At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most challenging problems? If so, lets talk.
We are seeking an experienced and proactive SIEM & SOAR Consultant to design, implement, and optimize Security Information and Event Management (SIEM) and Security Orchestration, Automation and Response (SOAR) solutions. The ideal candidate will work closely with our Security Operations Center (SOC), IT, and other business units to enhance security visibility, automate responses, and streamline incident detection and response processes.x
Deploy, configure, and maintain SIEM platforms
Develop log ingestion pipelines and custom parsers.
Correlate and normalize data to detect threats and anomalies.
Create custom dashboards, alerts, and reports to enhance threat visibility.
Design and implement automated playbooks using SOAR platforms
Integrate SOAR tools with SIEM, ticketing systems, threat intelligence feeds, and EDR tools.
Build workflows for automated incident triage, enrichment, containment, and response.
Collaborate with SOC analysts to refine detection rules and improve alert fidelity.
Perform threat hunting and root cause analysis using SIEM data.
Recommend enhancements based on evolving threat landscapes and attack vectors.
- 2+ years of experience in information security or SOC environment.
- Hands-on experience with at least one enterprise-grade SIEM and one SOAR platform.
- Proficient in scripting languages like Python or PowerShell.
- Understanding of MITRE ATT&CK framework and use-case development.
- Familiarity with cloud security monitoring (AWS, Azure, GCP).
- Strong analytical and troubleshooting skills.
- Excellent communication and documentation abilities.
- SIEM/SOAR specific: Splunk Certified Admin/Architect, Cortex XSOAR Certified Engineer
- Security: CISSP, CISM, CEH, CompTIA Security+
- Cloud: AWS/Azure Security Specialty