1

Xsoar Engineer Jobs in Virginia (NOW HIRING)

SOAR Engineer

Gainesville, VA ยท On-site

$95K - $105K/yr

Experience with playbook development using Security Orchestration and Automated Response (SOAR) platforms such as Tines, Palo Alto XSOAR, Splunk Phantom, or Swimlane * Experience with programming ...

Sr. Torq/SOAR Engineer

Falls Church, VA ยท On-site

$140K - $190K/yr

The Sr. TORQ/SOAR Engineer serves as a technical leader and trusted authority for Security ... Stay current on competing SOAR technologies (e.g., Palo Alto Cortex XSOAR, Splunk SOAR, Siemplify ...

Senior DevOps Engineer TS/SCI (or eligible)

Reston, VA ยท On-site

$137K - $176K/yr

This role is ideal for a seasoned engineer and technical leader who is passionate about automation ... Experience with Palo Alto XDR / XSOAR / XSIAM and/or Prisma Cloud / Cortex Cloud is highly desired.

Senior DevOps Engineer TS/SCI (or eligible)

Reston, VA ยท On-site

$137K - $176K/yr

This role is ideal for a seasoned engineer and technical leader who is passionate about automation ... Experience with Palo Alto XDR / XSOAR / XSIAM and/or Prisma Cloud / Cortex Cloud is highly desired.

Additionally, the engineer will leverage Microsoft Intune to administer endpoint security ... XSOAR .] Core Responsibilities * Strategic Execution: Lead the strategic implementation and ...

Endpoint Security Engineer

Alexandria, VA ยท On-site

$100K - $110K/yr

Additionally, the engineer will leverage Microsoft Intune to administer endpoint security ... XSOAR .] Core Responsibilities * Strategic Execution: Lead the strategic implementation and ...

Endpoint Security Engineer

Alexandria, VA ยท On-site

$100K - $110K/yr

Additionally, the engineer will leverage Microsoft Intune to administer endpoint security ... XSOAR .] Core Responsibilities * Strategic Execution: Lead the strategic implementation and ...

Senior AI Security Engineer

Mclean, VA ยท On-site

$115K - $158K/yr

LLM Performance Engineering: Continuously evaluate, benchmark, and optimize LLM performance ... Palo Alto XSOAR). * Experience deploying and scaling AI workloads in containerized cloud ...

Senior DevOps Engineer TS/SCI (or eligible)

Reston, VA ยท Hybrid

$137K - $176K/yr

This role is ideal for a seasoned engineer and technical leader who is passionate about automation ... Experience with Palo Alto XDR / XSOAR / XSIAM and/or Prisma Cloud / Cortex Cloud is highly desired.

next page

Showing results 1-20

Xsoar Engineer information

What are the key skills and qualifications needed to thrive as an XSOAR Engineer, and why are they important?

To thrive as an XSOAR Engineer, you need expertise in cybersecurity, scripting (such as Python), and incident response, usually supported by a degree in computer science or a related field. Familiarity with Palo Alto Cortex XSOAR, SIEM platforms, and relevant certifications like Palo Alto Networks Certified Security Automation Engineer (PCSAE) is essential. Strong problem-solving skills, attention to detail, and effective communication set top performers apart in this role. These skills and qualifications are vital for efficiently automating security operations and improving an organization's incident response capabilities.

What is an XSOAR Engineer?

An XSOAR Engineer is a cybersecurity professional who specializes in deploying, configuring, and maintaining Palo Alto Networks Cortex XSOAR (Extended Security Orchestration, Automation, and Response) platforms. Their main responsibilities include automating security operations, integrating threat intelligence, and developing playbooks to streamline incident response. XSOAR Engineers work closely with security teams to improve efficiency and reduce response times to cyber threats. They require strong knowledge of security operations, scripting, and integrating various security tools and APIs. This role is crucial in modern security operations centers (SOCs) to enhance automation and coordination of security processes.

What are some common challenges XSOAR Engineers face when integrating new security tools into an existing SOAR platform?

XSOAR Engineers often encounter challenges when integrating new security tools due to differences in APIs, data formats, and authentication methods. Ensuring seamless communication between platforms requires strong troubleshooting skills and an in-depth understanding of both the SOAR platform and the third-party tool. Additionally, engineers must carefully map data fields and develop custom scripts when out-of-the-box integrations are not available. Collaboration with security analysts and vendors is essential to address compatibility issues and maintain effective automation workflows.

What is the difference between Xsoar Engineer vs Cortex XSOAR Specialist?

AspectXsoar EngineerCortex XSOAR Specialist
CertificationsRelevant security and cloud certifications, such as Palo Alto Networks certificationsSame certifications, often including Palo Alto Networks certifications
Work EnvironmentSecurity teams, cybersecurity firms, IT departmentsSecurity operations centers, cybersecurity consulting firms
Industry UsageUsed across industries for security automation and orchestrationPrimarily in cybersecurity and threat management sectors
Job FocusDesign, develop, and maintain Xsoar integrations and automationImplement, optimize, and manage Cortex XSOAR platforms and playbooks

Both roles focus on security automation with Cortex XSOAR, but Xsoar Engineers typically develop and maintain integrations, while Cortex XSOAR Specialists focus on platform deployment and management. The roles often overlap, especially in organizations using Cortex XSOAR for security operations.

What are popular job titles related to Xsoar Engineer jobs in Virginia? For Xsoar Engineer jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Xsoar Engineer jobs in Virginia look for? The top searched job categories for Xsoar Engineer jobs in Virginia are:
What cities in Virginia are hiring for Xsoar Engineer jobs? Cities in Virginia with the most Xsoar Engineer job openings:
Sr. Information Systems Security Engineer - Splunk/ACAS/Trellix with Security Clearance

Sr. Information Systems Security Engineer - Splunk/ACAS/Trellix with Security Clearance

Amentum

Warrenton, VA โ€ข On-site

$114K - $157K/yr

Other

Posted 6 days ago


Job description

In support of a challenging, critical, and rewarding program that provides integrated voice, video, and data services throughout the Information Technology lifecycle, Amentum is seeking Senior Information System Security Engineer (ISSE) to serve as a subject matter expert in the design, implementation, and optimization of enterprise security toolsets. The successful candidate will lead the engineering efforts for the Trellix (ePO) ecosystem and the ACAS (Nessus) suite, ensuring mission-critical assets remain secure, compliant, and resilient. This role requires a blend of high-level security architecture, hands-on troubleshooting, and the ability to drive secure-by-design principles across the System Development Life Cycle (SDLC). You must be a critical thinker, have a strong work ethic, and be able to work independently or as a member of a team in a dynamic environment. We value candidates who are detail-oriented while also being able to think and react quickly to emerging and unique problem sets. To be successful, you must be able to rapidly adapt and learn how to operate the front and back end of new products and processes. Work Schedule: 5 Days (Mon โ€“ Fri); 8 hrs/Day; 40 hrs/wkly
Essential Responsibilities: The duties and responsibilities of the Senior Information Systems Security Engineer include, but are not limited to the following: Endpoint Security Engineering (Trellix/ePO)
Ecosystem Management: Expertly design, configure, and maintain Trellix components (ePO, Trellix Agent, DLP, HIPS, Policy Auditor, ABM, and VSE) across Windows and Linux environments.
Policy Development: Author and deploy endpoint security policies for ENS modules (Threat Prevention, Firewall, Web Control) based on DISA STIGs and organizational needs.
Threat Mitigation: Develop custom signatures, rules, and exceptions to address zero-day threats and specific operational requirements.
Operational Continuity: Validate custom exceptions to ensure uninterrupted operation of mission-critical processes without compromising compliance.
Vulnerability Management (ACAS/Nessus)
Architecture & Strategy: Design enterprise-wide vulnerability scanning strategies and manage the deployment of Security Centers and Nessus scanners.
Advanced Troubleshooting: Serve as the final escalation point for complex scan issues, credentialing problems, and system communication failures.
Risk Reporting: Configure automated reporting of compliance data to continuous monitoring systems and risk-scoring repositories.
Security Integration & Engineering
Tool Orchestration: Integrate Trellix and ACAS with tools such as Splunk, XSOAR, and ServiceNow to automate workflows and enhance incident response.
RMF Support: Provide authoritative recommendations and ACAS-generated artifacts to support the Assessment and Authorization (A&A) process and RMF packages for Authority to Operate (ATO).
Strategic Oversight: Lead the maintenance and scalability of test, development, and operational environments, collaborating with Network and DevSecOps teams to enhance resilience.
Multi-Tier Support: Deliver Tier 1โ€“3 maintenance and incident response for the full cybersecurity portfolio (ACAS, Trellix, Splunk, XSOAR).
Compliance Mastery: Deep understanding of DISA STIGs, NIST 800-53, and the Risk Management Framework (RMF).
Minimum Requirements: Must have active Top-Secret clearance with SCI or TS with the ability to acquire SCI
Knowledge and experience with NESSUS/ACAS and Trellix administration
Experience in Splunk role while working in a Splunk Clustered Environment
Must be able to work a 40-hour work week, normally Monday through Friday.
Ability to work overtime during critical peaks and be available to meet last-minute requests for overtime if needed.
Ability to travel (5-10%) primarily within 75 miles.
Familiarity with MS Office applications such as Excel, Word, Outlook, SharePoint, Project, and Visio.
Exceptional attention to detail; excellent verbal and written communication skills; strong critical thinking, organizational, time-management, and problem-solving skills.โ€ฏโ€ฏโ€ฏโ€ฏ
Ability to work both independently and as part of a team in a dynamic environment.โ€ฏโ€ฏ
Clearance Required: Must have active Top-Secret clearance with SCI or TS with the ability to acquire SCI
Minimum Education: Bachelorโ€™s Degree in a related field (Cyber and/or Engineering)
Minimum Years of Experience: 8 years of relevant experience
Required Certifications: Must possess, or be able to obtain, one of the following 8140 IAT Level II or III baseline certifications before a start date:
Level II certifications include โ€“ CCNA Security, GISCP, GSEC, Security+ CE, SSCP
Level III certifications include โ€“ CASP CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH
Preferred Qualifications: RHEL Administration: Proficient understanding of Red Hat Enterprise Linux (RHEL) 8 and 9, including the ability to monitor and maintain cybersecurity tools at the OS level.
SOAR Automation: Experience managing the full lifecycle of XSOAR infrastructure, including building complex playbooks, custom scripts, and integrations to automate cyber workflows.
Splunk O&M: Proficiency in Splunk Operations & Maintenance, including managing distributed components, index management, version upgrades, and creating custom dashboards via the Monitoring Console.