
Senior XSIAM Consultant/Engineer β EMEA
Posted Aug 11

Posted Aug 11
This is a fully remote position, open to applicants in Netherlands.
β’ Lead the kickoff and planning stages for XSIAM deployments, establishing scope, objectives, timelines, and necessary resources.
β’ Conduct architectural discovery sessions that encompass client environments, security requirements, and integrations.
β’ Oversee and actively engage in Cortex XSIAM infrastructure deployments, including multi-tenant setups with child tenants.
β’ Facilitate the onboarding of data sources and the ingestion of security telemetry into XSIAM.
β’ Optimize endpoints to enhance data quality and minimize detection noise.
β’ Create correlation rules for sophisticated threat detection and alert generation.
β’ Configure Attack Surface Management functionalities.
β’ Design and refine data models and parsers.
β’ Identify opportunities for alert automation and playbook development with clients.
β’ Provide guidance on threat intelligence management and the integration of threat intelligence sources.
β’ Define specifications for and potentially assist in the development of custom widgets and reports.
β’ Lead and participate in SOC transformation initiatives.
β’ Generate architectural designs, configuration guides, operational runbooks, and other project-related documentation.
β’ A Bachelor's degree in Computer Science, Information Security, or a related discipline is required; a Master's degree is preferred.
β’ At least 8 years of experience in cybersecurity, with a focus on SOC, incident response, and threat detection.
β’ Proven experience in leading and delivering complex cybersecurity extended expertise engagements.
β’ Proficient in deploying, configuring, and optimizing Palo Alto Networks Cortex XSIAM.
β’ Extensive experience with SIEM platforms, SOAR technologies, and endpoint security solutions.
β’ Practical experience in data source integration, parsing, and data model creation.
β’ Familiarity with scripting languages such as Python for automation and data manipulation is advantageous.
β’ In-depth knowledge of MITRE ATT&CK, NIST, network security, endpoint security, cloud security, and threat intelligence.
β’ Experience with AWS, Azure, GCP, and containerization technologies is highly desirable.
β’ Outstanding written, verbal, communication, and presentation abilities.
β’ Strong interpersonal, organizational, and project management skills.
β’ Capability to work independently and collaboratively within a distributed team.
β’ A proactive, results-driven attitude and a dedication to client success.
β’ Preferred certifications include PCNSE, PCSAE, CISSP, CISM, GCIH, or GCFA.
β’ Complimentary training for all consultants.
β’ Opportunity for qualified consultants to facilitate workshops or bootcamps between projects or on a full-time basis.
β’ Support from the company along with strong relationships with consultants and partners.
Mercor
RTX
Expel
Get handpicked remote jobs straight to your inbox weekly.