
Senior Professional Services Consultant – Cortex XSIAM, SIEM & Automation
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in California, +1 more state.
• Lead the comprehensive modernization of the Security Operations Center focusing on SIEM and SOAR capabilities.
• Assist enterprise clients in the process of log migration.
• Develop strategies for the onboarding, ingestion, and parsing of log sources into Cortex XSIAM.
• Create and refine correlation and detection rules across endpoint, network, and cloud environments.
• Oversee and optimize log source performance, ingestion rates, and detection logic.
• Convert manual SOC processes into automated and scalable workflows utilizing XSIAM automation playbooks.
• Develop custom Python integrations to connect Cortex XSIAM with third-party security tools and RESTful APIs.
• Implement and oversee content packs, custom layouts, and automated dashboards tailored for customer security scenarios.
• Act as a subject-matter expert on Cortex XSIAM, SIEM log architecture, correlation logic, and best practices in SOAR automation.
• Collaborate with security stakeholders to establish security metrics and develop strategic automation roadmaps.
• Facilitate technical workshops and generate technical design documentation to empower customer independence.
• Travel occasionally for on-site meetings with customers, strategic workshops, and technical kickoffs.
• Minimum of 6 years of hands-on experience in deploying, integrating, and managing enterprise SIEM solutions such as Splunk, IBM QRadar, or Microsoft Sentinel.
• At least 4 years of direct experience with SOC tools, incident response lifecycles, and security analysis across cloud, endpoint, and network layers.
• Demonstrated experience in creating playbooks, configuring correlation rules, and managing content and integrations within the Cortex ecosystem.
• Proficiency in Python for integrating security tools and scripting for automation.
• Strong skills in Regex for log parsing.
• Familiarity with RESTful APIs, JSON data structures, and third-party security integrations.
• Excellent written and verbal communication skills.
• Proven ability to author clear technical design documentation.
• Strong analytical mindset capable of troubleshooting complex technical workflows and integration processes independently.
• Proactive and consultative in understanding customer challenges and converting them into actionable engineering requirements.
• Willingness to travel occasionally, up to 10%, for on-site customer meetings, strategic workshops, and technical kickoffs.
• A Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience is preferred.
• Preferred certifications include Palo Alto Networks credentials such as PCNSE, PCDRA, or specialized XSOAR/XSIAM certifications.
• Industry certifications such as CISSP, GIAC, or vendor SIEM qualifications are preferred.
• Applicants must not require immigration sponsorship; this position does not support work visa sponsorship.
• Restricted stock units.
• Bonus opportunities.
• Employee benefits as detailed in the posting.
• Reasonable accommodations for qualified individuals with disabilities or special needs.
CVS Health
CVS Health
Get handpicked remote jobs straight to your inbox weekly.