
Senior XSIAM Consultant/Engineer
Posted Sep 20

Posted Sep 20
This is a fully remote position, open to applicants in Netherlands.
β’ Lead the initiation and planning stages for XSIAM deployments, outlining scope, objectives, timelines, and resource needs.
β’ Facilitate architectural discovery sessions that explore client environments, security requirements, and integration points.
β’ Supervise and take part in Cortex XSIAM infrastructure deployments, including intricate multi-tenant setups with child tenants.
β’ Provide guidance and assistance for onboarding data sources for security telemetry ingestion into XSIAM.
β’ Optimize endpoints to enhance data quality and minimize noise.
β’ Create and execute correlation rules for advanced threat detection and alert generation.
β’ Set up Attack Surface Management capabilities to enhance visibility of the digital attack surface.
β’ Design, develop, and refine data models and parsers.
β’ Identify opportunities for alert automation and playbook development, contributing to implementation as necessary.
β’ Apply threat intelligence management best practices and integrate various threat intelligence sources.
β’ Specify requirements for and assist in the development of custom widgets and reports.
β’ Lead and take part in SOC transformation initiatives utilizing XSIAM.
β’ Produce documentation, including architectural designs, configuration guides, and operational runbooks.
β’ Bachelor's degree in Computer Science, Information Security, or a related discipline.
β’ At least 8 years of experience in cybersecurity, with a strong emphasis on Security Operations Centers (SOC), incident response, and threat detection.
β’ Proven track record in leading and executing complex cybersecurity engagements.
β’ Demonstrated expertise in deploying, configuring, and optimizing Palo Alto Networks Cortex XSIAM.
β’ Extensive familiarity with SIEM platforms, SOAR technologies, and endpoint security solutions.
β’ Practical experience with data source integration, parsing, and data model creation.
β’ Proficiency in scripting languages like Python for automation and data manipulation is advantageous.
β’ In-depth understanding of security frameworks such as MITRE ATT&CK and NIST.
β’ Expertise in network security, endpoint security, cloud security, and threat intelligence.
β’ Strong analytical and problem-solving skills with the ability to troubleshoot complex technical problems.
β’ Familiarity with AWS, Azure, GCP, and containerization technologies is highly desirable.
β’ Exceptional written, verbal, and presentation skills.
β’ Strong interpersonal abilities and capacity to build rapport and trust with clients.
β’ Excellent organizational and project management skills.
β’ Capability to work independently and as part of a distributed team.
β’ Proactive, results-driven mindset with a commitment to client success.
β’ Preferred certifications include: PCNSE, PCSAE, CISSP, CISM, GCIH, or GCFA.
β’ Free training available for all consultants.
β’ Opportunities for qualified consultants to conduct workshops or bootcamps during or between projects.
β’ Ongoing support from Saddleback Solutions throughout engagements.
Mercor
RTX
Expel
Qualus
Get handpicked remote jobs straight to your inbox weekly.