> Markdown version of [/jobs/ext/1958229-cortex-xsiam-security-engineer](https://www.wearedevelopers.com/jobs/ext/1958229-cortex-xsiam-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cortex XSIAM Security Engineer - **Company:** CELESTIAL INNOVATIONS GROUP, LLC - **Location:** Washington, DC, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, Data Analysis, ARM Architecture, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Query Languages, Issue Tracking Systems, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Zero Trust Network Access, Security Information and Event Management, Systems Integration, Scripting, Google Cloud, Data Ingestion, Mitre Att&ck, QRadar, Cyber Threat Analysis, Firewalls (Computer Science), SC Clearance, Information Technology, Cybercrime, Palo Alto Networks, Microsoft Sentinel, Enterprise Integration, Cortex XSOAR Platform, Marketplace, Prisma Cloud Platform, Splunk, Data Pipelines, Security Orchestration, Automation & Response, Servicenow - **Published:** August 6, 2026 - **Apply:** https://www.wayup.com/i-j-Cortex-XSIAM-Security-Engineer-CELESTIAL-INNOVATIONS-GROUP-LLC-508916725398734/ ## About the Role 3+ years of hands-on experience with Palo Alto Networks Cortex XDR or Cortex XSIAM in an enterprise or federal environment. Demonstrated experience deploying or administering SIEM platforms (Splunk, Microsoft Sentinel, IBM QRadar, or equivalent). Proficiency with XQL or comparable query languages for log analysis and threat hunting. Working knowledge of SOAR concepts and experience building security automation playbooks. Understanding of EDR, NDR, and UEBA technologies and how they feed into a converged SOC platform. Familiarity with MITRE ATT&CK framework and its application to detection engineering. Active Secret clearance (minimum); TS/SCI preferred for federal engagements. Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field, OR equivalent professional experience. Preferred Qualifications Palo Alto Networks Certified Security Automation Engineer (PCSAE) or Cortex XSIAM-specific certification. Experience with federal compliance frameworks including NIST SP 800-53, RMF, DISA STIGs, and CDM program requirements. Familiarity with Zero Trust Architecture principles (NIST SP 800-207, CISA ZT Maturity Model) and how XSIAM supports ZTA adoption. Experience integrating Cortex XSIAM with Palo Alto Networks NGFW, Prisma Cloud, or Zscaler platforms. Knowledge of cloud security telemetry sources (AWS, Azure, GCP) and their ingestion into XSIAM. Exposure to Python or JavaScript for custom XSIAM integration development or automation scripting. Prior experience supporting federal SOC operations or DHS CDM program environments. CISSP, CEH, CompTIA Security+, or equivalent security certification. Technical Skills & Tools SOC Platforms Cortex XSIAM / XDR Cortex XSOAR SIEM platforms XQL query language EDR / NDR / UEBA Security Frameworks MITRE ATT&CK NIST SP 800-53 / RMF NIST SP 800-207 (Zero Trust Architecture) CISA Zero Trust Maturity Model DISA STIGs Integrations & Tools Palo Alto NGFW / Prisma Zscaler ZIA / ZPA Microsoft Sentinel / Azure ServiceNow / Ticketing systems AWS / Azure / GCP ## Description The Cortex XSIAM Engineer will serve as a subject-matter expert (SME) throughout the full platform lifecycle: from requirements gathering and architecture design through deployment, integration, and continuous optimization - driving measurable improvements in threat detection and incident response times for our government and commercial clients. Must be located in the DC Metro Area as this role requires onsite and remote support. Key Responsibilities Platform Deployment & Integration Lead end-to-end deployment of Cortex XSIAM for federal and enterprise clients, including data source onboarding, log ingestion, and normalization. Integrate XSIAM with existing security ecosystem tools including firewalls, endpoints, cloud platforms, identity providers, and ticketing systems. Configure data pipelines to ingest and normalize telemetry from diverse sources (endpoints, network, cloud, identity) into XSIAM's unified data model. Migrate clients from legacy SIEM platforms to Cortex XSIAM, ensuring continuity of detection coverage and compliance reporting. Detection Engineering & Analytics Build and tune correlation rules, behavioral analytics, and ML-based detection models within XSIAM to reduce false positive rates and improve detection fidelity. Develop and maintain XSIAM analytics leveraging XQL (Extended Query Language) to extract actionable insights from security telemetry. Map detection content to MITRE ATT&CK framework, ensuring coverage across all relevant tactics, techniques, and procedures (TTPs). Configure AI SmartScoring and technique-based incident grouping to reduce alert fatigue and prioritize analyst workload effectively. Automation & Playbook Development Design, build, and maintain SOAR automation playbooks within XSIAM to automate triage, enrichment, and remediation workflows. Leverage Cortex Marketplace content packs and develop custom integrations as needed to support client-specific security processes. Implement dev/prod playbook lifecycle management to ensure safe testing and controlled promotion of automation content. Continuously improve automation coverage, targeting measurable reductions in manual analyst workload. Incident Response & Threat Management Serve as escalation point for complex incident investigations, using XSIAM causality chains and full attack-story visualizations to support rapid remediation. Coordinate with client SOC teams during active incidents, leveraging XSIAM's embedded automation and enrichment capabilities. Support Attack Surface Management (ASM) functions to proactively identify and remediate client exposure. Utilize integrated Threat Intelligence Platform (TIP) capabilities, including Unit 42 threat feeds, to enrich alerts and inform response priorities. Client Engagement & Advisory Serve as a trusted technical advisor to federal and commercial clients on XSIAM capabilities, roadmap, and SOC modernization strategy. Produce SOC performance dashboards, compliance reports, and executive summaries within XSIAM to support client governance requirements. Conduct training and knowledge transfer sessions to build client SOC team proficiency on the XSIAM platform. Support CIG business development efforts by contributing to proposals, demos, and technical capability briefings for prospective clients. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)