XSIAM Security Analyst

Saundersscott
UK
2 months ago
Apply on saundersscott.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

CompTIA Security+ Cyber Security Issue Tracking Systems Python (Programming Language) Microsoft Security Essentials Windows PowerShell Security Information and Event Management Scripting Palo Alto Networks Security Orchestration, Automation & Response

Job description

  • Monitor and manage alerts generated by XSIAM in real-time.
  • Perform initial incident triage, validation, and categorization.
  • Execute predefined automation playbooks for common alerts.
  • Escalate complex incidents to Level 3 analysts with detailed context.
  • Document incident details and actions taken in ticketing systems.
  • Support the transition and knowledge sharing with Level 3 analysts.

Requirements

  • Proficient in managing Palo Alto XSIAM platform alerts, incidents, and automation workflows.
  • Strong understanding of security event correlation, alert triage, and incident escalation.
  • Experience with integrating XSIAM with other security tools (SIEM, SOAR, EDR, etc.).
  • Knowledge of threat intelligence feeds, data sources, and automation scripting (Python, PowerShell, etc.).
  • Familiarity with incident response processes, including containment, eradication, and recovery., * 3+ years of experience in SOC operations or security monitoring.
  • Hands-on experience with Palo Alto XSIAM or similar SOAR/SIEM platforms.
  • Previous involvement in managing security alerts, performing initial investigations, and escalating incidents.
  • Client references from similar deployments are a plus.

Certifications & Qualifications:

  • Palo Alto Networks Certified Cybersecurity Associate (PCSA) or equivalent.
  • Certified SOC Analyst (CSA) or equivalent cybersecurity certifications (e.g., CompTIA Security+, GIAC Security Essentials)., * Strong communication skills for clear incident reporting.
  • Ability to work effectively in a global, 24/7 environment.
  • Team-oriented with a proactive approach to problem-solving.
  • Flexibility to adapt to shift rotations and peak demand periods.

Location & Flexibility:

  • Preferably based in or willing to operate across EMEA, APAC, or AMER regions.
  • Open to remote work within secure, compliant environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on saundersscott.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

Videos

See all

Related articles

See all