More jobs:
Cortex XSIAM Security Engineer
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-08-07
Listing for:
CELESTIAL INNOVATIONS GROUP LLC
Full Time
position Listed on 2026-08-07
Job specializations:
-
IT/Tech
Cybersecurity, Security Management & Operations
Job Description & How to Apply Below
Benefits
- 401(k)
- Competitive salary
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Celestial Innovations Group (CIG) is seeking a skilled Cortex XSIAM Security Engineer to deploy, configure, and operationalize Palo Alto Networks Cortex XSIAM for federal and enterprise clients. This role is at the center of CIG's AI-driven Security Operations practice, enabling clients to modernize their SOC by consolidating SIEM, XDR, SOAR, UEBA, ASM, and TIP capabilities into a single, converged platform.
Key Responsibilities Platform Deployment & Integration- Lead end-to-end deployment of Cortex XSIAM for federal and enterprise clients, including data source onboarding, log ingestion, and normalization.
- Integrate XSIAM with existing security ecosystem tools including firewalls, endpoints, cloud platforms, identity providers, and ticketing systems.
- Configure data pipelines to ingest and normalize telemetry from diverse sources (endpoints, network, cloud, identity) into XSIAM's unified data model.
- Migrate clients from legacy SIEM platforms to Cortex XSIAM, ensuring continuity of detection coverage and compliance reporting.
- Build and tune correlation rules, behavioral analytics, and ML-based detection models within XSIAM to reduce false positive rates and improve detection fidelity.
- Develop and maintain XSIAM analytics leveraging XQL (Extended Query Language) to extract actionable insights from security telemetry.
- Map detection content to MITRE ATT&CK framework, ensuring coverage across all relevant tactics, techniques, and procedures (TTPs).
- Configure AI Smart Scoring and technique-based incident grouping to reduce alert fatigue and prioritize analyst workload effectively.
- Design, build, and maintain SOAR automation playbooks within XSIAM to automate triage, enrichment, and remediation workflows.
- Leverage Cortex Marketplace content packs and develop custom integrations as needed to support client-specific security processes.
- Implement dev/prod playbook lifecycle management to ensure safe testing and controlled promotion of automation content.
- Continuously improve automation coverage, targeting measurable reductions in manual analyst workload.
- Serve as escalation point for complex incident investigations, using XSIAM causality chains and full attack-story visualizations to support rapid remediation.
- Coordinate with client SOC teams during active incidents, leveraging XSIAM's embedded automation and enrichment capabilities.
- Support Attack Surface Management (ASM) functions to proactively identify and remediate client exposure.
- Utilize integrated Threat Intelligence Platform (TIP) capabilities, including Unit 42 threat feeds, to enrich alerts and inform response priorities.
- Serve as a trusted technical advisor to federal and commercial clients on XSIAM capabilities, roadmap, and SOC modernization strategy.
- Produce SOC performance dashboards, compliance reports, and executive summaries within XSIAM to support client governance requirements.
- Conduct training and knowledge transfer sessions to build client SOC team proficiency on the XSIAM platform.
- Support CIG business development efforts by contributing to proposals, demos, and technical capability briefings for prospective clients.
- 3+ years of hands‑on experience with Palo Alto Networks Cortex XDR or Cortex XSIAM in an enterprise or federal environment.
- Demonstrated experience deploying or administering SIEM platforms (Splunk, Microsoft Sentinel, IBM QRadar, or equivalent).
- Proficiency with XQL or comparable query languages for log analysis and threat hunting.
- Working knowledge of SOAR concepts and experience building security automation playbooks.
- Understanding of EDR, NDR, and UEBA technologies and how they feed into a converged SOC platform.
- Familiarity with MITRE ATT&CK framework and its application to detection engineering.
- Active Secret clearance (minimum); TS/SCI preferred for federal engagements.
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field, OR equivalent…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×