1

Xsoar Jobs in Virginia (NOW HIRING)

Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent ...

... XSOAR .] Core Responsibilities * Strategic Execution: Lead the strategic implementation and optimization of SentinelOne EPP/EDR capabilities to strengthen the organization's endpoint security posture ...

Cyber Data Platform Architect

Reston, VA · On-site

$86.80 - $198/hr

Experience with SOAR platforms such as Swimlane, XSOAR, or Phantom * Experience with DevSecOps CI/CD pipelines in IL5 or IL6 environments * Experience with Python or scripting languages for security ...

New

Showing results 21-40

Xsoar information

See Virginia salary details

$5

$66

$84

How much do xsoar jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for xsoar in Virginia is $66.54, according to ZipRecruiter salary data. Most workers in this role earn between $51.67 and $79.02 per hour, depending on experience, location, and employer.

What is an XSOAR?

A XSOAR job typically involves working with Palo Alto Networks Cortex XSOAR, a security orchestration, automation, and response (SOAR) platform. Professionals in this role are responsible for integrating security tools, automating incident response workflows, and managing security playbooks. They work closely with SOC teams to enhance threat detection and response time. Strong skills in scripting (Python), API integrations, and cybersecurity operations are essential for success in this role.

What are the key skills and qualifications needed to thrive in the XSOAR position, and why are they important?

To thrive as a Cortex XSOAR (Security Orchestration, Automation, and Response) Engineer, you need strong expertise in cybersecurity, incident response, automation scripting (such as Python), and knowledge of SOAR platforms. Familiarity with the Palo Alto Networks Cortex XSOAR platform, relevant security certifications (like CISSP or CEH), and experience with SIEM and ticketing systems are typically required. Attention to detail, problem-solving skills, and effective communication are key soft skills for this role. These skills ensure timely and accurate automation of security tasks, effective collaboration with IT and security teams, and improved response to cyber threats.

What are the typical daily responsibilities of a Cortex XSOAR engineer?

As a Cortex XSOAR Engineer, your day-to-day responsibilities include designing, building, and maintaining playbooks to automate security incident response tasks. You will collaborate closely with SOC analysts, threat intelligence teams, and IT staff to streamline workflows and improve threat containment. Regular duties also involve integrating various security tools and monitoring their performance to ensure seamless automation. Additionally, you will participate in troubleshooting, optimizing scripts, and recommending improvements to enhance overall security operations efficiency.

What are the most commonly searched types of Xsoar jobs in Virginia?

The most popular types of Xsoar jobs in Virginia are:

Infographic showing various Xsoar job openings in Virginia as of August 2026, with employment types broken down into 71% Full Time, and 29% Contract. Highlights an 74% In-person, and 26% Remote job distribution, with an average salary of $138,413 per year, or $66.5 per hour.

Endpoint Security Engineer with Security Clearance

Halvik

Alexandria, VA • On-site

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago

New


Job description

Halvik Corp delivers a wide range of services to 13 executive agencies and 15 independent agencies. Halvik is a highly successful WOB business with more than 50 prime contracts and 500+ professionals delivering Digital Services, Advanced Analytics, Artificial Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part of something special! Position Overview The SentinelOne Endpoint Security Engineer is responsible for the administration, management, and optimization of the organization's endpoint security environment, with a primary focus on SentinelOne Endpoint Protection Platform (EPP) and Endpoint Detection and Response (EDR). This role works closely with Cybersecurity Operations teams to protect enterprise Windows endpoints from malware, ransomware, and advanced cyber threats while ensuring compliance with organizational security standards. This role is on site Monday through Friday in Alexandria, VA. The position is responsible for deploying and maintaining SentinelOne agents, managing endpoint security policies, investigating security alerts, and supporting incident response activities. Additionally, the engineer will leverage Microsoft Intune to administer endpoint security configurations and support the organization's transition from traditional endpoint management solutions to modern cloud-based management. The ideal candidate possesses strong experience in enterprise endpoint security, Windows administration, PowerShell automation, and security tool integration. This role also requires expertise in developing automated workflows through APIs and integrating endpoint security solutions with SIEM and SOAR platforms such as Microsoft Sentinel, Splunk, IBM QRadar, and Cortex XSOAR.] Core Responsibilities * Strategic Execution: Lead the strategic implementation and optimization of SentinelOne EPP/EDR capabilities to strengthen the organization's endpoint security posture and align with cybersecurity objectives. Drive the adoption of modern endpoint management practices through Microsoft Intune, supporting the transition from traditional on-premises management to cloud-based solutions. Develop and execute endpoint security roadmaps, ensuring compliance with security standards, regulatory requirements, and industry best practices. Enhance operational efficiency through PowerShell automation, API integrations, and SIEM/SOAR orchestration to improve threat detection, response, and reporting capabilities. Collaborate with cybersecurity, infrastructure, and operations teams to proactively identify risks, implement security controls, and support continuous security improvement initiatives. * Operational Oversight: Oversee daily operations of the SentinelOne EPP/EDR platform, ensuring continuous endpoint protection, policy compliance, and operational effectiveness across the enterprise. Monitor security alerts, investigate threats, and coordinate incident response activities to rapidly detect, contain, and remediate endpoint security risks. Manage endpoint security configurations and deployments through Microsoft Intune, ensuring consistent enforcement of security policies and compliance standards. Collaborate with cybersecurity and IT teams to maintain a secure, resilient, and well-governed endpoint environment while driving continuous operational improvements. * Collaboration: Partner with Cybersecurity Operations, Infrastructure, and IT support teams to strengthen endpoint security, streamline incident response, and ensure effective threat mitigation across the enterprise. Collaborate with stakeholders to implement and maintain security policies, compliance standards, and endpoint protection strategies using SentinelOne and Microsoft Intune. Work closely with security analysts, engineers, and administrators to integrate endpoint security solutions with SIEM/SOAR platforms and enhance security automation capabilities. Engage with business and technical teams to support endpoint management initiatives, drive continuous improvement, and promote security best practices throughout the organization. * Technical Performance: Demonstrate technical expertise in administering and optimizing the SentinelOne EPP/EDR platform to provide effective threat detection, prevention, and response capabilities across enterprise endpoints. Manage the deployment, configuration, and maintenance of SentinelOne agents and endpoint security policies to ensure consistent protection, compliance, and operational stability. Utilize Microsoft Intune, PowerShell scripting, and automation solutions to enhance endpoint management, streamline security operations, and improve reporting accuracy. Leverage SentinelOne APIs and SIEM/SOAR integrations to automate security workflows, accelerate incident response, and strengthen overall endpoint security posture. Apply advanced troubleshooting and analytical skills to resolve endpoint security, malware, ransomware, and Windows operating system issues while maintaining adherence to security baselines and best practices. Minimum Requirements * Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. * Experience: Minimum of three (3) years of experience administering enterprise endpoint security solutions. * Hands-on experience with SentinelOne EPP and EDR platforms. * Experience managing Windows 10/11 enterprise environments. * Experience deploying and managing Microsoft Intune policies and configurations. * Experience supporting enterprise cybersecurity operations and incident response activities. * Experience implementing endpoint hardening and security compliance standards. * Technical Proficiency: Strong expertise in SentinelOne administration, monitoring, and policy management. * Advanced PowerShell scripting and automation experience. * Strong knowledge of Microsoft Intune and modern endpoint management. * Experience with Microsoft Entra ID (Azure AD). * Knowledge of Windows security architecture and security controls. * Understanding of malware analysis, ransomware protections, and endpoint threat detection. * Familiarity with enterprise security frameworks such as NIST 800-53, CIS Benchmarks, and Zero Trust principles. * Knowledge of endpoint compliance monitoring and vulnerability remediation processes. * Compliance: ensuring devices and endpoint management processes meet organizational standards, security requirements, and configuration policies. It includes maintaining patch levels, enforcing device and application policies, supporting conditional access, and monitoring systems to verify that endpoints remain secure and aligned with enterprise requirements. * Must be eligible to obtain and maintain Public Trust clearance. Preferred Expertise * Strong analytical and troubleshooting skills. * Excellent written and verbal communication abilities. * Ability to manage multiple priorities in a fast-paced environment. * Strong problem-solving and decision-making capabilities. * Ability to work independently and collaboratively within cross-functional teams. * Commitment to continuous learning and cybersecurity best practices. Privacy Policy - Halvik Corp Halvik offers a competitive full benefits package including: Company-supported medical, dental, vision, life, STD, and LTD insurance Benefits include 11 federal holidays and PTO Eligible employees may receive performance-based incentives in recognition of individual and/or team achievements. 401(k) with company matching Flexible Spending Accounts for commuter, medical, and dependent care expenses Tuition Assistance Charitable Contribution matching Halvik Corp is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.