> Markdown version of [/jobs/ext/2716771-principal-consultant-soc-transformation-xsiam-deployment](https://www.wearedevelopers.com/jobs/ext/2716771-principal-consultant-soc-transformation-xsiam-deployment). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Consultant - SOC Transformation & XSIAM Deployment - **Company:** Palo Alto Networks - **Location:** Burbank, United States - **Experience:** Expert - **Salary:** $163,000.0 - $224,500.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing Security, Cyber Security, Security Information and Event Management, Mttr, QRadar, Cyber Threat Analysis, Splunk, Security Orchestration, Automation & Response - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/principal-consultant-soc-transformation-xsiam-deployment-paloaltonetworks-com-8588742 ## About the Role * A proven track record in modernizing Security Operations Centers (SOCs) to achieve automation, AI-driven detection, and measurable improvements in MTTD/MTTR * Exceptional executive presence, with strong verbal and written communication skills to engage with stakeholders from the SOC analyst to the CISO * Experience acting as a trusted advisor to senior security leaders, with the ability to diagnose challenges and deliver strategic recommendations * 10+ years of hands-on experience in deploying and integrating SIEM/security analytics solutions within large enterprise environments * 8+ years of experience with Security Operations Center (SOC) tooling, processes, and workflows * Hands-on technical mastery across SIEM, SOAR, EDR, cloud security, and threat intelligence * Ability to conceive, architect, and develop effective correlation and detection rules * Must be able to travel up to 30%, * Industry-recognized certifications such as CISSP, GIAC, etc. * Familiarity with a range of SIEM technologies, such as Splunk and IBM QRadar. ## Description As a Principal Consultant for SOC Transformation & XSIAM Deployment, you will be a seasoned leader at the forefront of our most strategic customer engagements. You will leverage a blend of consultative presence, technical mastery, and executive influence to guide customers through complex SOC transformations. Your primary role is to drive these large-scale programs, ensuring successful execution from log migration to sophisticated detection strategies, delivering measurable security outcomes., * Serve as the lead strategic advisor and subject matter expert for customers undertaking a full-scale SOC modernization with XSIAM. * Lead multi-national SOC transformation programs, consolidating fragmented detection and response processes into a unified, AI-driven platform. * Direct enterprise-scale XSIAM deployments, guiding customers from initial strategy through to full operationalization. * Devise and oversee comprehensive log ingestion strategies to ensure high-quality data fuels the XSIAM platform. * Architect and implement sophisticated detection strategies and correlation rules to fortify customer defenses against advanced threats. * Fine-tune and optimize log sources and correlation rules to maximize system performance and detection efficacy. * Identify opportunities to enhance analyst alert handling and response through automation, collaborating with teams to implement solutions. * Build and mentor high-performing professional services teams, fostering a culture of collaboration and accountability. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)