2

Remote Cortex Xdr Jobs (NOW HIRING)

This contractor will be primarily focused on Cortex XSIAM and Cortex XDR engineering ... Role is 100% Remote. Preference will be given to local candidates who can come to the office as ...

$104K - $169K/yr

This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across ... Cortex XDR. This role is ideal for analysts who thrive in fast-paced SOC and incident response ...

Remote Experience: 10+ Years Must Have Hands on Experience in Thales CipherTrust Transparent ... Cortex XDR - Endpoint protection & incident response * Palo Alto Networks Firewalls & Panorama ...

... as Cortex XDR and SentinelOne * Configure, manage, and troubleshoot cloud-based firewall ... Remote The base pay range for this position varies based on the geographic location. More ...

IT Security Engineer SR

Goodlettsville, TN · Remote

$107K - $147K/yr

... Alto Cortex XDR, and Sysdig Secure to identify and mitigate threats. * Manage and respond to ... In-depth understanding of PKI, VPN/remote access technologies (CyberArk Alero, GlobalProtect), and ...

next page

Showing results 1-20

Remote Cortex Xdr information

See salary details

$81K

$140.3K

$197K

How much do remote cortex xdr jobs pay per year?

As of Jul 25, 2026, the average yearly pay for remote cortex xdr in the United States is $140,327.00, according to ZipRecruiter salary data. Most workers in this role earn between $119,500.00 and $158,000.00 per year, depending on experience, location, and employer.

Can you make $200,000 in cyber security?

Remote Cortex XDR roles and other cybersecurity positions can offer salaries approaching or exceeding $200,000, especially with experience, advanced certifications, and specialized skills in threat detection and incident response. High-level roles such as security architects or senior analysts tend to have higher compensation, often influenced by industry, location, and company size.

What are the key skills and qualifications needed to thrive as a Remote Cortex XDR Specialist, and why are they important?

To thrive as a Remote Cortex XDR Specialist, you need strong cybersecurity expertise, experience with endpoint detection and response (EDR) tools, and relevant certifications like CompTIA Security+ or CISSP. Proficiency with the Palo Alto Cortex XDR platform, SIEM systems, and scripting languages such as Python or PowerShell is typically required. Analytical thinking, attention to detail, and effective communication skills help specialists investigate threats and coordinate with teams. These competencies are vital for timely threat detection, incident response, and maintaining robust security for distributed environments.

What are some typical challenges faced by remote Cortex XDR analysts, and how can they be addressed?

Remote Cortex XDR analysts often face challenges such as maintaining effective communication with on-site teams, staying updated on evolving threats, and managing alerts across distributed environments. To address these, it's important to establish clear communication channels with security and IT teams, participate in regular briefings, and leverage automation features within Cortex XDR to reduce alert fatigue. Continuous learning and collaboration through virtual meetings and threat intelligence sharing can also help analysts stay ahead of new security risks.

Can you make $500,000 a year in cyber security?

Earning $500,000 annually in cybersecurity is possible for senior roles such as security architects or chief information security officers, especially with extensive experience, advanced certifications, and leadership responsibilities. Roles like Remote Cortex XDR specialists typically have lower salary ranges, but combining skills, certifications, and experience can lead to higher compensation in the field.

Does Palo Alto allow remote work?

Remote Cortex XDR roles are available at Palo Alto Networks, and the company offers flexible work arrangements, including remote work options for certain positions. Eligibility for remote work depends on the specific role, team needs, and location policies, and candidates should review the job listing for details. Skills in cybersecurity, cloud environments, and remote collaboration tools are often required.

What is a Remote Cortex XDR specialist?

A Remote Cortex XDR specialist is a cybersecurity professional who manages, monitors, and responds to threats using Palo Alto Networks' Cortex XDR platform from a remote location. Cortex XDR is an extended detection and response solution that integrates data from various sources to detect and address security incidents. Remote specialists use this tool to investigate alerts, perform threat hunting, and coordinate incident response without being physically present in an organization's office. Their expertise helps organizations strengthen their security posture while allowing for flexible, remote work arrangements.

What is the difference between Remote Cortex Xdr vs Remote Security Analyst?

AspectRemote Cortex XdrRemote Security Analyst
CertificationsRelevant cybersecurity certifications (e.g., CompTIA Security+, CEH)Similar certifications often required
Work EnvironmentSecurity platform management, threat detection, incident responseMonitoring security alerts, analyzing threats, reporting
Industry UsageUsed by cybersecurity teams for endpoint detection and responseEmployed across various industries for security monitoring

Remote Cortex Xdr specialists focus on managing and utilizing the Cortex XDR platform for threat detection and response, while Remote Security Analysts monitor security alerts and analyze threats across systems. Both roles require cybersecurity certifications and work in similar environments, but their core responsibilities differ: one manages security tools, the other analyzes security data.

Is cybersecurity a dying field?

Cybersecurity roles such as Remote Cortex XDR specialists are in high demand due to increasing cyber threats and the need for advanced threat detection tools like Cortex XDR. The field is expected to grow as organizations prioritize security, requiring skills in threat analysis, incident response, and familiarity with security platforms. Continuous learning and certifications are important for staying current in this evolving industry.
More about Remote Cortex Xdr jobs
What cities are hiring for Remote Cortex Xdr jobs? Cities with the most Remote Cortex Xdr job openings:
What are the most commonly searched types of Cortex Xdr jobs? The most popular types of Cortex Xdr jobs are:
What states have the most Remote Cortex Xdr jobs? States with the most job openings for Remote Cortex Xdr jobs include:
Infographic showing various Remote Cortex Xdr job openings in the United States as of July 2026, with employment types broken down into 100% Full Time. Highlights an 100% Remote job distribution, with an average salary of $140,327 per year, or $67.5 per hour.
Palo Alto Cortex XSIAM and XDR platform engineer W-2 ONLY

Palo Alto Cortex XSIAM and XDR platform engineer W-2 ONLY

United Global Technologies

Columbia, SC • Remote

Full-time

Posted 10 days ago


Job description

W-2 ONLY No subs, No sponsorship

This position is 100% remote and will participate in a monthly on-call rotation supporting a 24x7 security operations center serving multiple agencies. Other after-hours work may be required as needed.

Primarily assist in the planning, design, deployment, administration and operational support of enterprise SIEM and XDR capabilities, including:

  • Palo alto cortex XSIAM and cortex XDR platform engineering, configuration, optimization and troubleshooting.
  • Multi-tenant agency onboarding, tenant-specific configuration, role-based access, data
  • segregation, dashboards and reporting.
  • Detection engineering, correlation rules, analytics, threat-hunting queries, watchlists, suppression logic and false-positive reduction.

Secondarily assist in the planning, design, deployment and operational support of log management and security data pipelines, including:

  • CRIBL data modeling, log pipeline design, routing, parsing, normalization, enrichment, filtering, replay and ingestion.
  • Onboarding and health monitoring of cloud, endpoint, network, identity, SAAS and custom application telemetry.
  • Log volume, retention, performance and cost optimization while maintaining security and compliance requirements.
  • Integrations with ticketing, case management, notification, identity, threat intelligence and other enterprise systems as needed.
  • Develop, test, deploy and maintain automated response workflows and playbooks for enrichment, triage, containment, escalation, notifications, case management and incident response.
  • Create and maintain operational runbooks, standard operating procedures, escalation matrices, troubleshooting guides, architecture diagrams, data-flow documentation, use-case catalogs and analyst knowledge articles.
  • Support tier 1 through tier 3 soc analysts and incident responders through platform troubleshooting, detection tuning, threat hunting, technical escalation, knowledge transfer and shift handoffs.
  • Monitor and report on ingestion health, platform availability, alert volumes, detection coverage, false positives, service levels, mean time to detect, mean time to respond and tenant-specific operational metrics.
  • Ensure high availability, resilience, backup, recovery, lifecycle management and controlled change processes for SIEM, XDR and supporting log pipeline services.
  • Collaborate with security architects, engineers, analysts and agency stakeholders to align solutions with business goals, industry-standard frameworks, regulatory requirements and organizational risk tolerance.


Work Location: Role is 100% Remote. Preference will be given to local candidates who can come to the office as needed for client and departmental meetings, trainings, and other onsite activities.

Open to nationwide candidates. All travel-related costs for onsite work will be the responsibility of the resource no matter the frequency of onsite work.

Required Skills:

  • 5+ years of experience support large IT environments and/or system deployments
  • Hands-on experience with Palo Alto Cortex, XSIAM, and Cortex XDR design, implementation, administration and operational support.
  • Experience engineering and supporting SIEM capabilities for multi-tenant environments and 24x7 Security Operations Center operations.
  • Experience developing and tuning detections, correlation rules, analytics, threat-hunting queries, dashboards, reporting and alert suppression logic.
  • Experience creating and managing complex playbooks
  • CRIBL Data Modeling, log pipeline design, parsing, normalization, enrichment, routing and ingestion.
  • Experience developing automation, integrations, playbooks and response workflows using scripting languages such as Python and Bash.
  • Experience onboarding and troubleshooting telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows and custom application sources.
  • Strong understanding of enterprise security architecture, incident response, networking, access control, secure system design and industry-standard cybersecurity frameworks.

Education: Bachelor's Degree in an Information Technology or Information Security related field (8+ years of relevant work experience may be substituted in lieu of education).

Preferred Skills:

  • Palo Alto Cortex, CRIBL or other relevant SIEM/security platform certification
  • Hands-on experience operating Cortex XSIAM and Cortex XDR in a large, multi-tenant environment.
  • Hands-on CRIBL administration, data modeling and log pipeline optimization experience.
  • Experience supporting Tier 1 through Tier 3 SOC analysts, threat hunting, incident response and 24x7 operational handoffs.
  • Familiarity with industry-standard security and compliance frameworks and experience developing playbooks, runbooks, procedures and technical documentation.

Certification:
CISSP, Security+ or GIAC certification