SIEM Engineer (QRadar) | Contract | £600 - £750 per day | Inside IR35
We’re looking for an experienced QRadar SIEM Engineer to join a leading insurer on an initial 6 month contract.
You’ll lead the onboarding, tuning and secure operation of their QRadar log ingestion environment, with a focus on reliable, load-balanced, high-availability log collection.
What you’ll be doing:
Onboarding and migrating log sources into QRadar (firewalls, EDR, cloud, authentication, proxies)
Building custom DSMs, log source extensions and custom properties
Designing and managing load balancing across Event Collectors, Event Processors and Data Nodes
Managing EPS and tuning offenses and rules with the SOC, IR and threat detection teams
Monitoring log source health and documenting log flows and architecture
What you’ll need:
Strong hands-on QRadar engineering experience (Console, Event/Flow Processors, Event Collectors, HA, DSMs)
Solid knowledge of log transport and balancing (syslog, TCP/UDP, API collection, DNS round-robin)
QRadar AQL, rule and building block creation
Scripting/automation in Python or shell
Splunk experience is a bonus, not essential
IBM QRadar certifications are desirable
Details:
£600 - £750 P/D (Inside IR 35)
Hybrid role, 2-3 days P/W onsite
Initial 6-Month contract
To apply, message me directly or send your CV to (url removed)