, we want to hear from you.
As a SIEM Admin at CyberGate, you will be the backbone of our detection capabilities, ensuring that our IBM QRadar ecosystem is optimized, resilient, and ahead of the threat landscape.
🚀 Key Responsibilities
1️⃣ Deployment & Architecture
Lead the deployment of QRadar Consoles, Event/Flow Processors, and Collectors.
Design distributed architectures based on EPS/FPS sizing for high-availability (HA) and multi-tenant MSS environments.
2️⃣ Log Source Onboarding & Validation
Integrate complex log sources across Infra, Network, Cloud, and Apps.
Expert configuration of DSMs, custom log sources, and WinCollect deployments.
Validate end-to-end log parsing and event categorization.
3️⃣ Use Case Engineering (MITRE ATT&CK)
Develop and deploy sophisticated correlation rules aligned with the MITRE ATT&CK framework.
Create building blocks and reference sets while performing continuous fine-tuning to eliminate false positives.
4️⃣ Platform Maintenance & Optimization
Perform system health checks, patching, and version upgrades.
Monitor license utilization (EPS/FPS) and manage backup/restore validations.
5️⃣ SOC & MSS Excellence
Partner with the SOC team to drive detection maturity and coverage.
Implement feedback-driven tuning to support audit and compliance requirements.
🎯 What We’re Looking For
Technical Mastery: Deep hands-on experience with IBM QRadar architecture and administration.
Problem Solvers: Ability to troubleshoot complex parsing issues and performance bottlenecks.
Certification: IBM Certified Associate/Professional Administrator - QRadar SIEM is highly preferred.
The "Detective" Mindset: A passion for validating that every event from source to offense is meaningful.