1

Cortex Xdr Jobs (NOW HIRING)

$120 - $180/hr

Configure and deploy Cortex XDR, XSIAM, and XSOAR, translating architecture and design decisions into a working environment * Lead endpoint agent rollout, log source and data onboarding, and ...

New

Senior Staff Engineer (Cortex XDR)

$107K - $146K/yr

The Senior Staff Engineer at Cortex XDR will serve as a technical authority, focusing on the stability and performance of Windows endpoint agents while managing critical escalations and ensuring ...

New

next page

Showing results 1-20

Cortex Xdr information

See salary details

$73.5K

$122K

$164K

How much do cortex xdr jobs pay per year?

As of Aug 15, 2026, the average yearly pay for cortex xdr in the United States is $122,008.00, according to ZipRecruiter salary data. Most workers in this role earn between $103,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is a Cortex XDR?

A Cortex XDR job typically involves working with Palo Alto Networks' Cortex XDR platform to detect, investigate, and respond to cybersecurity threats. Professionals in this role analyze security events, manage endpoint protection, and configure security policies to prevent breaches. They may also work with automation tools, threat intelligence, and forensic analysis to enhance an organization's security posture. Strong knowledge of SIEM, EDR, and incident response methodologies is often required.

What are the key skills and qualifications needed to thrive in the Cortex XDR position?

To excel as a Cortex XDR Specialist, you need a deep understanding of cybersecurity principles, threat detection, and incident response, often backed by a degree in information security or computer science. Familiarity with Palo Alto Networks Cortex XDR platform, SIEM tools, and certifications such as CISSP or PCNSE are highly valued. Strong analytical thinking, attention to detail, and effective communication skills are essential for interpreting data and collaborating with IT teams. These competencies ensure prompt identification and remediation of security threats, maintaining the organization's cyber resilience.

What does a Cortex XDR specialist do?

A typical day for a Cortex XDR Specialist involves proactively monitoring security alerts, investigating suspicious activities, and responding to potential incidents using the Cortex XDR platform. Collaboration is frequent, as you’ll work closely with incident response teams, IT staff, and sometimes end users to gather insights and implement mitigation strategies. You may also spend time tuning security policies, preparing threat reports, or participating in tabletop exercises to ensure ongoing readiness. The role is dynamic and requires a balance of technical investigation and clear communication to help protect the organization’s digital assets.

What cities are hiring for Cortex Xdr jobs?

Cities with the most Cortex Xdr job openings:

What are the most commonly searched types of Cortex Xdr jobs?

The most popular types of Cortex Xdr jobs are:

What states have the most Cortex Xdr jobs?

States with the most job openings for Cortex Xdr jobs include:

Infographic showing various Cortex Xdr job openings in the United States as of August 2026, with employment types broken down into 91% Full Time, 1% Part Time, and 8% Contract. Highlights an 84% Physical, 5% Hybrid, and 11% Remote job distribution, with an average salary of $122,008 per year, or $58.7 per hour.

Palo Alto Cortex XSIAM and XDR platform engineer W-2 ONLY

United Global Technologies

Columbia, SC • Remote

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

W-2 ONLY No subs, No sponsorship

This position is 100% remote and will participate in a monthly on-call rotation supporting a 24x7 security operations center serving multiple agencies. Other after-hours work may be required as needed.

Primarily assist in the planning, design, deployment, administration and operational support of enterprise SIEM and XDR capabilities, including:

  • Palo alto cortex XSIAM and cortex XDR platform engineering, configuration, optimization and troubleshooting.
  • Multi-tenant agency onboarding, tenant-specific configuration, role-based access, data
  • segregation, dashboards and reporting.
  • Detection engineering, correlation rules, analytics, threat-hunting queries, watchlists, suppression logic and false-positive reduction.

Secondarily assist in the planning, design, deployment and operational support of log management and security data pipelines, including:

  • CRIBL data modeling, log pipeline design, routing, parsing, normalization, enrichment, filtering, replay and ingestion.
  • Onboarding and health monitoring of cloud, endpoint, network, identity, SAAS and custom application telemetry.
  • Log volume, retention, performance and cost optimization while maintaining security and compliance requirements.
  • Integrations with ticketing, case management, notification, identity, threat intelligence and other enterprise systems as needed.
  • Develop, test, deploy and maintain automated response workflows and playbooks for enrichment, triage, containment, escalation, notifications, case management and incident response.
  • Create and maintain operational runbooks, standard operating procedures, escalation matrices, troubleshooting guides, architecture diagrams, data-flow documentation, use-case catalogs and analyst knowledge articles.
  • Support tier 1 through tier 3 soc analysts and incident responders through platform troubleshooting, detection tuning, threat hunting, technical escalation, knowledge transfer and shift handoffs.
  • Monitor and report on ingestion health, platform availability, alert volumes, detection coverage, false positives, service levels, mean time to detect, mean time to respond and tenant-specific operational metrics.
  • Ensure high availability, resilience, backup, recovery, lifecycle management and controlled change processes for SIEM, XDR and supporting log pipeline services.
  • Collaborate with security architects, engineers, analysts and agency stakeholders to align solutions with business goals, industry-standard frameworks, regulatory requirements and organizational risk tolerance.


Work Location: Role is 100% Remote. Preference will be given to local candidates who can come to the office as needed for client and departmental meetings, trainings, and other onsite activities.

Open to nationwide candidates. All travel-related costs for onsite work will be the responsibility of the resource no matter the frequency of onsite work.

Required Skills:

  • 5+ years of experience support large IT environments and/or system deployments
  • Hands-on experience with Palo Alto Cortex, XSIAM, and Cortex XDR design, implementation, administration and operational support.
  • Experience engineering and supporting SIEM capabilities for multi-tenant environments and 24x7 Security Operations Center operations.
  • Experience developing and tuning detections, correlation rules, analytics, threat-hunting queries, dashboards, reporting and alert suppression logic.
  • Experience creating and managing complex playbooks
  • CRIBL Data Modeling, log pipeline design, parsing, normalization, enrichment, routing and ingestion.
  • Experience developing automation, integrations, playbooks and response workflows using scripting languages such as Python and Bash.
  • Experience onboarding and troubleshooting telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows and custom application sources.
  • Strong understanding of enterprise security architecture, incident response, networking, access control, secure system design and industry-standard cybersecurity frameworks.

Education: Bachelor's Degree in an Information Technology or Information Security related field (8+ years of relevant work experience may be substituted in lieu of education).

Preferred Skills:

  • Palo Alto Cortex, CRIBL or other relevant SIEM/security platform certification
  • Hands-on experience operating Cortex XSIAM and Cortex XDR in a large, multi-tenant environment.
  • Hands-on CRIBL administration, data modeling and log pipeline optimization experience.
  • Experience supporting Tier 1 through Tier 3 SOC analysts, threat hunting, incident response and 24x7 operational handoffs.
  • Familiarity with industry-standard security and compliance frameworks and experience developing playbooks, runbooks, procedures and technical documentation.

Certification:
CISSP, Security+ or GIAC certification