Orbus International
Website:
cybersectrainings.com
Company:
https://www.linkedin.com/company/orbusinternational
Seniority: Mid-Senior level
Industries: IT Services and IT Consulting, Technology, Information and Media, and Computer and Network Security
Job details:
We are looking for a skilled Palo Alto Cortex XSIAM Engineer with hands-on implementation and deployment experience to design, implement, configure, and optimize Palo Alto Cortex XSIAM solutions for enterprise customers. The ideal candidate should have strong experience in SIEM, SOAR, XDR, security automation, log onboarding, and threat detection engineering.
Key Responsibilities
- Lead end-to-end implementation and deployment of Palo Alto Cortex XSIAM.
- Design and configure XSIAM architecture based on customer security requirements.
- Integrate multiple data sources including:
- Firewalls
- Endpoints
- Active Directory / Identity Providers
- Cloud platforms (AWS, Azure, GCP)
- Email Security
- Third-party security tools
- Configure log ingestion, normalization, parsing, and data modeling.
- Develop and customize:
- Correlation Rules
- Detection Rules
- Automation Playbooks
- Dashboards and Reports
- Implement SOAR workflows for automated incident response.
- Configure integrations using REST APIs and Marketplace content packs.
- Perform health checks, troubleshooting, tuning, and optimization of the XSIAM platform.
- Support migration from legacy SIEM/SOAR platforms such as Splunk, QRadar, Microsoft Sentinel, or Cortex XDR to Cortex XSIAM.
- Work closely with SOC teams for threat detection, threat hunting, incident response, and alert tuning.
- Prepare technical documentation, solution design, and deployment guides.
Required Skills
- 4+ years of Cyber Security/SOC experience.
- Minimum 2+ years of hands-on implementation experience with Palo Alto Cortex XSIAM.
- Strong understanding of:
- SIEM
- SOAR
- XDR
- SOC Operations
- Incident Response
- Experience onboarding and integrating log sources.
- Knowledge of detection engineering and correlation rule creation.
- Experience developing automation playbooks.
- Good understanding of MITRE ATT&CK Framework.
- Hands-on experience with REST APIs and third-party integrations.
- Knowledge of Windows, Linux, Active Directory, DNS, DHCP, Networking, and TCP/IP.
- Scripting knowledge in Python, PowerShell, or Bash.
- Experience with cloud environments (AWS/Azure/GCP).
- Excellent troubleshooting and analytical skills.
Preferred Skills
- Experience with Cortex XDR and Cortex XSOAR.
- Migration experience from Splunk, QRadar, Sentinel, ArcSight, or other SIEM platforms.
- Exposure to EDR technologies.
- Experience in Threat Hunting and Detection Engineering.
- Knowledge of security frameworks such as NIST, CIS, and MITRE ATT&CK.
- Palo Alto XSIAM Engineer Certification or PCNSE certification is preferred.
Click on Apply to know more.