2

Full Time Cortex Xdr Jobs (NOW HIRING)

Job Type Full-time Description Binary Defense is seeking an experienced and motivated Detection ... Preferred • Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction ...

Senior System Engineer

Manassas, VA · On-site

$97K - $134K/yr

Job Type Full-time Description Senior System Engineer Manassas, VA Full-time, Exempt Security ... CORTEX XDR * NetScout * NetApp Storage Administration * Keyfactor * LDAP * PKI / TLS * Nessus ...

Senior System Engineer

Manassas, VA · Hybrid

$97K - $134K/yr

Description Senior System Engineer Manassas, VA Full-time, Exempt Security Clearance: Top Secret ... CORTEX XDR * NetScout * NetApp Storage Administration * Keyfactor * LDAP * PKI / TLS * Nessus ...

Senior Security Engineer

Clackamas, OR · On-site

$120K - $165K/yr

IT Group Employment Type: Full Time Location: Clackamas Reporting To: Mark Thorsrud Description At ... Palo Alto Security toolset experience (Strata, IoT, PanOS, Cortex XDR) * Experience with Microsoft ...

Senior System Engineer

Manassas, VA · On-site

$97K - $134K/yr

Senior System Engineer Manassas, VA Full-time, Exempt Security Clearance: Top Secret Does working ... CORTEX XDR * NetScout * NetApp Storage Administration * Keyfactor * LDAP * PKI / TLS * Nessus ...

Full Time Cortex Xdr information

See salary details

$73.5K

$122K

$164K

How much do full time cortex xdr jobs pay per year?

As of Aug 15, 2026, the average yearly pay for full time cortex xdr in the United States is $122,008.00, according to ZipRecruiter salary data. Most workers in this role earn between $103,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cortex XDR security analyst?

To thrive as a Cortex XDR Security Analyst, a strong background in cybersecurity, threat detection, and incident response is essential, often supported by a degree in information security or related certifications like CompTIA Security+ or CISSP. Familiarity with Palo Alto Networks Cortex XDR platform, SIEM systems, and scripting languages such as Python is typically required. Analytical thinking, effective communication, and problem-solving skills help analysts investigate alerts and coordinate with teams. These abilities are crucial for quickly identifying, responding to, and mitigating security threats in complex enterprise environments.

What are some common challenges faced by professionals working full time with Cortex XDR, and how can they be addressed?

One common challenge for professionals working full time with Cortex XDR is staying up-to-date with the rapid evolution of cybersecurity threats and adapting detection rules accordingly. Additionally, effectively triaging and responding to the high volume of alerts can be demanding, necessitating strong analytical and prioritization skills. Collaboration with IT and security teams is essential to investigate incidents thoroughly and implement necessary remediations. Regular training, leveraging automation features, and participating in knowledge-sharing sessions with colleagues are practical ways to overcome these challenges and excel in this role.

What is a full time Cortex XDR specialist?

A Full Time Cortex XDR specialist is a cybersecurity professional who manages and operates Palo Alto Networks' Cortex XDR platform on a full-time basis. Cortex XDR is an extended detection and response (XDR) solution that integrates data from endpoints, networks, and cloud environments to detect and respond to cyber threats. Specialists in this role are responsible for monitoring security alerts, investigating incidents, tuning detection rules, and ensuring the overall security posture of an organization. They also collaborate with IT and security teams to respond to threats quickly and efficiently.

What is the difference between Full Time Cortex Xdr vs Full Time Endpoint Security Specialist?

AspectFull Time Cortex XdrFull Time Endpoint Security Specialist
CertificationsRelevant security certifications (e.g., CySA+, CISSP)Security certifications often required (e.g., CompTIA Security+)
Work EnvironmentSecurity operations centers, cybersecurity teamsIT departments, cybersecurity teams
Industry UsageUsed across various industries for threat detectionPrimarily in IT and cybersecurity sectors
Job FocusThreat detection, response, and security analytics using Cortex XDR platformManaging and securing endpoints, malware prevention, and incident response

While both roles focus on cybersecurity, a Full Time Cortex Xdr specialist primarily works with the Cortex XDR platform for threat detection and response, whereas a Full Time Endpoint Security Specialist concentrates on securing endpoints and managing endpoint protection tools. The roles often overlap but differ in their core focus and tools used.

More about Full Time Cortex Xdr jobs

What cities are hiring for Full Time Cortex Xdr jobs?

Cities with the most Full Time Cortex Xdr job openings:

What are the most commonly searched types of Cortex Xdr jobs?

The most popular types of Cortex Xdr jobs are:

What states have the most Full Time Cortex Xdr jobs?

States with the most job openings for Full Time Cortex Xdr jobs include:

Infographic showing various Full Time Cortex Xdr job openings in the United States as of August 2026, with employment types broken down into 91% Full Time, 1% Part Time, and 8% Contract. Highlights an 84% Physical, 5% Hybrid, and 11% Remote job distribution, with an average salary of $122,008 per year, or $58.7 per hour.

Detection Engineer - REMOTE

Binary Defense

Houston, TX • On-site, Remote

Full-time

Medical, Dental, Vision, Retirement

Posted 17 days ago


Job description

Job Type
Full-time
Description
Binary Defense is seeking an experienced and motivated Detection Engineer to join our growing Detection Engineering team. You'll be a hands-on contributor, responsible for building, deploying, and maintaining high-quality detections across a variety of platforms, including SIEMs, EDRs, and cloud environments.
Our team operates detection engineering as code, and we are looking for someone who thrives in a modern, automation-driven environment. You should have a strong grasp of threat modeling, detection choke points, and the ability to abstract away UI dependencies using Python and REST APIs. This is an opportunity to contribute to a mature detection pipeline focused on coverage, efficacy, and scalability.
Responsibilities
• Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne).
• Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.
• Leverage APIs to automate rule deployment, validation, and telemetry inspection-reducing reliance on GUIs.
• Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors.
• Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps.
• Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.
• Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting.
• Support documentation of detection logic, coverage rationale, and response guidance.
• Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards.
Requirements
• 2-5+ years of hands-on experience in detection engineering, threat hunting, or incident response.
• Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows.
• Demonstrated experience writing, tuning, and validating detection logic in at least one of: Sigma, YARA-L, Splunk SPL, KQL, XQL.
• Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.
• Familiarity with MITRE ATT&CK and how to map detections to adversary techniques and detection choke points.
• Ability to quickly learn new security technologies and adapt detection strategies accordingly.
• Comfortable working in a fast-paced environment where threat-driven detection and rapid iteration are the norm.
Preferred
• Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction is a major plus).
• Experience contributing to a detection-as-code pipeline (e.g., Git-based workflows, rule validation, CI/CD).
• Exposure to multi-tenant or MDR environments and scaling detections across customer environments.
• Familiarity with Sigma to YARA-L translation, or with detection rule normalization and enrichment workflows.
• Experience in IR consulting and working across diverse EDR/SIEM stacks.
About Binary Defense
Binary Defense is a leading Managed Detection and Response (MDR) provider, trusted by hundreds of organizations to protect what matters most. Our team of SOC analysts, threat hunters, detection engineers, and threat researchers work around the clock to deliver proactive, risk-focused security outcomes. We bring the attacker's mindset to defense, helping clients detect threats earlier, respond faster, and continuously improve their security posture.
For more information, visit our website , check out our blog , or follow us on LinkedIn .
Binary Defense offers competitive medical, dental and vision coverage for employees and dependents, a 401k match which vests every payroll, a flexible and remote friendly work environment, as well as training opportunities to expand your skill set (to name a few!). If you're interested in joining a growing team with great perks, we encourage you to apply!