2

Remote Cortex Xdr Jobs (NOW HIRING)

Remote Experience: 10+ Years Must Have Hands on Experience in Thales CipherTrust Transparent ... Cortex XDR - Endpoint protection & incident response * Palo Alto Networks Firewalls & Panorama ...

Detection Engineering Lead

$104K - $138K/yr

... Alto Cortex XDR. * Experience with cloud security platforms including AWS, Azure, and GCP ... Work Environment/Travel We are a 100% remote company where you will work from your home with ...

Detection Engineering Lead

$104K - $138K/yr

... Alto Cortex XDR. * Experience with cloud security platforms including AWS, Azure, and GCP ... Work Environment/Travel We are a 100% remote company where you will work from your home with ...

IT Security Engineer SR

Goodlettsville, TN · Remote

$107K - $147K/yr

... Alto Cortex XDR, and Sysdig Secure to identify and mitigate threats. * Manage and respond to ... In-depth understanding of PKI, VPN/remote access technologies (CyberArk Alero, GlobalProtect), and ...

Remote Cortex Xdr information

See salary details

$81K

$140.3K

$197K

How much do remote cortex xdr jobs pay per year?

As of Sep 5, 2026, the average yearly pay for remote cortex xdr in the United States is $140,327.00, according to ZipRecruiter salary data. Most workers in this role earn between $119,500.00 and $158,000.00 per year, depending on experience, location, and employer.

What is a remote Cortex XDR specialist?

A Remote Cortex XDR specialist is a cybersecurity professional who manages, monitors, and responds to threats using Palo Alto Networks' Cortex XDR platform from a remote location. Cortex XDR is an extended detection and response solution that integrates data from various sources to detect and address security incidents. Remote specialists use this tool to investigate alerts, perform threat hunting, and coordinate incident response without being physically present in an organization's office. Their expertise helps organizations strengthen their security posture while allowing for flexible, remote work arrangements.

What are the key skills and qualifications needed to thrive as a remote Cortex XDR specialist?

To thrive as a Remote Cortex XDR Specialist, you need strong cybersecurity expertise, experience with endpoint detection and response (EDR) tools, and relevant certifications like CompTIA Security+ or CISSP. Proficiency with the Palo Alto Cortex XDR platform, SIEM systems, and scripting languages such as Python or PowerShell is typically required. Analytical thinking, attention to detail, and effective communication skills help specialists investigate threats and coordinate with teams. These competencies are vital for timely threat detection, incident response, and maintaining robust security for distributed environments.

What are some typical challenges faced by remote Cortex XDR specialists, and how can they be addressed?

Remote Cortex XDR analysts often face challenges such as maintaining effective communication with on-site teams, staying updated on evolving threats, and managing alerts across distributed environments. To address these, it's important to establish clear communication channels with security and IT teams, participate in regular briefings, and leverage automation features within Cortex XDR to reduce alert fatigue. Continuous learning and collaboration through virtual meetings and threat intelligence sharing can also help analysts stay ahead of new security risks.

What is the difference between Remote Cortex Xdr vs Remote Security Analyst?

AspectRemote Cortex XdrRemote Security Analyst
CertificationsRelevant cybersecurity certifications (e.g., CompTIA Security+, CEH)Similar certifications often required
Work EnvironmentSecurity platform management, threat detection, incident responseMonitoring security alerts, analyzing threats, reporting
Industry UsageUsed by cybersecurity teams for endpoint detection and responseEmployed across various industries for security monitoring

Remote Cortex Xdr specialists focus on managing and utilizing the Cortex XDR platform for threat detection and response, while Remote Security Analysts monitor security alerts and analyze threats across systems. Both roles require cybersecurity certifications and work in similar environments, but their core responsibilities differ: one manages security tools, the other analyzes security data.

More about Remote Cortex Xdr jobs

What cities are hiring for Remote Cortex Xdr jobs?

Cities with the most Remote Cortex Xdr job openings:

What are the most commonly searched types of Cortex Xdr jobs?

The most popular types of Cortex Xdr jobs are:

What states have the most Remote Cortex Xdr jobs?

States with the most job openings for Remote Cortex Xdr jobs include:

Infographic showing various Remote Cortex Xdr job openings in the United States as of August 2026, with employment types broken down into 96% Full Time, 1% Part Time, and 3% Contract. Highlights an 73% Physical, 7% Hybrid, and 20% Remote job distribution, with an average salary of $140,327 per year, or $67.5 per hour.

SIEM Engineer - Contract - Remote (Onsite in SC if required)

SUNSHINE ENTERPRISE USA LLC

Columbia, SC • On-site, Remote

Contractor

Re-posted 21 days ago


Job description


Job Title: SIEM Engineer
Location:
100% Remote. Preference will be given to local candidates who can come to the office as needed for client and departmental meetings, trainings, and other onsite activities.
Interview Process: 1-2 Rounds of Virtual Interviews. In person availability for interviews preferred.
Duration: 12 MonthsEmployment Type: ContractExperience Required: 10+ Years
Candidate location: No South Carolina residency required. Open to nationwide candidates. All travel-related costs for onsite work will be the responsibility of the resource no matter the frequency of onsite work.
Project Scope:
We are seeking an experienced Security Architect Consultant - SIEM Engineer to support the Department of Administration's Division of Information Security. This role is focused on the design, implementation, administration, optimization, and operational support of Palo Alto Cortex XSIAM and Cortex XDR in a large-scale, multi-tenant enterprise security environment.
The successful candidate will work alongside enterprise security architects, engineers, and a 24x7 Security Operations Center (SOC) team to enhance SIEM, XDR, detection engineering, automation, incident response, and security monitoring capabilities across multiple state agencies. This role also provides secondary support for Cribl data pipelines, log management, and telemetry onboarding.
Key Responsibilities:
• Design, implement, configure, and maintain Palo Alto Cortex XSIAM and Cortex XDR platforms.
• Support multi-tenant SIEM environments, including tenant onboarding, role-based access, data segregation, dashboards, and reporting.
• Develop and optimize: Detection rules, Correlation rules, Analytics, Threat hunting queries, Watchlists, Alert suppression logic
• Design and manage Cribl log pipelines, including: Data modeling, Parsing, Normalization, Enrichment, Routing, Filtering, Replay, Log ingestion
• Integrate telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, and custom applications.
• Develop and maintain automated playbooks and response workflows using Python and Bash.
• Support incident response, threat hunting, and SOC operations.
• Create and maintain: Runbooks, SOPs, Architecture diagrams, Data flow documentation, Knowledge articles
• Support Tier 1-Tier 3 SOC analysts through troubleshooting, tuning, and knowledge transfer.
• Monitor SIEM health, ingestion, availability, detection coverage, false positives, MTTD, MTTR, and operational metrics.
• Ensure platform resilience, backup, recovery, lifecycle management, and change control.
• Collaborate with security architects, engineers, analysts, and business stakeholders to improve enterprise security capabilities.
Required Skills & Experience:
  • Hands-onexperience with Palo Alto Cortex XSIAM and Cortex XDR architecture, implementation, administration, and operational support.
  • Experiencesupporting enterprise SIEM platforms within large multi-tenantenvironments.
  • Experiencesupporting 24x7 Security Operations Centers (SOC).
  • Strongdetection engineering experience including:
    • Correlationrules
    • Threathunting
    • Analytics
    • Dashboards
    • Alerttuning
    • False-positivereduction
  • Hands-on Cribl administration including:
    • Datamodeling
    • Logpipeline design
    • Parsing
    • Normalization
    • Enrichment
    • Routing
    • Ingestion
  • Experiencedeveloping automation using:
    • Python
    • Bash
  • Experienceonboarding cloud, endpoint, network, identity, SaaS, Windows, Linux, andcustom application telemetry.
  • Strongknowledge of:
    • Enterprisesecurity architecture
    • Incidentresponse
    • Securesystem design
    • Networking
    • Identity& Access Management
    • Cybersecurityframeworks

Preferred Skills:
• Excellent written and verbal communication skills.
• Strong ability to create: Business Requirements Documents (BRD), Functional Requirements Documents (FRD), Use Cases, Process Documentation
• Experience gathering requirements through stakeholder interviews, policy documents, regulations, and business rules analysis.
• Knowledge of business modeling techniques and graphical process flow tools.
• Ability to communicate effectively with: Executive management, Business users, Project managers, Technical teams, External stakeholders
Education
Bachelor's degree in Information Technology, Information Security, Computer Science, or related field.
Eight (8) years of relevant experience may be substituted for the degree requirement.
Minimum five (5) years supporting large enterprise IT environments or system deployments.
Preferred Certifications
  • CISSP
  • Security+
  • GIAC
  • Palo AltoCortex Certification
  • CriblCertification
  • Otherrelevant SIEM or cybersecurity certifications