Cyber - Palo Alto SecOps - Senior Consultant

Deloitte T.T.L.
Seattle, WA, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services ARM Architecture Microsoft Azure Cyber Security Data Normalization Identity and Access Management Security Information and Event Management Data Ingestion Information Technology Palo Alto Networks Cyber Warfare Splunk

Job description

Experteer Overview In this role you will help clients strengthen cyber resilience by leading Next-Generation SOC initiatives within Deloitte’s Cyber Defense & Resilience team. You will design and deploy advanced SOC capabilities (including Cortex XSIAM) and optimize SIEM/SOAR workflows to improve threat visibility and response. You’ll integrate diverse log sources, refine data quality, and advise on detection use cases and automation strategies. You collaborate with cross-functional teams to tailor solutions to client needs and communicate findings to stakeholders. This is a high-impact consulting position at a firm that prioritizes innovation, client outcomes, and professional growth. Compensation / Benefits * Design and deploy Next-Generation SOC platforms (Cortex XSIAM) with advanced detection rules, SIEM ingestion, and SOAR playbooks * Integrate log and telemetry sources for data normalization and operational visibility * Develop and optimize automated response workflows for incident containment and remediation * Advise clients on threat detection use cases, automation strategies, and SOC capabilities * Collaborate with cross-functional teams to enhance solutions, incorporate threat intelligence, and present findings to client stakeholders Tasks * Bachelor in Computer Science or related technical field * 4+ years in cloud, network, or identity security including 3+ years with AWS, GCP, or Azure and native security tools * 3+ years with SOC tools/platforms such as Cortex XSIAM, Cortex XDR, Splunk or similar SIEM * 3+ years in SOC detection engineering, automation/playbook development, data ingestion and data normalization * 3+ years with endpoint detection and response (EDR) platforms (e.g., Microsoft Defender, Cortex XDR, CrowdStrike) and governance, risk, or compliance work using established frameworks * Palo Alto Networks PCNSE, CCSP, CEH or CISSP-like certifications (preferred) * Ability to travel ~50% and potential limited immigration sponsorship Key requirements *

Requirements

You containment and remediation * Advise clients on threat detection use cases, automation strategies, and SOC capabilities * Collaborate with cross-functional teams to enhance solutions, incorporate threat intelligence, and present findings to client stakeholders Tasks * Bachelor in Computer Science or related technical field * 4+ years in cloud, network, or identity security including 3+ years with AWS, GCP, or Azure and native security tools * 3+ years with SOC tools/platforms such as Cortex XSIAM, Cortex XDR, Splunk or similar SIEM * 3+ years in SOC detection engineering, automation/playbook development, data ingestion and data normalization * 3+ years with endpoint detection and response (EDR) platforms (e.g., Microsoft Defender, Cortex XDR, CrowdStrike) and governance, risk, or compliance work using established frameworks * Palo Alto Networks PCNSE, CCSP, CEH or CISSP-like certifications (preferred) * Ability to travel ~50% and potential limited immigration sponsorship Key aaaaaaaaaai _ *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all