1

Xsoar Engineer Jobs in Amherst, MA (NOW HIRING)

Xsoar Engineer information

What is an XSOAR engineer?

An XSOAR Engineer is a cybersecurity professional who specializes in deploying, configuring, and maintaining Palo Alto Networks Cortex XSOAR (Extended Security Orchestration, Automation, and Response) platforms. Their main responsibilities include automating security operations, integrating threat intelligence, and developing playbooks to streamline incident response. XSOAR Engineers work closely with security teams to improve efficiency and reduce response times to cyber threats. They require strong knowledge of security operations, scripting, and integrating various security tools and APIs. This role is crucial in modern security operations centers (SOCs) to enhance automation and coordination of security processes.

What are the key skills and qualifications needed to thrive as an XSOAR engineer, and why are they important?

To thrive as an XSOAR Engineer, you need expertise in cybersecurity, scripting (such as Python), and incident response, usually supported by a degree in computer science or a related field. Familiarity with Palo Alto Cortex XSOAR, SIEM platforms, and relevant certifications like Palo Alto Networks Certified Security Automation Engineer (PCSAE) is essential. Strong problem-solving skills, attention to detail, and effective communication set top performers apart in this role. These skills and qualifications are vital for efficiently automating security operations and improving an organization's incident response capabilities.

What are some common challenges XSOAR engineers face when integrating new security tools into an existing SOAR platform?

XSOAR Engineers often encounter challenges when integrating new security tools due to differences in APIs, data formats, and authentication methods. Ensuring seamless communication between platforms requires strong troubleshooting skills and an in-depth understanding of both the SOAR platform and the third-party tool. Additionally, engineers must carefully map data fields and develop custom scripts when out-of-the-box integrations are not available. Collaboration with security analysts and vendors is essential to address compatibility issues and maintain effective automation workflows.

What is the difference between Xsoar Engineer vs Cortex XSOAR Specialist?

AspectXsoar EngineerCortex XSOAR Specialist
CertificationsRelevant security and cloud certifications, such as Palo Alto Networks certificationsSame certifications, often including Palo Alto Networks certifications
Work EnvironmentSecurity teams, cybersecurity firms, IT departmentsSecurity operations centers, cybersecurity consulting firms
Industry UsageUsed across industries for security automation and orchestrationPrimarily in cybersecurity and threat management sectors
Job FocusDesign, develop, and maintain Xsoar integrations and automationImplement, optimize, and manage Cortex XSOAR platforms and playbooks

Both roles focus on security automation with Cortex XSOAR, but Xsoar Engineers typically develop and maintain integrations, while Cortex XSOAR Specialists focus on platform deployment and management. The roles often overlap, especially in organizations using Cortex XSOAR for security operations.

What cities near Amherst, MA are hiring for Xsoar Engineer jobs?

Cities near Amherst, MA with the most Xsoar Engineer job openings:

IT - Technology Architect | Identity Management | IDAM-Design , work flow , Implementation

Spruce Infotech

Springfield, MA • On-site

Full-time

Re-posted 16 days ago


Job description

Job title - Mobile Device Vulnerability Management & Configuration Compliance Engineer
Work location - Springfield, Boston or New York/ NJ
Is it Hybrid, onsite or remote position - Onsite
Tentative Start date - Start Date will be decided based on candidate selection by client
Contract duration - 12 months
Vendor rate - 87.66
Does this position require Visa independent candidates only? Yes
Minimum years of experience needed in the required skills- 5 years of experience
Minimum over all work experience required - 5 years
Domain - Cyber Security : Application Security
JD:
The Mobile Device Vulnerability Management & Configuration Compliance Engineer will partner
with internal stakeholders to design, validate, and operationalize an automated mobile device
vulnerability scanning and configuration compliance capability across enterprise-issued mobile
endpoints (iOS/iPadOS and Android). This role leads proof-of-technology (PoT) activities including
tool evaluation, architecture validation, security controls mapping, and pilot execution, and drives
full-scale implementation through integration with other security tools such as MDM, SIEM/SOAR,
ITSM, and asset inventory/CMDB systems.
The engineer will establish and maintain mobile vulnerability management processes aligned to
corporate and regulatory requirements, develop continuous compliance and policy enforcement
strategies, implement risk-based remediation workflows, and deliver measurable improvements in
mobile endpoint security posture.
Key Responsibilities
• Define PoT scope, success criteria, and test plans for automated mobile vulnerability
scanning (e.g., agent-based/agentless, MDM-integrated, API-driven).
• Evaluate candidate tools for: coverage (OS/app/cert/profile), detection accuracy,
scalability, device impact, privacy controls, and reporting fidelity.
• Execute pilots across representative device populations validating:
o vulnerability detection capabilities (OS versions, CVEs, patch levels, risky apps)
o configuration compliance checks (encryption, jailbreak/root, screen lock, OS
hardening)
o integration readiness (Intune/Workspace ONE/Jamf; SIEM; ITSM; CMDB)
• Produce PoT outcomes: findings, risk analysis, cost/benefit, architecture decision record,
and go/no-go recommendation.
• Coordinate with InfoSec and Compliance teams to ensure SaaS platform posture aligns with
regulatory requirements (NYDFS).
• Build and run mobile vulnerability lifecycle processes: discovery, assessment, prioritization,
remediation, validation, reporting.
• Establish severity/risk scoring tuned for mobile (exposure, device role, app risk, compliance
impact).
• Coordinate remediation with endpoint engineering, mobility admins, app owners, and
operations teams.
• Validate remediation effectiveness using scanner re-runs, policy compliance, and audit
evidence.
• Develop, deploy, and continuously improve baseline security configurations for iOS/iPadOS
and Android.
• Translate requirements into enforceable policies (password/biometrics, encryption, OS
update controls, app controls, certificate/profile constraints, VPN/Wi-Fi security, logging
settings).
• Implement compliance monitoring and drift detection; drive automated or semi-automated
corrective actions.
• Build automation scripts and APIs to normalize and enrich findings
• Support change management and communications for new controls impacting device
behavior and user experience.
• Provide technical guidance and training to operations teams for ongoing support.
Required Skills
• Mobile OS security fundamentals: iOS/iPadOS and Android security models, patching,
permissions, app ecosystems, jailbreak/root detection concepts.
• Vulnerability management expertise: CVE/patch lifecycle, risk-based prioritization, SLAs,
validation, metrics.
• Configuration compliance: baseline hardening, policy enforcement, continuous compliance
monitoring, and drift remediation.
• Mobility Scanning Tool Experience (hands-on): Qualys Mobile VMDR, Lookout, Workspace
One + Microsoft Threat Defense, or equivalent.
• MDM experience (hands-on): Microsoft Intune, Omnissa Workspace ONE, Jamf Pro, or
equivalent.
• Enterprise integration skills: API integration, data normalization, and automation with
SIEM/SOAR/ITSM (e.g., Splunk, Sentinel, QRadar; XSOAR, Sentinel SOAR; ServiceNow).
• Identity & access: conditional access concepts, device compliance states, SSO,
certificates, MFA, posture-based access controls.
• Scripting/automation: PowerShell and/or Python; familiarity with REST APIs, JSON, OAuth,
and secrets management.
• Security documentation: ability to author PoT plans, architecture diagrams, operational
runbooks, and audit evidence.
• Excellent documentation and stakeholder management skills.
• Strong analytical and problem-solving skills.
• Excellent communication and stakeholder management skills; experience presenting PoT
results and recommendations.
• Ability to work independently and across multifunctional teams.
• Detail-oriented with a focus on process improvement and operational excellence.
• Ability to manage multiple workstreams (pilot + integration + operations) with minimal
supervision.
• Familiarity with NIST, CIS Benchmarks, DISA STIG (mobile), ISO 27001 control mapping, or
similar frameworks.
Educational Requirements
• Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering,
or equivalent practical experience.
Relevant Certifications
• CompTIA Security+, CySA+
• GIAC: GSEC, GMON, or related (if available/appropriate)
• Qualys/Rapid7/Tenable (or equivalent vulnerability platform certifications where relevant)
• Governance / Risk / Architecture (bonus)
• CISSP, CISM, CCSP
• ITIL Foundation (for ITSM integration and operations maturity)
Experience Level
• 5 - 8+ years in cybersecurity/endpoint security, with 2 - 4+ years specifically in mobile/UEM
security, vulnerability management, or compliance engineering.
Interview mode - In person/Virtual : Virtual
How many rounds of interview - minimum 2 rounds.