1

Xsiam Jobs (NOW HIRING)

Security Architect

$66.50 - $86/hr

... XSIAM • Continuously improve detection pipelines and threat intelligence integration Qualifications : Required : • Bachelor's degree in Information Technology, Information Security, or related ...

Security Engineer

Chicago, IL · On-site

$78K - $119K/yr

Partner to integrate IAM with the rest of the security stack so that XSIAM, CASB, DLP, and EDR/XDR all see consistent identity signal. * Run technical access reviews and tighten entitlement design ...

Partner to integrate IAM with the rest of the security stack so that XSIAM, CASB, DLP, and EDR/XDR all see consistent identity signal. * Run technical access reviews and tighten entitlement design ...

Partner to integrate IAM with the rest of the security stack so that XSIAM, CASB, DLP, and EDR/XDR all see consistent identity signal. * Run technical access reviews and tighten entitlement design ...

next page

Showing results 1-20

Xsiam information

What are the key skills and qualifications needed to thrive as an XSIAM (Extended Security Intelligence & Automation Management) Specialist, and why are they important?

To thrive as an XSIAM Specialist, you need a deep understanding of cybersecurity principles, incident response, and threat intelligence, along with relevant IT or cybersecurity certifications. Familiarity with security information and event management (SIEM) platforms—especially Palo Alto Networks’ Cortex XSIAM—and scripting or automation tools is crucial. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are critical for proactively detecting threats, automating security workflows, and ensuring robust organizational defense.

What is an XSIAM specialist?

An XSIAM specialist is a cybersecurity professional who focuses on managing and optimizing the Extended Security Intelligence and Automation Management (XSIAM) platform, developed by Palo Alto Networks. XSIAM integrates security data, analytics, and automated response capabilities to help organizations detect, investigate, and respond to cybersecurity threats more effectively. Specialists in this field are skilled in configuring the platform, integrating various data sources, creating automation playbooks, and analyzing security events to reduce incident response times. They often work closely with security operations centers (SOCs) to enhance threat detection and streamline security operations.

How does an XSIAM (Extended Security Intelligence and Automation Management) specialist typically collaborate with other teams within an organization?

An XSIAM specialist works closely with IT, security operations, and incident response teams to integrate and automate security workflows. Collaboration often involves coordinating with system administrators to implement automated threat detection and response, as well as working with security analysts to refine detection rules and improve incident investigation processes. Regular communication and cross-functional meetings are common to ensure that the XSIAM platform aligns with organizational security objectives and adapts to evolving threats.
More about Xsiam jobs
What cities are hiring for Xsiam jobs? Cities with the most Xsiam job openings:
What states have the most Xsiam jobs? States with the most job openings for Xsiam jobs include:
What job categories do people searching Xsiam jobs look for? The top searched job categories for Xsiam jobs are:
Infographic showing various Xsiam job openings in the United States as of July 2026, with employment types broken down into 68% Full Time, 1% Temporary, and 31% Contract. Highlights an 51% Physical, 3% Hybrid, and 46% Remote job distribution.
SIEM Engineer - Contract - Remote (Onsite in SC if required)

SIEM Engineer - Contract - Remote (Onsite in SC if required)

SUNSHINE ENTERPRISE USA LLC

Columbia, SC • On-site

Contractor

Posted 9 days ago


Job description

Job Title: SIEM Engineer Location: 100% Remote. Preference will be given to local candidates who can come to the office as needed for client and departmental meetings, trainings, and other onsite activities. Interview Process: 1-2 Rounds of Virtual Interviews.

In person availability for interviews preferred. Duration: 12 Months Employment Type: Contract Experience Required: 10+ Years Candidate location: No South Carolina residency required. Open to nationwide candidates.

All travel-related costs for onsite work will be the responsibility of the resource no matter the frequency of onsite work. Project Scope: We are seeking an experienced Security Architect Consultant - SIEM Engineer to support the Department of Administration's Division of Information Security. This role is focused on the design, implementation, administration, optimization, and operational support of Palo Alto Cortex XSIAM and Cortex XDR in a large-scale, multi-tenant enterprise security environment.

The successful candidate will work alongside enterprise security architects, engineers, and a 24x7 Security Operations Center (SOC) team to enhance SIEM, XDR, detection engineering, automation, incident response, and security monitoring capabilities across multiple state agencies. This role also provides secondary support for Cribl data pipelines, log management, and telemetry onboarding. Key Responsibilities: Design, implement, configure, and maintain Palo Alto Cortex XSIAM and Cortex XDR platforms.

Support multi-tenant SIEM environments, including tenant onboarding, role-based access, data segregation, dashboards, and reporting. Develop and optimize: Detection rules, Correlation rules, Analytics, Threat hunting queries, Watchlists, Alert suppression logic Design and manage Cribl log pipelines, including: Data modeling, Parsing, Normalization, Enrichment, Routing, Filtering, Replay, Log ingestion Integrate telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, and custom applications. Develop and maintain automated playbooks and response workflows using Python and Bash.

Support incident response, threat hunting, and SOC operations. Create and maintain: Runbooks, SOPs, Architecture diagrams, Data flow documentation, Knowledge articles Support Tier 1-Tier 3 SOC analysts through troubleshooting, tuning, and knowledge transfer. Monitor SIEM health, ingestion, availability, detection coverage, false positives, MTTD, MTTR, and operational metrics.

Ensure platform resilience, backup, recovery, lifecycle management, and change control. Collaborate with security architects, engineers, analysts, and business stakeholders to improve enterprise security capabilities. Required Skills & Experience: Hands-on experience with Palo Alto Cortex XSIAM and Cortex XDR architecture, implementation, administration, and operational support.

Experience supporting enterprise SIEM platforms within large multi-tenant environments. Experience supporting 24x7 Security Operations Centers (SOC). Strong detection engineering experience including: Correlation rules Threat hunting Analytics Dashboards Alert tuning False-positive reduction Hands-on Cribl administration including: Data modeling Log pipeline design Parsing Normalization Enrichment Routing Ingestion Experience developing automation using: Python Bash Experience onboarding cloud, endpoint, network, identity, SaaS, Windows, Linux, and custom application telemetry.

Strong knowledge of: Enterprise security architecture Incident response Secure system design Networking Identity & Access Management Cybersecurity frameworks Preferred Skills: Excellent written and verbal communication skills. Strong ability to create: Business Requirements Documents (BRD), Functional Requirements Documents (FRD), Use Cases, Process Documentation Experience gathering requirements through stakeholder interviews, policy documents, regulations, and business rules analysis. Knowledge of business modeling techniques and graphical process flow tools.

Ability to communicate effectively with: Executive management, Business users, Project managers, Technical teams, External stakeholders Education Bachelor's degree in Information Technology, Information Security, Computer Science, or related field. Eight (8) years of relevant experience may be substituted for the degree requirement. Minimum five (5) years supporting large enterprise IT environments or system deployments.

Preferred Certifications CISSP Security+ GIAC Palo Alto Cortex Certification Cribl Certification Other relevant SIEM or cybersecurity certifications