
SIEM / SOAR Platform Administrator (RARR Job 6256)
Job Skills
Job Description
We are looking for a skilled SIEM / SOAR Platform Administrator to manage, maintain, and optimize Security Operations Center (SOC) monitoring platforms. The ideal candidate should have hands-on experience in administering SIEM solutions, security log management, platform integrations, troubleshooting, and performance optimization.
The candidate will be responsible for ensuring the availability, reliability, and efficiency of cybersecurity monitoring tools used for threat detection and incident response.
Key Responsibilities:
- Manage the complete lifecycle of SOC platforms, including deployment, hardening, patch management, capacity planning, and high-availability configuration across Production, Disaster Recovery (DR), and Staging environments.
- Administer and support enterprise security platforms, including SIEM, SOAR, UEBA, NDR, Deception, and Attack Surface Management (ASM), to ensure optimal performance and availability.
- Design, implement, and maintain log ingestion pipelines, including connectors, parsers, normalization rules, enrichment feeds, and integrations, ensuring seamless onboarding of log sources with minimal data loss.
- Configure and enforce security controls such as Role-Based Access Control (RBAC), certificate-based authentication, API key management, encryption mechanisms, and audit logging in line with organizational and regulatory compliance requirements.
- Monitor platform health, performance, license utilization, ingestion rates, and cluster stability through dashboards and automated alerting mechanisms. Prepare periodic performance and capacity planning reports.
- Develop and maintain integrations between various SOC platforms using APIs, webhooks, and data-forwarding mechanisms to support end-to-end detection, enrichment, automation, and incident response workflows.
- Plan and execute platform upgrades, migrations, and enhancement activities with minimal operational disruption while maintaining system availability.
- Create and maintain operational documentation, runbooks, standard operating procedures (SOPs), and disaster recovery plans. Participate in DR testing and recovery validation exercises.
Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. Master's degree preferred.
- Minimum 3 years of hands-on experience in the administration and support of enterprise SIEM platforms within a Security Operations Center (SOC) environment.
- Experience working with at least one leading SIEM platform such as Splunk, IBM QRadar, Microsoft Sentinel, ArcSight, or LogRhythm.
- Exposure to SOAR platforms and security monitoring technologies in production environments.
- Strong knowledge of Linux and Windows server administration.
- Experience with log pipeline technologies such as Kafka, Logstash, Cribl, or similar log management solutions.
- Understanding of security monitoring, log management, incident detection, and SOC operations.
Preferred Skills
- SIEM Administration (Splunk, QRadar, Sentinel, ArcSight, LogRhythm)
- SOAR Platforms
- UEBA Solutions
- NDR Technologies
- API Integrations and Automation
- Scripting (Python, PowerShell, Bash)
- High Availability and Disaster Recovery Concepts
- Security Compliance Standards and Audit Requirements
Stay Ahead.
Never Miss the Right Opportunity.
Manage your job alerts, preferences, and subscription anytime.
Matching Jobs
Stay Ahead.
Never Miss the Right Opportunity.
Manage your job alerts, preferences, and subscription anytime.