2

Full Time Cortex Xdr Jobs in Virginia (NOW HIRING)

Firewall Engineer III

Springfield, VA · Hybrid

$117K - $128K/yr

Springfield, VA - on site Time Type: Full time, Exempt Clearance Required to Start: Active TS/SCI ... Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy. * Zero Trust Network ...

Firewall Engineer III

Springfield, VA · On-site

$117K - $128K/yr

Springfield, VA - on site Time Type: Full time, Exempt Clearance Required to Start: Active TS/SCI ... Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy. * Zero Trust Network ...

Palo Alto Subject Matter Expert

Springfield, VA · Hybrid

$61 - $80/hr

Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI Employee ... Hands-on experience with Cortex XDR or Cortex XSOAR for automated threat response. Migration Tools:

Full Time Cortex Xdr information

What is a full time Cortex XDR specialist?

A Full Time Cortex XDR specialist is a cybersecurity professional who manages and operates Palo Alto Networks' Cortex XDR platform on a full-time basis. Cortex XDR is an extended detection and response (XDR) solution that integrates data from endpoints, networks, and cloud environments to detect and respond to cyber threats. Specialists in this role are responsible for monitoring security alerts, investigating incidents, tuning detection rules, and ensuring the overall security posture of an organization. They also collaborate with IT and security teams to respond to threats quickly and efficiently.

What are the key skills and qualifications needed to thrive as a Cortex XDR security analyst?

To thrive as a Cortex XDR Security Analyst, a strong background in cybersecurity, threat detection, and incident response is essential, often supported by a degree in information security or related certifications like CompTIA Security+ or CISSP. Familiarity with Palo Alto Networks Cortex XDR platform, SIEM systems, and scripting languages such as Python is typically required. Analytical thinking, effective communication, and problem-solving skills help analysts investigate alerts and coordinate with teams. These abilities are crucial for quickly identifying, responding to, and mitigating security threats in complex enterprise environments.

What are some common challenges faced by professionals working full time with Cortex XDR, and how can they be addressed?

One common challenge for professionals working full time with Cortex XDR is staying up-to-date with the rapid evolution of cybersecurity threats and adapting detection rules accordingly. Additionally, effectively triaging and responding to the high volume of alerts can be demanding, necessitating strong analytical and prioritization skills. Collaboration with IT and security teams is essential to investigate incidents thoroughly and implement necessary remediations. Regular training, leveraging automation features, and participating in knowledge-sharing sessions with colleagues are practical ways to overcome these challenges and excel in this role.

What is the difference between Full Time Cortex Xdr vs Full Time Endpoint Security Specialist?

AspectFull Time Cortex XdrFull Time Endpoint Security Specialist
CertificationsRelevant security certifications (e.g., CySA+, CISSP)Security certifications often required (e.g., CompTIA Security+)
Work EnvironmentSecurity operations centers, cybersecurity teamsIT departments, cybersecurity teams
Industry UsageUsed across various industries for threat detectionPrimarily in IT and cybersecurity sectors
Job FocusThreat detection, response, and security analytics using Cortex XDR platformManaging and securing endpoints, malware prevention, and incident response

While both roles focus on cybersecurity, a Full Time Cortex Xdr specialist primarily works with the Cortex XDR platform for threat detection and response, whereas a Full Time Endpoint Security Specialist concentrates on securing endpoints and managing endpoint protection tools. The roles often overlap but differ in their core focus and tools used.

What are the most commonly searched types of Cortex Xdr jobs in Virginia?

The most popular types of Cortex Xdr jobs in Virginia are:

What are popular job titles related to Full Time Cortex Xdr jobs in Virginia?

For Full Time Cortex Xdr jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Full Time Cortex Xdr jobs in Virginia look for?

The top searched job categories for Full Time Cortex Xdr jobs in Virginia are:

What cities in Virginia are hiring for Full Time Cortex Xdr jobs?

Cities in Virginia with the most Full Time Cortex Xdr job openings:

Infographic showing various Full Time Cortex Xdr job openings in Virginia as of July 2026, with employment types broken down into 42% Locum Tenens, 45% Full Time, 4% Part Time, 1% Temporary, 2% Contract, and 6% Summer. Highlights an 84% Physical, 4% Hybrid, and 12% Remote job distribution.

Firewall Engineer III

RISA

Springfield, VA • Hybrid

$117K - $128K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 9 days ago


Job description

Palo Alto Firewall Engineer / SME (PCNSE)

Location: Springfield, VA - on site

Time Type: Full time, Exempt

Clearance Required to Start: Active TS/SCI (U.S. citizenship required)

Additional Requirement: Must be able to obtain and maintain a U.S. Government polygraph

Travel: Up to 15%, local and CONUS

Salary Range: $117,000 – $128,000

Own the Palo Alto estate - legacy iron through Prisma and Panorama.

RISA is hiring a Palo Alto SME to be the focal point for every Palo Alto task, operation, and project on the Network Security Services team supporting an Intelligence Community customer. The work spans both ends of the estate: PA-3000 and PA-5000 hardware refreshes and legacy CLI on one side, Prisma Access, VM-Series, and Cortex on the other. You will talk to the owner here, not a recruiting queue.

What You Will Do

  • Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto NGFWs across a hybrid enterprise.
  • Lead the design, analysis, testing, and implementation of secure network architectures on the Palo Alto stack.
  • Manage the full hardware and software lifecycle, including complex refreshes and PAN-OS upgrades on legacy platforms.
  • Run Panorama for centralized policy management across a fleet of physical and virtual firewalls.
  • Configure master-level security profiles - App-ID, User-ID, Content-ID, SSL Decryption, and WildFire.
  • Own configuration management processes and SOPs for all Palo Alto platforms.
  • Mentor junior engineers and act as the escalation point for complex troubleshooting.
  • Liaise with contract, customer, and government DAA on network security status, policies, and procedures.

What You'll Bring

  • U.S. citizenship and an active TS/SCI.
  • Ability to successfully obtain and maintain a U.S. Government polygraph.
  • Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.
  • 7+ years hands-on administering, configuring, and troubleshooting Palo Alto NGFWs in large-scale enterprise or global environments.
  • Active PCNSE certification.
  • DoD 8140.01 and 8570.01-M IAT Level II (e.g. Security+ CE), and CSSP Infrastructure Support within 120 days of start.
  • Deep practical knowledge of legacy Gen 2/Gen 3 hardware - PA-3000 and PA-5000 series, legacy CLI, physical troubleshooting, line-card replacement.
  • Prisma Access (SASE), Prisma SD-WAN, and VM-Series in AWS, Azure, or GCP.
  • Panorama template and device-group inheritance across a hybrid fleet.
  • Advanced BGP, OSPF, IPSec VPN, and NAT.

Nice to Have

  • PCNSC or Prisma Certified SASE Professional (PCSAE).
  • Python, plus firewall automation with Ansible, Terraform, or the Palo Alto XML/REST APIs.
  • Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy.
  • Zero Trust Network Access architecture; F5 (APM, AFM), Juniper SRX, or Cisco FTD/ASA.

About RISA

Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down.

Benefits

Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.

RISA is an Equal Opportunity Employer.