P
Cortex XSIAM Engineer
Programmers.io
Dallas · On-site Full-time Senior 3w ago
About the role
Experience / Qualifications – Cortex XSIAM
- Exceptional written and verbal communication and presentation skills, with the ability to articulate complex technical concepts to both technical and non-technical stakeholders.
- 6+ years of hands-on experience deploying and managing SIEM and SOAR solutions in large-scale enterprise environments, including direct experience with Palo Alto Networks Cortex XSIAM.
- Proven expertise in onboarding log sources and integrating them into Cortex XSIAM using Broker VMs, XDR Collectors, and custom ingestion methods.
- Proficient in developing and managing XSIAM Data Models, including field mapping, enrichment, normalization, and schema standardization across multiple data sources.
- Strong experience crafting and optimizing detection logic using XQL (XSIAM Query Language) to build high-fidelity correlation rules, dashboards, and proactive threat hunting queries.
- Solid understanding of Palo Alto XDR endpoint integration, sensor health monitoring, and policy tuning for enhanced endpoint visibility.
- Experienced in event collection strategy, log onboarding, log tuning, and normalization to ensure high-quality and actionable data within the XSIAM platform.
- Demonstrated ability to translate security monitoring requirements into use cases and actionable detection content, aligned with MITRE ATT&CK and industry best practices.
- Familiarity with broader SIEM technologies (e.g., Splunk, IBM QRadar) and how they compare/contrast with Cortex XSIAM architecture and capabilities.
- Strong grasp of security operations workflows, alert triage, threat detection, incident response, and automation within XSIAM.
- Hands-on experience creating and managing security dashboards and visualizations to provide meaningful insights for SOC teams and leadership.
- Expertise in Regular Expressions (Regex), JSON parsing, and log analysis to derive context-rich detection strategies.
- Working knowledge of generating performance and health reports across log source status, ingestion rates, data pipeline performance, and detection coverage.
- Relevant certifications (e.g., Palo Alto Networks Certified XSIAM Engineer or XSIAM Analyst or XSIAM EDU-270). Bachelor’s degree in computer science, Information Security, or related field is a plus.
Skills
Cortex XSIAMDockerIBM QRadarJSONMITRE ATT&CKPalo Alto NetworksPalo Alto XDRRegexSIEMSOARSplunkXQL
Don't send a generic resume
Paste this job description into Mimi and get a resume tailored to exactly what the hiring team is looking for.
Get started free