Skip to content
mimi

Cortex XSIAM Engineer

Programmers.io

Dallas · On-site Full-time Senior 3w ago

About the role

Experience / Qualifications – Cortex XSIAM

  • Exceptional written and verbal communication and presentation skills, with the ability to articulate complex technical concepts to both technical and non-technical stakeholders.
  • 6+ years of hands-on experience deploying and managing SIEM and SOAR solutions in large-scale enterprise environments, including direct experience with Palo Alto Networks Cortex XSIAM.
  • Proven expertise in onboarding log sources and integrating them into Cortex XSIAM using Broker VMs, XDR Collectors, and custom ingestion methods.
  • Proficient in developing and managing XSIAM Data Models, including field mapping, enrichment, normalization, and schema standardization across multiple data sources.
  • Strong experience crafting and optimizing detection logic using XQL (XSIAM Query Language) to build high-fidelity correlation rules, dashboards, and proactive threat hunting queries.
  • Solid understanding of Palo Alto XDR endpoint integration, sensor health monitoring, and policy tuning for enhanced endpoint visibility.
  • Experienced in event collection strategy, log onboarding, log tuning, and normalization to ensure high-quality and actionable data within the XSIAM platform.
  • Demonstrated ability to translate security monitoring requirements into use cases and actionable detection content, aligned with MITRE ATT&CK and industry best practices.
  • Familiarity with broader SIEM technologies (e.g., Splunk, IBM QRadar) and how they compare/contrast with Cortex XSIAM architecture and capabilities.
  • Strong grasp of security operations workflows, alert triage, threat detection, incident response, and automation within XSIAM.
  • Hands-on experience creating and managing security dashboards and visualizations to provide meaningful insights for SOC teams and leadership.
  • Expertise in Regular Expressions (Regex), JSON parsing, and log analysis to derive context-rich detection strategies.
  • Working knowledge of generating performance and health reports across log source status, ingestion rates, data pipeline performance, and detection coverage.
  • Relevant certifications (e.g., Palo Alto Networks Certified XSIAM Engineer or XSIAM Analyst or XSIAM EDU-270). Bachelor’s degree in computer science, Information Security, or related field is a plus.

Skills

Cortex XSIAMDockerIBM QRadarJSONMITRE ATT&CKPalo Alto NetworksPalo Alto XDRRegexSIEMSOARSplunkXQL

Don't send a generic resume

Paste this job description into Mimi and get a resume tailored to exactly what the hiring team is looking for.

Get started free