Hiring · XSIAM Engineer

XSIAM Engineer

Modernize enterprise and federal Security Operations Centers with Palo Alto Networks Cortex XSIAM. Deploy AI-driven detection, automate incident response, engineer high-fidelity security content, and turn complex endpoint, cloud, and network telemetry into decisive action.

Cortex XSIAMCortex XDRCortex XSOARXpanseXQLMITRE ATT&CKPython / PowerShellSOAR Playbooks
What you'll own

Engineer the AI-driven security operations platform

Own deployment, detection, automation, platform tuning, proactive threat hunting, and customer enablement across the Cortex XSIAM ecosystem—turning complex security telemetry into faster, more confident response.

01 · Deploy

Platform Deployment & Migration

Integrate Cortex XSIAM, XDR, XSOAR, and Xpanse, then lead secure migrations from legacy SIEM environments into a unified operations platform.

02 · Detect

Detection & Content Engineering

Build correlation rules and behavioral analytics mapped to MITRE ATT&CK, continuously improving coverage, fidelity, and investigative context.

03 · Automate

Automation & Playbooks

Engineer resilient SOAR workflows for alert triage, containment, enrichment, escalation, and response—reducing manual effort and time to action.

04 · Tune

Log Ingestion & Tuning

Onboard diverse log sources, parse and normalize telemetry, validate data quality, and tune detections to reduce false positives without losing signal.

05 · Hunt

Threat Hunting with XQL

Use XQL for deep cross-source analysis, hypothesis-driven investigation, and proactive hunting that exposes stealthy behaviors before they escalate.

06 · Enable

Customer Enablement

Serve as the XSIAM SME with practical guidance, analyst training, operational playbooks, and maturity assessments that build lasting customer capability.

Typical Requirements & Qualifications

XSIAM depth. Security engineering discipline.

Bring proven detection-platform experience, automation fluency, and the architectural judgment to strengthen modern security operations at enterprise scale.

Enterprise platform tenure

3–5+ years working with enterprise SIEM and SOAR platforms in complex security operations environments.

Detection platform depth

Hands-on experience with Cortex XSIAM, Splunk, or Microsoft Sentinel across detection, investigation, and response workflows.

Querying & automation

Practical XQL expertise plus scripting ability in Python, PowerShell, or JavaScript for enrichment and automation.

Security architecture

Strong EDR and NDR knowledge with a clear understanding of endpoint and cloud security architecture.

Education & foundation

Bachelor’s degree in Computer Science or Cybersecurity, or equivalent professional experience.

Preferred credentials

Palo Alto Networks Certified XSIAM Engineer or CISSP credentials are preferred.

JOIN ENTELLIGENCE

Modernize the SOC with Cortex XSIAM

Bring your XSIAM, SIEM/SOAR, detection engineering, automation, and threat-hunting experience to Entelligence. We’re looking for engineers ready to transform security operations, accelerate response, and help enterprise SOC teams achieve measurable security outcomes.

AI-driven security operations

Unify detection and response across data, analytics, incidents, and investigations with Cortex XSIAM.

Automation that matters

Engineer production-grade playbooks that remove repetitive work and drive faster, more consistent containment.

Expert-led customer impact

Enable SOC analysts with practical expertise while improving customer security maturity, workflows, and outcomes.

Full Name *
Email Address *
Phone Number
LinkedIn Profile
Résumé *
Powered byhireEZ