1

Xsoar Engineer Jobs in Bothell, WA (NOW HIRING)

Xsoar Engineer information

What are the key skills and qualifications needed to thrive as an XSOAR engineer, and why are they important?

To thrive as an XSOAR Engineer, you need expertise in cybersecurity, scripting (such as Python), and incident response, usually supported by a degree in computer science or a related field. Familiarity with Palo Alto Cortex XSOAR, SIEM platforms, and relevant certifications like Palo Alto Networks Certified Security Automation Engineer (PCSAE) is essential. Strong problem-solving skills, attention to detail, and effective communication set top performers apart in this role. These skills and qualifications are vital for efficiently automating security operations and improving an organization's incident response capabilities.

What is an XSOAR engineer?

An XSOAR Engineer is a cybersecurity professional who specializes in deploying, configuring, and maintaining Palo Alto Networks Cortex XSOAR (Extended Security Orchestration, Automation, and Response) platforms. Their main responsibilities include automating security operations, integrating threat intelligence, and developing playbooks to streamline incident response. XSOAR Engineers work closely with security teams to improve efficiency and reduce response times to cyber threats. They require strong knowledge of security operations, scripting, and integrating various security tools and APIs. This role is crucial in modern security operations centers (SOCs) to enhance automation and coordination of security processes.

What are some common challenges XSOAR engineers face when integrating new security tools into an existing SOAR platform?

XSOAR Engineers often encounter challenges when integrating new security tools due to differences in APIs, data formats, and authentication methods. Ensuring seamless communication between platforms requires strong troubleshooting skills and an in-depth understanding of both the SOAR platform and the third-party tool. Additionally, engineers must carefully map data fields and develop custom scripts when out-of-the-box integrations are not available. Collaboration with security analysts and vendors is essential to address compatibility issues and maintain effective automation workflows.

What is the difference between Xsoar Engineer vs Cortex XSOAR Specialist?

AspectXsoar EngineerCortex XSOAR Specialist
CertificationsRelevant security and cloud certifications, such as Palo Alto Networks certificationsSame certifications, often including Palo Alto Networks certifications
Work EnvironmentSecurity teams, cybersecurity firms, IT departmentsSecurity operations centers, cybersecurity consulting firms
Industry UsageUsed across industries for security automation and orchestrationPrimarily in cybersecurity and threat management sectors
Job FocusDesign, develop, and maintain Xsoar integrations and automationImplement, optimize, and manage Cortex XSOAR platforms and playbooks

Both roles focus on security automation with Cortex XSOAR, but Xsoar Engineers typically develop and maintain integrations, while Cortex XSOAR Specialists focus on platform deployment and management. The roles often overlap, especially in organizations using Cortex XSOAR for security operations.

What are popular job titles related to Xsoar Engineer jobs in Bothell, WA?

For Xsoar Engineer jobs in Bothell, WA, the most frequently searched job titles are:

What job categories do people searching Xsoar Engineer jobs in Bothell, WA look for?

The top searched job categories for Xsoar Engineer jobs in Bothell, WA are:

What cities near Bothell, WA are hiring for Xsoar Engineer jobs?

Cities near Bothell, WA with the most Xsoar Engineer job openings:

Infographic showing various Xsoar Engineer job openings in Bothell, WA as of June 2026, with employment types broken down into 57% Full Time, and 43% Contract. Highlights an 80% In-person, and 20% Remote job distribution.

Threat and Incident Response Engineer

Volanno

Seattle, WA • On-site

Full-time

Posted 2 days ago

New


Job description

Description

Volanno is seeking two Threat and Incident Response Engineers to support the information security team at Sound Transit, the regional transit authority serving the Puget Sound area. The work spans the corporate IT network and the operational technology that runs transit systems. Time is split about evenly between responding to security incidents and proactive threat hunting, with detection tuning running underneath both.

On the incident side, this role owns alerts from the moment they arrive. That means triage out of SIEM, EDR, NDR, and the OT monitoring platform, then analysis, escalation, and guidance on containment, eradication, and recovery. This team member will write the root cause analyses and incident reports that go to Sound Transit leadership, keep incident metrics current, and build out response playbooks. In the OT environment the work also involves reading industrial network traffic and coordinating directly with plant and engineering staff, since a response step that is routine on a corporate network can take something offline that needs to stay running.

On the hunting side, this team member will form hypotheses and test them against endpoint, network, log, and OT protocol telemetry. What the hunts turn up becomes new detection content. Coverage is mapped against MITRE ATT&CK to guide where hunts focus next, and threat intelligence feeds back into the following round.

Alert quality runs through both halves of the job. Detection tuning is a standing part of the role, so expect meaningful time on rule tuning, suppression logic, correlation and enrichment, and SOAR automation.

This position will function within a highly motivated, dynamic team. We are looking for someone who works calmly during an active incident and who takes the initiative on hunting rather than waiting for work to be assigned.

Requirements

Required Background

Bachelor's degree from an accredited U.S. college or university in Computer Science, Information Security, Information Systems, or a related subject.

Minimum of ten (10) years of experience in cybersecurity operations for the senior position, or five (5) or more years for the mid-level position, covering both security incident response and proactive threat hunting.

Demonstrated experience responding to security incidents in an Operational Technology (OT), ICS, or SCADA environment, not enterprise IT alone.

Ability to pass a Sound Transit background check.

Ability to work Pacific Time business hours and to be onsite in the Seattle area on occasion.

Required Abilities, Knowledge & Skills

Proven experience managing security incidents end to end, from triage through containment, eradication, recovery, and post-incident review.

Working proficiency with a major SIEM such as Microsoft Sentinel, Splunk, or QRadar, including writing and tuning detection content.

Working proficiency with EDR such as Microsoft Defender for Endpoint, CrowdStrike, or SentinelOne, and with network detection and response tooling.

Experience with OT monitoring platforms such as Dragos, Claroty, or Nozomi Networks.

Practical fluency with MITRE ATT&CK, including ATT&CK for ICS, and the ability to map detection and hunt coverage against it.

Ability to design and run hypothesis-driven threat hunts across endpoint, network, log, and OT protocol telemetry.

Detection engineering skills, including writing and refining correlation rules, queries, and use cases in SIEM and EDR platforms.

A track record of reducing false positives, alert noise, and duplicate ticketing, with metrics to support it.

Familiarity with industrial protocols and industrial network traffic analysis, such as Modbus, DNP3, OPC, or BACnet.

Experience folding threat intelligence into hunting and detection workflows.

Ability to produce incident documentation, root cause analysis reports, SOPs, playbooks, and metrics such as MTTD, MTTR, and SLA adherence.

Judgment to recognize when a standard IT containment action is unsafe in an operational environment, and to work out a safe alternative with engineering staff.

Strong written and verbal communication skills, with the ability to brief technical responders and executive stakeholders.

Ability to work independently within a client environment and coordinate across information security, infrastructure, operations, and engineering teams.


Preferred

Experience supporting a transit, rail, utility, or other critical infrastructure organization

Public sector or government client experience

Certifications such as GCIH, GCIA, GCFA, GNFA, GICSP, GRID, or CISSP

SOAR automation and playbook development using Sentinel Automation Rules, Splunk SOAR, Cortex XSOAR, or a comparable platform

Experience standing up or maturing a formal threat hunting program

Familiarity with the NIST Cybersecurity Framework, NIST SP 800-82, IEC 62443, and TSA Security Directives

Scripting for detection and automation, such as KQL, SPL, Python, or PowerShell

Digital forensics or malware analysis capability

Experience mentoring SOC analysts or leading post-incident reviews


Company Profile

Volanno is a certified woman-owned small business based in Washington, DC. As an IT solution provider, our services include custom software development, program management, and advanced data analytics. From scoping and defining to implementation and support, we are ready to support our clients' needs at any stage of development in designing and building solutions that prepare them for the future.

Volanno is an equal opportunity employer. Volanno will consider all qualified applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status.