Cortex XSIAM Security Engineer
CELESTIAL INNOVATIONS GROUP LLC
Job Description
Job Description
Benefits:
- 401(k)
- Competitive salary
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Celestial Innovations Group (CIG) is seeking a skilled Cortex XSIAM Security Engineer to deploy, configure, and operationalize Palo Alto Networks Cortex XSIAM for federal and enterprise clients. This role is at the center of CIG's AI-driven Security Operations practice, enabling clients to modernize their SOC by consolidating SIEM, XDR, SOAR, UEBA, ASM, and TIP capabilities into a single, converged platform. The Cortex XSIAM Engineer will serve as a subject-matter expert (SME) throughout the full platform lifecycle: from requirements gathering and architecture design through deployment, integration, and continuous optimization — driving measurable improvements in threat detection and incident response times for our government and commercial clients. Must be located in the DC Metro Area as this role requires onsite and remote support.
Key Responsibilities
Platform Deployment & Integration
- Lead end-to-end deployment of Cortex XSIAM for federal and enterprise clients, including data source onboarding, log ingestion, and normalization.
- Integrate XSIAM with existing security ecosystem tools including firewalls, endpoints, cloud platforms, identity providers, and ticketing systems.
- Configure data pipelines to ingest and normalize telemetry from diverse sources (endpoints, network, cloud, identity) into XSIAM's unified data model.
- Migrate clients from legacy SIEM platforms to Cortex XSIAM, ensuring continuity of detection coverage and compliance reporting.
- Build and tune correlation rules, behavioral analytics, and ML-based detection models within XSIAM to reduce false positive rates and improve detection fidelity.
- Develop and maintain XSIAM analytics leveraging XQL (Extended Query Language) to extract actionable insights from security telemetry.
- Map detection content to MITRE ATT&CK framework, ensuring coverage across all relevant tactics, techniques, and procedures (TTPs).
- Configure AI SmartScoring and technique-based incident grouping to reduce alert fatigue and prioritize analyst workload effectively.
- Design, build, and maintain SOAR automation playbooks within XSIAM to automate triage, enrichment, and remediation workflows.
- Leverage Cortex Marketplace content packs and develop custom integrations as needed to support client-specific security processes.
- Implement dev/prod playbook lifecycle management to ensure safe testing and controlled promotion of automation content.
- Continuously improve automation coverage, targeting measurable reductions in manual analyst workload.
- Serve as escalation point for complex incident investigations, using XSIAM causality chains and full attack-story visualizations to support rapid remediation.
- Coordinate with client SOC teams during active incidents, leveraging XSIAM's embedded automation and enrichment capabilities.
- Support Attack Surface Management (ASM) functions to proactively identify and remediate client exposure.
- Utilize integrated Threat Intelligence Platform (TIP) capabilities, including Unit 42 threat feeds, to enrich alerts and inform response priorities.
- Serve as a trusted technical advisor to federal and commercial clients on XSIAM capabilities, roadmap, and SOC modernization strategy.
- Produce SOC performance dashboards, compliance reports, and executive summaries within XSIAM to support client governance requirements.
- Conduct training and knowledge transfer sessions to build client SOC team proficiency on the XSIAM platform.
- Support CIG business development efforts by contributing to proposals, demos, and technical capability briefings for prospective clients.
- 3+ years of hands-on experience with Palo Alto Networks Cortex XDR or Cortex XSIAM in an enterprise or federal environment.
- Demonstrated experience deploying or administering SIEM platforms (Splunk, Microsoft Sentinel, IBM QRadar, or equivalent).
- Proficiency with XQL or comparable query languages for log analysis and threat hunting.
- Working knowledge of SOAR concepts and experience building security automation playbooks.
- Understanding of EDR, NDR, and UEBA technologies and how they feed into a converged SOC platform.
- Familiarity with MITRE ATT&CK framework and its application to detection engineering.
- Active Secret clearance (minimum); TS/SCI preferred for federal engagements.
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field, OR equivalent professional experience.
- Palo Alto Networks Certified Security Automation Engineer (PCSAE) or Cortex XSIAM-specific certification.
- Experience with federal compliance frameworks including NIST SP 800-53, RMF, DISA STIGs, and CDM program requirements.
- Familiarity with Zero Trust Architecture principles (NIST SP 800-207, CISA ZT Maturity Model) and how XSIAM supports ZTA adoption.
- Experience integrating Cortex XSIAM with Palo Alto Networks NGFW, Prisma Cloud, or Zscaler platforms.
- Knowledge of cloud security telemetry sources (AWS, Azure, GCP) and their ingestion into XSIAM.
- Exposure to Python or JavaScript for custom XSIAM integration development or automation scripting.
- Prior experience supporting federal SOC operations or DHS CDM program environments.
- CISSP, CEH, CompTIA Security+, or equivalent security certification.
SOC Platforms
- Cortex XSIAM / XDR
- Cortex XSOAR
- SIEM platforms
- XQL query language
- EDR / NDR / UEBA
- MITRE ATT&CK
- NIST SP 800-53 / RMF
- NIST SP 800-207 (Zero Trust Architecture)
- CISA Zero Trust Maturity Model
- DISA STIGs
- Palo Alto NGFW / Prisma
- Zscaler ZIA / ZPA
- Microsoft Sentinel / Azure
- ServiceNow / Ticketing systems
- AWS / Azure / GCP
Flexible work from home options available.
Vacancy posted 11 days ago
Similar jobs that could be interesting for youBased on the Cortex XSIAM Security Engineer in Washington DC vacancy
- ...Artificial Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology across the... ...The SentinelOne Endpoint Security Engineer is responsible for the administration,... ...Microsoft Sentinel, Splunk, IBM QRadar, and Cortex XSOAR .] Core Responsibilities...SuggestedMonday to FridayFlexible hours
- ...s Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across... ...with at least one of the following: Splunk, Palo Alto XSIAM, or Crowdstrike NG SIEM ~ Security certification such as...SuggestedRemote work
- ...Senior Security Engineer Evolver Federal is seeking a Senior Security Engineer to fulfill a requirement for a potential government client... ...reporting Hands-on experience with SIEM (Splunk, Elastic), SOAR (Cortex XSOAR), and EDR (CrowdStrike, Microsoft Defender)....SuggestedContract workFlexible hours
$178.4k - $226.7k
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience... ...Services. Apart from work, we provide opportunities for our engineers to pursue projects they are passionate about while maintaining...SuggestedInternshipFlexible hours$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats...SuggestedInternshipFlexible hours$136k - $184k
Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering undetected threat activities at petabyte scale. In this role, you will work alongside other Threat Hunting engineers to proactively...InternshipFlexible hoursShift work- ...business development efforts for upcoming opportunities with the U.S. Department of State’s Bureau of Diplomatic Security (DS) - Training - Technical Security Engineering. The Advisor will play a critical role in refining our understanding of the client landscape, validating...Contract workWork at office
$178.4k - $226.7k
AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...InternshipRemote workFlexible hours- Washington DCTechnology - Security /RemoteThe Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services that support our business. You will understand data and automation are important ingredients to our mission and...Temporary workWork at officeRemote workWork from homeFlexible hours
$145k - $200k
Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds the world’s leading software for data-driven... ...the way a real attacker would. As an Offensive Security Engineer, you will test internal applications and infrastructure, chain...Full timeWork experience placementWork at officeRemote workWork from homeRelocation package- ...Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most complex technology... ...and New Zealand market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure capacity to deliver...Full timeLocal area
- ...Responsibilities The U.S. Cybersecurity and Infrastructure Security (CISA) mission is to lead the national effort to protect and enhance... ...as well as its MEOs. This task order is to provide Enterprise Engineering and Operations Support Services (EEOSS) to CISA/OCIO to...Full timeNight shift
- ...project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have... ...Washington, DCJob DescriptionThe Identity and Authentication Security Engineer/Admin will be responsible for technical support to security...Remote work
$230k - $385k
...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are... ...customers in the public sector. As a Forward Deployed Security Engineer (FDSecE) you will be responsible for securing these novel applications...Work at officeLocal areaRemote workRelocation packageFlexible hours$5,000 per month
...Candidates who are not U.S. citizens are not eligible for this role. Imagine One Technology & Management, Ltd. is seeking two (2) Security Engineers. This position is contingent upon award of the associated work and will be performed in Dahlgren, Virginia.The Security...Work at office$120k - $130k
Job DescriptionEverforth ECS is seeking an Identity Security Engineer to work in our Washington, DC office / remote. The role is contingent upon additional funding.We are seeking a technically experienced Identity Security Engineer to join our security operations division...Work at officeRemote work$110k - $135k
...00 colleagues worldwide, all of whom are equity owners of the firm.Brown Advisory is currently seeking an Identity and Access Security Engineer to lead and mature the firm's identity security controls across Okta, Microsoft Entra ID, Active Directory, CyberArk, BloodHound...Full timeTemporary workFor contractorsH1bWorldwide$320k - $405k
...Security Engineer, Corporate Security San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC About Anthropic Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and...Visa sponsorshipFlexible hours- ...Security Engineer III The Security Engineer III will evaluate, implement, maintain, and monitor IT security measures utilized by USAC. The individual in this position is responsible for reviewing both new and existing applications for security vulnerabilities and compliance...
$100k
...Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Security Engineer to support enterprise cybersecurity operations and IT administrative and operational support services for a federal government client. This position requires an active...Local areaRemote workFlexible hours- ...Responsibilities: Developing, enhancing, and maintaining Security Operations Center (SOC) standard operating procedures (SOPs)... ...action items and outcomes, and briefing leadership on security engineering status and results. Supporting SOC alert analysis, triage,...
$320k - $405k
...Extend device-trust and zero-trust access controls while balancing security protections with employee workflow needs. Build identity... ...software security reviews. Partner with Security, IT, and Engineering on telemetry, detections, shared standards, and secure...Full timeWork at officeVisa sponsorshipFlexible hours- ...Security Engineer The Security Engineer implements and operates security controls on AWS. You will perform security testing, support ATO evidence and continuous monitoring, and remediate findings, helping keep a high-visibility federal filing platform secure and compliant...For contractorsFlexible hours
$10 per hour
...configuration drift across our critical SaaS applications. Own security configuration for the SaaS tools hundreds of Flexporters use... ...years of experience in corporate, enterprise, or IT security engineering — we care more about what you've shipped than the exact number...Work at officeImmediate startFlexible hours- ...Security Engineer We are seeking a highly skilled Security Engineer with strong DevOps experience and an active U.S. Government security clearance to support and secure cloud environments across AWS GovCloud, Azure Government, and DoD environments. The ideal candidate...Contract work
$180k - $230k
...As a Information System Security Engineer (ISSE) you will play a critical role in ensuring the confidentiality, integrity, and availability of information systems across their life-cycle. The ISSE conducts comprehensive information system security engineering activities...Full timeContract workWork experience placement- ...Federal and State Government Agencies. Learn More About ProSidian Consulting at DescriptionProSidian seeks a Mid-Level InfoSec Security Engineer (Focus On Network Security) Consultant focusing on Cyber-Security/Information Security (INFOSEC) and IT Effectiveness Solution...Full timeFor contractorsWork experience placementInternshipWork at officeMonday to FridayShift work
$138k - $166k
As a Sr. Endpoint Security Engineer (Trellix) I, you’ll serve as the technical lead for the organization's endpoint security and data protection ecosystem, balancing day-to-day operational support with strategic cybersecurity engineering initiatives. You will work closely...Full timeLocal area- GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and... ...prime contractors. We are growing our federal presales engineering team and looking for technically exceptional engineers who thrive...Contract workFor contractorsRemote workFlexible hours
$125.12k - $187.68k
...solutions for the nation’s most mission-critical facilities, secure environments, complex infrastructure, and global enterprises.... ...secure, and innovative power and technology solutions through engineering expertise and smart systems integration.Why Join Us?Our people...Work at officeLocal areaFlexible hoursNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cortex XSIAM Security Engineer. Be the first to apply!
Related searches
- security infrastructure engineer Washington DC
- information system security engineer Washington DC
- sr information security engineer Washington DC
- senior cloud security engineer Washington DC
- security engineer Washington DC
- senior security operations engineer Washington DC
- information technology security engineer Washington DC
- application security engineer Washington DC
- offensive security engineer Washington DC
- network security engineer Washington DC



