1

Xsoar Engineer Jobs in Portland, OR (NOW HIRING)

Xsoar Engineer information

What are the key skills and qualifications needed to thrive as an XSOAR engineer, and why are they important?

To thrive as an XSOAR Engineer, you need expertise in cybersecurity, scripting (such as Python), and incident response, usually supported by a degree in computer science or a related field. Familiarity with Palo Alto Cortex XSOAR, SIEM platforms, and relevant certifications like Palo Alto Networks Certified Security Automation Engineer (PCSAE) is essential. Strong problem-solving skills, attention to detail, and effective communication set top performers apart in this role. These skills and qualifications are vital for efficiently automating security operations and improving an organization's incident response capabilities.

What is an XSOAR engineer?

An XSOAR Engineer is a cybersecurity professional who specializes in deploying, configuring, and maintaining Palo Alto Networks Cortex XSOAR (Extended Security Orchestration, Automation, and Response) platforms. Their main responsibilities include automating security operations, integrating threat intelligence, and developing playbooks to streamline incident response. XSOAR Engineers work closely with security teams to improve efficiency and reduce response times to cyber threats. They require strong knowledge of security operations, scripting, and integrating various security tools and APIs. This role is crucial in modern security operations centers (SOCs) to enhance automation and coordination of security processes.

What are some common challenges XSOAR engineers face when integrating new security tools into an existing SOAR platform?

XSOAR Engineers often encounter challenges when integrating new security tools due to differences in APIs, data formats, and authentication methods. Ensuring seamless communication between platforms requires strong troubleshooting skills and an in-depth understanding of both the SOAR platform and the third-party tool. Additionally, engineers must carefully map data fields and develop custom scripts when out-of-the-box integrations are not available. Collaboration with security analysts and vendors is essential to address compatibility issues and maintain effective automation workflows.

What is the difference between Xsoar Engineer vs Cortex XSOAR Specialist?

AspectXsoar EngineerCortex XSOAR Specialist
CertificationsRelevant security and cloud certifications, such as Palo Alto Networks certificationsSame certifications, often including Palo Alto Networks certifications
Work EnvironmentSecurity teams, cybersecurity firms, IT departmentsSecurity operations centers, cybersecurity consulting firms
Industry UsageUsed across industries for security automation and orchestrationPrimarily in cybersecurity and threat management sectors
Job FocusDesign, develop, and maintain Xsoar integrations and automationImplement, optimize, and manage Cortex XSOAR platforms and playbooks

Both roles focus on security automation with Cortex XSOAR, but Xsoar Engineers typically develop and maintain integrations, while Cortex XSOAR Specialists focus on platform deployment and management. The roles often overlap, especially in organizations using Cortex XSOAR for security operations.

What are popular job titles related to Xsoar Engineer jobs in Portland, OR? For Xsoar Engineer jobs in Portland, OR, the most frequently searched job titles are:
What job categories do people searching Xsoar Engineer jobs in Portland, OR look for? The top searched job categories for Xsoar Engineer jobs in Portland, OR are:
Infographic showing various Xsoar Engineer job openings in Portland, OR as of August 2026, with employment types broken down into 80% Full Time, and 20% Contract. Highlights an 73% In-person, 4% Hybrid, and 23% Remote job distribution.

Cyber - Google SecOps - Senior Consultant

Deloitte

Portland, OR

Other

Posted 7 days ago


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 92 frontline employees who took The Breakroom Quiz

46th of 150 rated financial services


Job description

Join Deloitte's Cyber practice as a Cyber SecOps Senior Consultant and help clients navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat detection engineering, and automation. You will work with cross-functional teams to develop, implement, and optimize solutions that strengthen monitoring, detection, response, and operational efficiency. Your contributions will help clients build more secure, reliable, and effective cyber operations capabilities.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Cyber SecOps Senior Consultant on the Cyber Defense & Resilience team, you will be responsible for:

  • Designing and implementing secure, scalable, and resilient Google SecOps architectures for security information and event management (SIEM) and security orchestration, automation, and response (SOAR) deployments aligned with enterprise security policies and regulatory requirements, including General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
  • Leading deployment of log ingestion pipelines using data fabric technologies and application programming interface integrations, including Bindplane and cloud feeds
  • Collaborating with security operations center analysts and threat detection engineers to prioritize, develop, and tune threat detection content within Google SecOps to detect malicious behavior and adversary activity in enterprise environments
  • Translating security operations processes into SOAR playbooks and custom integrations to support automated data ingestion, alert enrichment, triage, and response
  • Building case management solutions within Google SecOps SOAR, supporting operational metrics and analyst workflows, mentoring junior team members, and staying current on cybersecurity threats, vulnerabilities, and compliance trends

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

The team

Deloitte's Cyber Defense & Resilience offering helps clients defend against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence capabilities. The team works with organizations to manage dynamic attack surfaces and strengthen readiness, response, and recovery across cyber incidents and broader business disruptions.

Qualifications

Required:

  • Bachelor's degree in computer science, cybersecurity, information systems, or equivalent work experience
  • 7+ years of experience in security operations, threat detection engineering, or enterprise information technology security
  • Experience with Google Cloud's SecOps tool stack and architecture, specifically security information and event management (SIEM) and security orchestration, automation, and response (SOAR), formerly Google Chronicle and Siemplify
  • Experience with security principles and frameworks such as MITRE ATT&CK and Cyber Kill Chain
  • Experience with Python for automation and integration development
  • Experience with Gostash or Logstash for log normalization and parsing, and with extract, transform, and load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, or Kafka
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Google Cloud Professional Cloud Architect, Google Cloud Professional Cloud Security Engineer, or Certified Cloud Security Professional certification
  • Experience with threat hunting or cyber threat intelligence
  • Experience with data fabric technologies such as Bindplane or Cribl
  • Experience with infrastructure and networking concepts such as IP networking, virtual private networks (VPNs), domain name system (DNS), load balancing, or firewalls
  • Experience with cloud infrastructure platforms such as Amazon Web Services (AWS) or Microsoft Azure
  • Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google Threat Intelligence

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.


Qualifications:

Join Deloitte's Cyber practice as a Cyber SecOps Senior Consultant and help clients navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat detection engineering, and automation. You will work with cross-functional teams to develop, implement, and optimize solutions that strengthen monitoring, detection, response, and operational efficiency. Your contributions will help clients build more secure, reliable, and effective cyber operations capabilities.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Cyber SecOps Senior Consultant on the Cyber Defense & Resilience team, you will be responsible for:

  • Designing and implementing secure, scalable, and resilient Google SecOps architectures for security information and event management (SIEM) and security orchestration, automation, and response (SOAR) deployments aligned with enterprise security policies and regulatory requirements, including General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
  • Leading deployment of log ingestion pipelines using data fabric technologies and application programming interface integrations, including Bindplane and cloud feeds
  • Collaborating with security operations center analysts and threat detection engineers to prioritize, develop, and tune threat detection content within Google SecOps to detect malicious behavior and adversary activity in enterprise environments
  • Translating security operations processes into SOAR playbooks and custom integrations to support automated data ingestion, alert enrichment, triage, and response
  • Building case management solutions within Google SecOps SOAR, supporting operational metrics and analyst workflows, mentoring junior team members, and staying current on cybersecurity threats, vulnerabilities, and compliance trends

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

The team

Deloitte's Cyber Defense & Resilience offering helps clients defend against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence capabilities. The team works with organizations to manage dynamic attack surfaces and strengthen readiness, response, and recovery across cyber incidents and broader business disruptions.

Qualifications

Required:

  • Bachelor's degree in computer science, cybersecurity, information systems, or equivalent work experience
  • 7+ years of experience in security operations, threat detection engineering, or enterprise information technology security
  • Experience with Google Cloud's SecOps tool stack and architecture, specifically security information and event management (SIEM) and security orchestration, automation, and response (SOAR), formerly Google Chronicle and Siemplify
  • Experience with security principles and frameworks such as MITRE ATT&CK and Cyber Kill Chain
  • Experience with Python for automation and integration development
  • Experience with Gostash or Logstash for log normalization and parsing, and with extract, transform, and load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, or Kafka
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Google Cloud Professional Cloud Architect, Google Cloud Professional Cloud Security Engineer, or Certified Cloud Security Professional certification
  • Experience with threat hunting or cyber threat intelligence
  • Experience with data fabric technologies such as Bindplane or Cribl
  • Experience with infrastructure and networking concepts such as IP networking, virtual private networks (VPNs), domain name system (DNS), load balancing, or firewalls
  • Experience with cloud infrastructure platforms such as Amazon Web Services (AWS) or Microsoft Azure
  • Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google Threat Intelligence

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.


Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom