1

Xsoar Engineer Jobs in Raleigh, NC (NOW HIRING)

Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process ... Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent ...

Xsoar Engineer information

What is an XSOAR engineer?

An XSOAR Engineer is a cybersecurity professional who specializes in deploying, configuring, and maintaining Palo Alto Networks Cortex XSOAR (Extended Security Orchestration, Automation, and Response) platforms. Their main responsibilities include automating security operations, integrating threat intelligence, and developing playbooks to streamline incident response. XSOAR Engineers work closely with security teams to improve efficiency and reduce response times to cyber threats. They require strong knowledge of security operations, scripting, and integrating various security tools and APIs. This role is crucial in modern security operations centers (SOCs) to enhance automation and coordination of security processes.

What are the key skills and qualifications needed to thrive as an XSOAR engineer, and why are they important?

To thrive as an XSOAR Engineer, you need expertise in cybersecurity, scripting (such as Python), and incident response, usually supported by a degree in computer science or a related field. Familiarity with Palo Alto Cortex XSOAR, SIEM platforms, and relevant certifications like Palo Alto Networks Certified Security Automation Engineer (PCSAE) is essential. Strong problem-solving skills, attention to detail, and effective communication set top performers apart in this role. These skills and qualifications are vital for efficiently automating security operations and improving an organization's incident response capabilities.

What are some common challenges XSOAR engineers face when integrating new security tools into an existing SOAR platform?

XSOAR Engineers often encounter challenges when integrating new security tools due to differences in APIs, data formats, and authentication methods. Ensuring seamless communication between platforms requires strong troubleshooting skills and an in-depth understanding of both the SOAR platform and the third-party tool. Additionally, engineers must carefully map data fields and develop custom scripts when out-of-the-box integrations are not available. Collaboration with security analysts and vendors is essential to address compatibility issues and maintain effective automation workflows.

What is the difference between Xsoar Engineer vs Cortex XSOAR Specialist?

AspectXsoar EngineerCortex XSOAR Specialist
CertificationsRelevant security and cloud certifications, such as Palo Alto Networks certificationsSame certifications, often including Palo Alto Networks certifications
Work EnvironmentSecurity teams, cybersecurity firms, IT departmentsSecurity operations centers, cybersecurity consulting firms
Industry UsageUsed across industries for security automation and orchestrationPrimarily in cybersecurity and threat management sectors
Job FocusDesign, develop, and maintain Xsoar integrations and automationImplement, optimize, and manage Cortex XSOAR platforms and playbooks

Both roles focus on security automation with Cortex XSOAR, but Xsoar Engineers typically develop and maintain integrations, while Cortex XSOAR Specialists focus on platform deployment and management. The roles often overlap, especially in organizations using Cortex XSOAR for security operations.

What are popular job titles related to Xsoar Engineer jobs in Raleigh, NC?

For Xsoar Engineer jobs in Raleigh, NC, the most frequently searched job titles are:

What job categories do people searching Xsoar Engineer jobs in Raleigh, NC look for?

The top searched job categories for Xsoar Engineer jobs in Raleigh, NC are:

What cities near Raleigh, NC are hiring for Xsoar Engineer jobs?

Cities near Raleigh, NC with the most Xsoar Engineer job openings:

Infographic showing various Xsoar Engineer job openings in Raleigh, NC as of August 2026, with employment types broken down into 100% Full Time. Highlights an 49% In-person, and 51% Hybrid job distribution.

Contract W2 Only || Security Platform Engineer (SOC, Splunk, Cribl) || Remote

Noblesoft Technologies

Raleigh, NC • On-site

$40 - $50/hr

Contractor

Re-posted yesterday


Job description

Role: Security Platform Engineer
Location: Remote

In USA

Mandatory: Splunk, Cribl

Preferred: Automation

Job Summary

We are seeking an experienced Security Platform Engineer with strong expertise in Splunk Enterprise/Enterprise Security, Cribl Stream, and Security Automation platforms. The ideal candidate will be responsible for designing, implementing, optimizing, and supporting enterprise-scale SIEM and log management platforms while enabling automation across SOC operations.

Key Responsibilities

  • Design, implement, and maintain Splunk Enterprise and Splunk Enterprise Security environments.
  • Deploy, configure, and manage Cribl Stream for log routing, filtering, masking, enrichment, and optimization.
  • Develop and maintain data onboarding pipelines from various security and infrastructure sources.
  • Configure and troubleshoot log ingestion, parsing, normalization, CIM mapping, and data models.
  • Optimize Splunk searches, dashboards, reports, and correlation searches for performance and scalability.
  • Build and maintain detection use cases, alerts, and security monitoring content.
  • Develop automation workflows using SOAR platforms such as Tines, Splunk SOAR, Cortex XSOAR, or similar automation tools.
  • Integrate security tools including Microsoft Defender, CrowdStrike, Palo Alto, Zscaler, Okta, Azure, AWS, and other enterprise technologies.
  • Perform troubleshooting of ingestion issues, parsing problems, search performance, and distributed architecture.
  • Work closely with SOC analysts, security engineers, architects, and infrastructure teams.
  • Implement best practices for platform monitoring, health checks, capacity planning, and upgrades.
  • Create technical documentation, SOPs, and operational runbooks.

Required Skills

  • 5+ years of hands-on experience with Splunk Enterprise.
  • Strong experience administering and supporting Splunk Enterprise Security (ES).
  • Hands-on experience with Cribl Stream administration and pipeline development.
  • Strong understanding of log onboarding, parsing, field extraction, normalization, and CIM.
  • Experience with Splunk Search Processing Language (SPL).
  • Experience with index management, forwarders, deployment server, search heads, indexers, and clustered environments.
  • Experience integrating cloud and security products with Splunk.
  • Knowledge of Linux administration and troubleshooting.
  • Experience with REST APIs and JSON.
  • Scripting experience using Python, PowerShell, or Bash.
  • Strong troubleshooting and analytical skills.

Preferred Skills

  • Experience with security automation platforms such as Tines, Splunk SOAR, Cortex XSOAR, Swimlane, or Torq.
  • Experience with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto, AWS, Azure, or GCP.
  • Knowledge of MITRE ATT&CK framework.
  • Familiarity with security operations and incident response workflows.
  • Experience with Git, CI/CD, and Infrastructure as Code.
  • Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Cribl Certified User/Admin, or security certifications such as CISSP or GIAC.

Nice to Have

  • Experience designing enterprise SIEM architectures.
  • Experience with threat detection engineering.
  • Experience implementing SOC automation and orchestration workflows.
  • Exposure to cloud-native security monitoring and observability platforms.