2

Remote Cortex Xdr Jobs (NOW HIRING)

$104K - $169K/yr

This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across ... Cortex XDR. This role is ideal for analysts who thrive in fast-paced SOC and incident response ...

Remote Experience: 10+ Years Must Have Hands on Experience in Thales CipherTrust Transparent ... Cortex XDR - Endpoint protection & incident response * Palo Alto Networks Firewalls & Panorama ...

IT Security Engineer SR

Goodlettsville, TN ยท Remote

$107K - $147K/yr

... Alto Cortex XDR, and Sysdig Secure to identify and mitigate threats. * Manage and respond to ... In-depth understanding of PKI, VPN/remote access technologies (CyberArk Alero, GlobalProtect), and ...

Remote Duration: Long Term We are seeking a senior SOC/SIEM/SOAR Consultant Architect to lead the ... Cortex XSIAM. This engagement suits seasoned SOC practitioners with hands-on XSIAM or XSOAR ...

Senior Security Engineer

Leawood, KS ยท On-site +1

$111K - $152K/yr

Headquartered in Burlington, MA, with additional office locations and hybrid and remote workers in ... XDR, or SOAR (Splunk, Google SecOps, Cortex XSOAR, TORQ, CrowdStrike Falcon, SentinelOne, etc.

Remote Cortex Xdr information

See salary details

$81K

$140.3K

$197K

How much do remote cortex xdr jobs pay per year?

As of Jun 28, 2026, the average yearly pay for remote cortex xdr in the United States is $140,327.00, according to ZipRecruiter salary data. Most workers in this role earn between $119,500.00 and $158,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Remote Cortex XDR Specialist, and why are they important?

To thrive as a Remote Cortex XDR Specialist, you need strong cybersecurity expertise, experience with endpoint detection and response (EDR) tools, and relevant certifications like CompTIA Security+ or CISSP. Proficiency with the Palo Alto Cortex XDR platform, SIEM systems, and scripting languages such as Python or PowerShell is typically required. Analytical thinking, attention to detail, and effective communication skills help specialists investigate threats and coordinate with teams. These competencies are vital for timely threat detection, incident response, and maintaining robust security for distributed environments.

What are some typical challenges faced by remote Cortex XDR analysts, and how can they be addressed?

Remote Cortex XDR analysts often face challenges such as maintaining effective communication with on-site teams, staying updated on evolving threats, and managing alerts across distributed environments. To address these, it's important to establish clear communication channels with security and IT teams, participate in regular briefings, and leverage automation features within Cortex XDR to reduce alert fatigue. Continuous learning and collaboration through virtual meetings and threat intelligence sharing can also help analysts stay ahead of new security risks.

What is a Remote Cortex XDR specialist?

A Remote Cortex XDR specialist is a cybersecurity professional who manages, monitors, and responds to threats using Palo Alto Networks' Cortex XDR platform from a remote location. Cortex XDR is an extended detection and response solution that integrates data from various sources to detect and address security incidents. Remote specialists use this tool to investigate alerts, perform threat hunting, and coordinate incident response without being physically present in an organization's office. Their expertise helps organizations strengthen their security posture while allowing for flexible, remote work arrangements.

What is the difference between Remote Cortex Xdr vs Remote Security Analyst?

AspectRemote Cortex XdrRemote Security Analyst
CertificationsRelevant cybersecurity certifications (e.g., CompTIA Security+, CEH)Similar certifications often required
Work EnvironmentSecurity platform management, threat detection, incident responseMonitoring security alerts, analyzing threats, reporting
Industry UsageUsed by cybersecurity teams for endpoint detection and responseEmployed across various industries for security monitoring

Remote Cortex Xdr specialists focus on managing and utilizing the Cortex XDR platform for threat detection and response, while Remote Security Analysts monitor security alerts and analyze threats across systems. Both roles require cybersecurity certifications and work in similar environments, but their core responsibilities differ: one manages security tools, the other analyzes security data.

More about Remote Cortex Xdr jobs
What cities are hiring for Remote Cortex Xdr jobs? Cities with the most Remote Cortex Xdr job openings:
What are the most commonly searched types of Cortex Xdr jobs? The most popular types of Cortex Xdr jobs are:
What states have the most Remote Cortex Xdr jobs? States with the most job openings for Remote Cortex Xdr jobs include:
Infographic showing various Remote Cortex Xdr job openings in the United States as of June 2026, with employment types broken down into 80% Full Time, and 20% Contract. Highlights an 100% Remote job distribution, with an average salary of $140,327 per year, or $67.5 per hour.

Cortex XSIAM Security Engineer

CELESTIAL INNOVATIONS GROUP LLC

Washington, DC โ€ข Remote

$120K - $150K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 9 days ago


Job description

Benefits:
  • 401(k)
  • Competitive salary
  • Dental insurance
  • Health insurance
  • Paid time off
  • Vision insurance

Position Summary
Celestial Innovations Group (CIG) is seeking a skilled Cortex XSIAM Security Engineer to deploy, configure, and operationalize Palo Alto Networks Cortex XSIAM for federal and enterprise clients. This role is at the center of CIG's AI-driven Security Operations practice, enabling clients to modernize their SOC by consolidating SIEM, XDR, SOAR, UEBA, ASM, and TIP capabilities into a single, converged platform.
The Cortex XSIAM Engineer will serve as a subject-matter expert (SME) throughout the full platform lifecycle: from requirements gathering and architecture design through deployment, integration, and continuous optimization driving measurable improvements in threat detection and incident response times for our government and commercial clients.
Must be located in the DC Metro Area as this role requires onsite and remote support.

Key Responsibilities
Platform Deployment & Integration
  • Lead end-to-end deployment of Cortex XSIAM for federal and enterprise clients, including data source onboarding, log ingestion, and normalization.
  • Integrate XSIAM with existing security ecosystem tools including firewalls, endpoints, cloud platforms, identity providers, and ticketing systems.
  • Configure data pipelines to ingest and normalize telemetry from diverse sources (endpoints, network, cloud, identity) into XSIAM's unified data model.
  • Migrate clients from legacy SIEM platforms to Cortex XSIAM, ensuring continuity of detection coverage and compliance reporting.
Detection Engineering & Analytics
  • Build and tune correlation rules, behavioral analytics, and ML-based detection models within XSIAM to reduce false positive rates and improve detection fidelity.
  • Develop and maintain XSIAM analytics leveraging XQL (Extended Query Language) to extract actionable insights from security telemetry.
  • Map detection content to MITRE ATT&CK framework, ensuring coverage across all relevant tactics, techniques, and procedures (TTPs).
  • Configure AI SmartScoring and technique-based incident grouping to reduce alert fatigue and prioritize analyst workload effectively.
Automation & Playbook Development
  • Design, build, and maintain SOAR automation playbooks within XSIAM to automate triage, enrichment, and remediation workflows.
  • Leverage Cortex Marketplace content packs and develop custom integrations as needed to support client-specific security processes.
  • Implement dev/prod playbook lifecycle management to ensure safe testing and controlled promotion of automation content.
  • Continuously improve automation coverage, targeting measurable reductions in manual analyst workload.
Incident Response & Threat Management
  • Serve as escalation point for complex incident investigations, using XSIAM causality chains and full attack-story visualizations to support rapid remediation.
  • Coordinate with client SOC teams during active incidents, leveraging XSIAM's embedded automation and enrichment capabilities.
  • Support Attack Surface Management (ASM) functions to proactively identify and remediate client exposure.
  • Utilize integrated Threat Intelligence Platform (TIP) capabilities, including Unit 42 threat feeds, to enrich alerts and inform response priorities.
Client Engagement & Advisory
  • Serve as a trusted technical advisor to federal and commercial clients on XSIAM capabilities, roadmap, and SOC modernization strategy.
  • Produce SOC performance dashboards, compliance reports, and executive summaries within XSIAM to support client governance requirements.
  • Conduct training and knowledge transfer sessions to build client SOC team proficiency on the XSIAM platform.
  • Support CIG business development efforts by contributing to proposals, demos, and technical capability briefings for prospective clients.

Required Qualifications
  • 3+ years of hands-on experience with Palo Alto Networks Cortex XDR or Cortex XSIAM in an enterprise or federal environment.
  • Demonstrated experience deploying or administering SIEM platforms (Splunk, Microsoft Sentinel, IBM QRadar, or equivalent).
  • Proficiency with XQL or comparable query languages for log analysis and threat hunting.
  • Working knowledge of SOAR concepts and experience building security automation playbooks.
  • Understanding of EDR, NDR, and UEBA technologies and how they feed into a converged SOC platform.
  • Familiarity with MITRE ATT&CK framework and its application to detection engineering.
  • Active Secret clearance (minimum); TS/SCI preferred for federal engagements.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field, OR equivalent professional experience.

Preferred Qualifications
  • Palo Alto Networks Certified Security Automation Engineer (PCSAE) or Cortex XSIAM-specific certification.
  • Experience with federal compliance frameworks including NIST SP 800-53, RMF, DISA STIGs, and CDM program requirements.
  • Familiarity with Zero Trust Architecture principles (NIST SP 800-207, CISA ZT Maturity Model) and how XSIAM supports ZTA adoption.
  • Experience integrating Cortex XSIAM with Palo Alto Networks NGFW, Prisma Cloud, or Zscaler platforms.
  • Knowledge of cloud security telemetry sources (AWS, Azure, GCP) and their ingestion into XSIAM.
  • Exposure to Python or JavaScript for custom XSIAM integration development or automation scripting.
  • Prior experience supporting federal SOC operations or DHS CDM program environments.
  • CISSP, CEH, CompTIA Security+, or equivalent security certification.

Technical Skills & Tools
SOC Platforms
  • Cortex XSIAM / XDR
  • Cortex XSOAR
  • SIEM platforms
  • XQL query language
  • EDR / NDR / UEBA
Security Frameworks
  • MITRE ATT&CK
  • NIST SP 800-53 / RMF
  • NIST SP 800-207 (Zero Trust Architecture)
  • CISA Zero Trust Maturity Model
  • DISA STIGs
Integrations & Tools
  • Palo Alto NGFW / Prisma
  • Zscaler ZIA / ZPA
  • Microsoft Sentinel / Azure
  • ServiceNow / Ticketing systems
  • AWS / Azure / GCP

Flexible work from home options available.