1

Xsoar Jobs in Tennessee (NOW HIRING)

Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent ...

Xsoar information

See Tennessee salary details

$5

$69

$88

How much do xsoar jobs pay per hour?

As of Aug 20, 2026, the average hourly pay for xsoar in Tennessee is $69.06, according to ZipRecruiter salary data. Most workers in this role earn between $53.62 and $82.01 per hour, depending on experience, location, and employer.

What is an XSOAR?

A XSOAR job typically involves working with Palo Alto Networks Cortex XSOAR, a security orchestration, automation, and response (SOAR) platform. Professionals in this role are responsible for integrating security tools, automating incident response workflows, and managing security playbooks. They work closely with SOC teams to enhance threat detection and response time. Strong skills in scripting (Python), API integrations, and cybersecurity operations are essential for success in this role.

What are the key skills and qualifications needed to thrive in the XSOAR position, and why are they important?

To thrive as a Cortex XSOAR (Security Orchestration, Automation, and Response) Engineer, you need strong expertise in cybersecurity, incident response, automation scripting (such as Python), and knowledge of SOAR platforms. Familiarity with the Palo Alto Networks Cortex XSOAR platform, relevant security certifications (like CISSP or CEH), and experience with SIEM and ticketing systems are typically required. Attention to detail, problem-solving skills, and effective communication are key soft skills for this role. These skills ensure timely and accurate automation of security tasks, effective collaboration with IT and security teams, and improved response to cyber threats.

What are the typical daily responsibilities of a Cortex XSOAR engineer?

As a Cortex XSOAR Engineer, your day-to-day responsibilities include designing, building, and maintaining playbooks to automate security incident response tasks. You will collaborate closely with SOC analysts, threat intelligence teams, and IT staff to streamline workflows and improve threat containment. Regular duties also involve integrating various security tools and monitoring their performance to ensure seamless automation. Additionally, you will participate in troubleshooting, optimizing scripts, and recommending improvements to enhance overall security operations efficiency.

What are the most commonly searched types of Xsoar jobs in Tennessee?

The most popular types of Xsoar jobs in Tennessee are:

Infographic showing various Xsoar job openings in Tennessee as of August 2026, with employment types broken down into 74% Full Time, and 26% Contract. Highlights an 74% In-person, and 26% Remote job distribution, with an average salary of $143,653 per year, or $69.1 per hour.

Full-time

Re-posted 18 days ago


Job description

Description

Position Summary: 

FRDA is looking for a Workflow Automation Engineer to design, build, and optimize automated processes across our security and IT ecosystem. This role focuses on reducing manual effort, improving response times, and ensuring consistent, scalable execution of critical workflows. 


This role is ideal for someone looking to have a positive impact on security processes and work with a driven, multi-disciplined team. 


This role is onsite in Nashville, TN. 


Primary Duties and Responsibilities: 

  • Design and implement automated workflows for security and IT operations, including incident response, vulnerability management, and identity lifecycle processes. 
  • Integrate systems and tools (e.g., SIEM, EDR, IAM, ticketing platforms, cloud services) using APIs and webhooks. 
  • Develop and maintain automation scripts and services primarily in Python or similar languages. 
  • Build and manage orchestration within Security Orchestration, Automation, and Response (SOAR) platforms or workflow engines. 
  • Ensure workflows, such as logging, monitoring, and alerting, are reliable, scalable, and observable. 
  • Collaborate with security and operations teams to translate manual processes into automation. 
  • Maintain version control, testing, and deployment pipelines for automation assets. 
  • Continuously improve workflows based on incident reviews and operational feedback. 

Requirements

Minimum Qualifications: 

  • A minimum of three (3) years of experience in automation, security engineering, DevOps, or related roles. 
  • Strong scripting or programming skills (Python preferred). 
  • Experience integrating systems via APIs and working with distributed systems. 
  • Familiarity with cybersecurity technologies and frameworks such as Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), and Identity and Access Management (IAM). 
  • Understanding of security or IT operational processes. 
  • Experience with cloud platforms such as AWS, Azure, or GCP. 


Preferred Qualifications: 

  • Experience with SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR, and Torq). 
  • Knowledge of Infrastructure as Code practices such as Terraform. 
  • Familiarity with modeling, detection and prevention concepts such as MITRE ATT&CK. 
  • Experience working in regulated or compliance-driven environments.