1

Cortex Xdr Jobs in Dallas, TX (NOW HIRING)

Lead POC for Cortex XDR/XSIAM: scenario design, detection validation, and operational fit * Evaluate Prisma Access (SASE: ZTNA, SWG, CASB) and Prisma Cloud (CSPM/CWPP) * Produce technical assessments ...

New

Lead POC for Cortex XDR/XSIAM: scenario design, detection validation, and operational fit * Evaluate Prisma Access (SASE: ZTNA, SWG, CASB) and Prisma Cloud (CSPM/CWPP) * Produce technical assessments ...

New

Transformation Success Engineer

Dallas, TX · On-site

$198K - $273K/yr

Hands-on expertise with the Palo Alto Networks portfolio (Cortex XDR/XSIAM, Prisma Cloud, or Strata) or direct competitive migration experience. * Strong technical background in security automation ...

New

Experience with SIEM/EDR platforms (Microsoft Sentinel, Defender XDR, Splunk, Elastic, CrowdStrike, Chronicle, Cortex XSIAM) is preferred. * Experience with cloud security tools (Wiz, Prisma Cloud ...

Cortex Xdr information

See Dallas, TX salary details

$72.7K

$120.7K

$162.2K

How much do cortex xdr jobs pay per year?

As of Aug 16, 2026, the average yearly pay for cortex xdr in Dallas, TX is $120,694.00, according to ZipRecruiter salary data. Most workers in this role earn between $101,900.00 and $139,500.00 per year, depending on experience, location, and employer.

What is a Cortex XDR?

A Cortex XDR job typically involves working with Palo Alto Networks' Cortex XDR platform to detect, investigate, and respond to cybersecurity threats. Professionals in this role analyze security events, manage endpoint protection, and configure security policies to prevent breaches. They may also work with automation tools, threat intelligence, and forensic analysis to enhance an organization's security posture. Strong knowledge of SIEM, EDR, and incident response methodologies is often required.

What are the key skills and qualifications needed to thrive in the Cortex XDR position?

To excel as a Cortex XDR Specialist, you need a deep understanding of cybersecurity principles, threat detection, and incident response, often backed by a degree in information security or computer science. Familiarity with Palo Alto Networks Cortex XDR platform, SIEM tools, and certifications such as CISSP or PCNSE are highly valued. Strong analytical thinking, attention to detail, and effective communication skills are essential for interpreting data and collaborating with IT teams. These competencies ensure prompt identification and remediation of security threats, maintaining the organization's cyber resilience.

What does a Cortex XDR specialist do?

A typical day for a Cortex XDR Specialist involves proactively monitoring security alerts, investigating suspicious activities, and responding to potential incidents using the Cortex XDR platform. Collaboration is frequent, as you’ll work closely with incident response teams, IT staff, and sometimes end users to gather insights and implement mitigation strategies. You may also spend time tuning security policies, preparing threat reports, or participating in tabletop exercises to ensure ongoing readiness. The role is dynamic and requires a balance of technical investigation and clear communication to help protect the organization’s digital assets.

What are the most commonly searched types of Cortex Xdr jobs in Dallas, TX?

The most popular types of Cortex Xdr jobs in Dallas, TX are:

What job categories do people searching Cortex Xdr jobs in Dallas, TX look for?

The top searched job categories for Cortex Xdr jobs in Dallas, TX are:

What cities near Dallas, TX are hiring for Cortex Xdr jobs?

Cities near Dallas, TX with the most Cortex Xdr job openings:

Infographic showing various Cortex Xdr job openings in Dallas, TX as of August 2026, with employment types broken down into 92% Full Time, 2% Part Time, and 6% Contract. Highlights an 84% Physical, 5% Hybrid, and 11% Remote job distribution, with an average salary of $120,694 per year, or $58 per hour.

Cybersecurity Operations Engineer

Momentum

Dallas, TX

Full-time

Medical, Life, Retirement, PTO

Posted yesterday

New


Job description

The Opportunity 

We are seeking a Cybersecurity Operations Engineer to run security operations across a holding company and its portfolio of businesses while leading the technical evaluation of our next-generation security stack.

This role owns MDR operations, incident response, endpoint security, and cloud security posture today, while driving proof-of-concept (POC) efforts for Palo Alto Cortex XDR/XSIAM and Prisma Access as we evaluate consolidating our MDR and moving toward a unified SASE and cloud security architecture.

You will work closely with the Cybersecurity Manager and vCISO, collaborate with the Sr. IT Operations Engineer on identity and endpoint controls, and partner with portfolio company IT and engineering teams. This role will also address critical gaps including cloud security strategy, CIS hardening, CASB/DLP, vulnerability management, and continuous pentesting.

Join us in this Full-time role, based in our Dallas Office at the Link: 2601 Olive Street, Dallas, TX. Be part of a vibrant community where amazing people, data & insights, and perpetual innovation converge to shape the future of digital commerce!

About This Role at Momentum

What You'll Do

MDR Operations & Incident Response
  • Serve as primary liaison to the MDR provider; own escalation workflows, alert triage, and SLA accountability across all entities
  • Act as primary incident responder, leading containment, eradication, recovery, and post-incident documentation
  • Maintain and test incident response playbooks aligned to MITRE ATT&CK
  • Lead tabletop exercises in coordination with the vCISO and drive IR maturity across portfolio companies
  • Lead technical evaluation of Palo Alto Cortex XSIAM, including POC design, capability assessment, and transition planning
Endpoint Security & Hardening
  • Own endpoint security posture across ~1,400 macOS and 300 Windows devices
  • Eliminate local admin access across the macOS fleet (priority initiative)
  • Manage Jamf, Jamf Protect, and Jamf Connect; maintain CrowdStrike configurations and detection tuning
  • Define and implement CIS baselines and hardening standards across endpoints and servers
Palo Alto Platform Evaluation
  • Lead POC for Cortex XDR/XSIAM: scenario design, detection validation, and operational fit
  • Evaluate Prisma Access (SASE: ZTNA, SWG, CASB) and Prisma Cloud (CSPM/CWPP)
  • Produce technical assessments covering capability gaps, integration complexity, migration risk, and total cost of ownership
  • Own implementation if selected
Cloud Security & Vulnerability Management
  • Own cloud security strategy across AWS, GCP, and Azure
  • Expand CloudTrail and GuardDuty coverage across environments
  • Secure CI/CD pipelines (GitHub Actions), enforce secrets management and least-privilege IAM
  • Evaluate and implement vulnerability management platform; enforce remediation SLAs and reporting
CASB, DLP & Detection Engineering
  • Lead CASB and DLP vendor evaluation and implementation
  • Maintain and improve CrowdStrike Next-Gen SIEM/LogScale detection rules
  • Map detection coverage to MITRE ATT&CK (focus on IAM abuse, lateral movement, data exfiltration)
  • Evaluate and implement continuous pentesting platforms (Pentera, NodeZero, Horizon3)
Portfolio Company Engagement
  • Conduct technical security assessments across portfolio companies
  • Support DevSecOps and secure SD

What We're Looking For

Required Qualifications

  • 7-9 years of experience in cybersecurity operations, security engineering, or senior SOC/IR roles

  • Hands-on MDR experience (alert triage, escalation workflows, MSSP management)

  • Deep expertise with CrowdStrike Falcon (EDR, detection tuning, SIEM/LogScale)

  • Endpoint security at scale (macOS with Jamf, Windows with Intune)

  • Proven incident response leadership (led incidents end-to-end)

  • Cloud security experience in AWS and either GCP or Azure (IAM, CloudTrail, GuardDuty, secrets management)

  • Experience leading enterprise security platform evaluations and POCs

  • Familiarity with SASE, CASB, or SSE architectures

  • Active daily use of AI and automation (100% internal AI adoption; required)

  • Experience in private equity, holding company, or multi-entity environments preferred

Preferred Qualifications

  • Palo Alto Networks experience (Cortex XDR, Prisma Access, Prisma Cloud); PCNSE preferred

  • Jamf Protect and Jamf Connect at scale

  • Continuous pentesting platforms (Pentera, NodeZero, Horizon3)

  • DLP tooling (policy design, data classification, endpoint/cloud enforcement)

  • MITRE ATT&CK expertise (detection mapping, threat modeling, tabletop exercises)

  • CIS benchmark implementation and enterprise-scale hardening

Preferred Certifications

  • PCNSE

  • GCIH

  • GCIA

  • CrowdStrike CCFA / CCFR

  • Or equivalent certifications

Commitment to Diversity and Inclusion at Momentum

At Momentum, our commitment to change for the better is reflected in our dedication to fostering a culture of belonging, inclusion, and diversity. We recognize diversity and inclusion as key components of our company's success and growth. Recognizing the ongoing journey ahead, we are determined to make lasting impacts through the collective efforts of our Leadership team, People & Culture team, and every employee.

Momentum is an equal opportunity employer, considering all qualified applicants regardless of characteristics protected by law. These include, but are not limited to, race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, color, ancestry, and Veteran status. We actively seek qualified applicants from diverse backgrounds, with no consideration of criminal histories, in alignment with applicable legal requirements.

Should a reasonable accommodation be necessary for the application process and beyond, we are eager to review and provide reasonable accommodations as needed, in compliance with applicable laws.

Total Rewards

At Momentum, we prioritize the well-being of the whole individual. We are committed to supporting our people in every moment that matters on their journey with us! We are pleased to offer a comprehensive total rewards package designed to provide protection, peace of mind, and a focus on overall well-being while helping our people plan for the future.

The base salary range for this position may vary based on location. Actual compensation will be determined by role, level, and location, considering additional factors such as job-related skills, experience, and relevant education or training. For roles eligible for remote work, the base salary is tailored to the designated work location. In addition to the base salary, candidates may be eligible to receive a discretionary annual bonus, determined based on both the company's business performance and individual contributions. The People & Culture team will provide specific details during the hiring process.

We take pride in offering a comprehensive benefits package for our full-time employees, encompassing healthcare benefits, a 401(k) plan with an employer match, short-term and long-term disability coverage, life insurance, paid time off, parental leave, and various paid holidays, among other perks.

Our workplace offers opportunities for involvement in a wide range of challenging and impactful projects, across diverse industries and business models, fostering career advancement and development within our growing  organization. The culture is highly collaborative and supportive, contributing to a fulfilling professional journey.

Note on Confidentiality

Any personal data collected during the application process will be treated with the utmost confidentiality and privacy.