Cortex XSIAM Security Engineer
CELESTIAL INNOVATIONS GROUP LLC
Job Description
Job Description
Benefits:
- 401(k)
- Competitive salary
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Celestial Innovations Group (CIG) is seeking a skilled Cortex XSIAM Security Engineer to deploy, configure, and operationalize Palo Alto Networks Cortex XSIAM for federal and enterprise clients. This role is at the center of CIG's AI-driven Security Operations practice, enabling clients to modernize their SOC by consolidating SIEM, XDR, SOAR, UEBA, ASM, and TIP capabilities into a single, converged platform. The Cortex XSIAM Engineer will serve as a subject-matter expert (SME) throughout the full platform lifecycle: from requirements gathering and architecture design through deployment, integration, and continuous optimization — driving measurable improvements in threat detection and incident response times for our government and commercial clients. Must be located in the DC Metro Area as this role requires onsite and remote support.
Key Responsibilities
Platform Deployment & Integration
- Lead end-to-end deployment of Cortex XSIAM for federal and enterprise clients, including data source onboarding, log ingestion, and normalization.
- Integrate XSIAM with existing security ecosystem tools including firewalls, endpoints, cloud platforms, identity providers, and ticketing systems.
- Configure data pipelines to ingest and normalize telemetry from diverse sources (endpoints, network, cloud, identity) into XSIAM's unified data model.
- Migrate clients from legacy SIEM platforms to Cortex XSIAM, ensuring continuity of detection coverage and compliance reporting.
- Build and tune correlation rules, behavioral analytics, and ML-based detection models within XSIAM to reduce false positive rates and improve detection fidelity.
- Develop and maintain XSIAM analytics leveraging XQL (Extended Query Language) to extract actionable insights from security telemetry.
- Map detection content to MITRE ATT&CK framework, ensuring coverage across all relevant tactics, techniques, and procedures (TTPs).
- Configure AI SmartScoring and technique-based incident grouping to reduce alert fatigue and prioritize analyst workload effectively.
- Design, build, and maintain SOAR automation playbooks within XSIAM to automate triage, enrichment, and remediation workflows.
- Leverage Cortex Marketplace content packs and develop custom integrations as needed to support client-specific security processes.
- Implement dev/prod playbook lifecycle management to ensure safe testing and controlled promotion of automation content.
- Continuously improve automation coverage, targeting measurable reductions in manual analyst workload.
- Serve as escalation point for complex incident investigations, using XSIAM causality chains and full attack-story visualizations to support rapid remediation.
- Coordinate with client SOC teams during active incidents, leveraging XSIAM's embedded automation and enrichment capabilities.
- Support Attack Surface Management (ASM) functions to proactively identify and remediate client exposure.
- Utilize integrated Threat Intelligence Platform (TIP) capabilities, including Unit 42 threat feeds, to enrich alerts and inform response priorities.
- Serve as a trusted technical advisor to federal and commercial clients on XSIAM capabilities, roadmap, and SOC modernization strategy.
- Produce SOC performance dashboards, compliance reports, and executive summaries within XSIAM to support client governance requirements.
- Conduct training and knowledge transfer sessions to build client SOC team proficiency on the XSIAM platform.
- Support CIG business development efforts by contributing to proposals, demos, and technical capability briefings for prospective clients.
- 3+ years of hands-on experience with Palo Alto Networks Cortex XDR or Cortex XSIAM in an enterprise or federal environment.
- Demonstrated experience deploying or administering SIEM platforms (Splunk, Microsoft Sentinel, IBM QRadar, or equivalent).
- Proficiency with XQL or comparable query languages for log analysis and threat hunting.
- Working knowledge of SOAR concepts and experience building security automation playbooks.
- Understanding of EDR, NDR, and UEBA technologies and how they feed into a converged SOC platform.
- Familiarity with MITRE ATT&CK framework and its application to detection engineering.
- Active Secret clearance (minimum); TS/SCI preferred for federal engagements.
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field, OR equivalent professional experience.
- Palo Alto Networks Certified Security Automation Engineer (PCSAE) or Cortex XSIAM-specific certification.
- Experience with federal compliance frameworks including NIST SP 800-53, RMF, DISA STIGs, and CDM program requirements.
- Familiarity with Zero Trust Architecture principles (NIST SP 800-207, CISA ZT Maturity Model) and how XSIAM supports ZTA adoption.
- Experience integrating Cortex XSIAM with Palo Alto Networks NGFW, Prisma Cloud, or Zscaler platforms.
- Knowledge of cloud security telemetry sources (AWS, Azure, GCP) and their ingestion into XSIAM.
- Exposure to Python or JavaScript for custom XSIAM integration development or automation scripting.
- Prior experience supporting federal SOC operations or DHS CDM program environments.
- CISSP, CEH, CompTIA Security+, or equivalent security certification.
SOC Platforms
- Cortex XSIAM / XDR
- Cortex XSOAR
- SIEM platforms
- XQL query language
- EDR / NDR / UEBA
- MITRE ATT&CK
- NIST SP 800-53 / RMF
- NIST SP 800-207 (Zero Trust Architecture)
- CISA Zero Trust Maturity Model
- DISA STIGs
- Palo Alto NGFW / Prisma
- Zscaler ZIA / ZPA
- Microsoft Sentinel / Azure
- ServiceNow / Ticketing systems
- AWS / Azure / GCP
Flexible work from home options available.
Vacancy posted more than 2 months ago
Similar jobs that could be interesting for youBased on the Cortex XSIAM Security Engineer in Washington DC vacancy
$107.93k - $188.9k
...s Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across... ...with at least one of the following: Splunk, Palo Alto XSIAM, or Crowdstrike NG SIEMSecurity certification such as...SuggestedRemote work$107.93k - $188.9k
...s Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across... ...with at least one of the following: Splunk, Palo Alto XSIAM, or Crowdstrike NG SIEM ~ Security certification such as...SuggestedRemote work- ...Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology across the US... ...OverviewThe SentinelOne Endpoint Security Engineer is responsible for the administration,... ...Microsoft Sentinel, Splunk, IBM QRadar, and Cortex XSOAR.]Core ResponsibilitiesStrategic...SuggestedMonday to Friday
- ...Senior Security Engineer Evolver Federal is seeking a Senior Security Engineer to fulfill a requirement for a potential government client... ...reporting Hands-on experience with SIEM (Splunk, Elastic), SOAR (Cortex XSOAR), and EDR (CrowdStrike, Microsoft Defender)....SuggestedContract workFlexible hours
$178.4k - $226.7k
AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...SuggestedInternshipRemote workFlexible hours$178.4k - $226.7k
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience... ...Services. Apart from work, we provide opportunities for our engineers to pursue projects they are passionate about while maintaining...InternshipFlexible hours$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats...InternshipFlexible hours$100k - $110k
...enterprise software architectures that support the bank’s information security operations functions. This role performs feedback and... ...bank. The position serves as a technical resource for security engineering initiatives, applying advanced knowledge to evaluate, build, and...Temporary workRemote workFlexible hours$136k - $184k
Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering undetected threat activities at petabyte scale. In this role, you will work alongside other Threat Hunting engineers to proactively...InternshipFlexible hoursShift work- ...business development efforts for upcoming opportunities with the U.S. Department of State’s Bureau of Diplomatic Security (DS) - Training - Technical Security Engineering. The Advisor will play a critical role in refining our understanding of the client landscape, validating...Contract workWork at office
$230k - $385k
...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are... ...customers in the public sector. As a Forward Deployed Security Engineer (FDSecE) you will be responsible for securing these novel applications...Work at officeLocal areaRemote workRelocation packageFlexible hours- ...Responsibilities The U.S. Cybersecurity and Infrastructure Security (CISA) mission is to lead the national effort to protect and enhance... ...as well as its MEOs. This task order is to provide Enterprise Engineering and Operations Support Services (EEOSS) to CISA/OCIO to...Full timeNight shift
$123k - $126k
Job DescriptionEverforth ECS Federal is seeking a Mid-Level Endpoint Security Engineer to support a mission-focused federal cybersecurity program in Washington DC.Please Note: This position is contingent upon contract award.Salary Range: $123,000 - $126,000Join Everforth...Contract work$120k - $130k
Job DescriptionEverforth ECS is seeking an Identity Security Engineer to work in our Washington, DC office / remote. The role is contingent upon additional funding.We are seeking a technically experienced Identity Security Engineer to join our security operations division...Work at officeRemote work$5,000 per month
...Candidates who are not U.S. citizens are not eligible for this role. Imagine One Technology & Management, Ltd. is seeking two (2) Security Engineers. This position is contingent upon award of the associated work and will be performed in Dahlgren, Virginia.The Security...Work at office- ...Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most complex technology... ...and New Zealand market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure capacity to deliver...Full timeLocal area
$159.3k - $202.4k
Amazon Security is seeking a Security Engineer who thrives in ambiguity and is motivated to build scalable security solutions. The Secure Third Party Tools (S3T) team has bold ambitions to redefine how Amazon protects customer trust across all third-party interactions —...InternshipWorldwideAll shiftsFlexible hours- ...project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have... ...Washington, DCJob DescriptionThe Identity and Authentication Security Engineer/Admin will be responsible for technical support to security...Remote work
- ...Reporting to the Program Manager, the Web Developer Embeds security across the SDLC for mission-critical web apps, APIs, and sensitive... ...~ Log analysis, FIM, WAF management ~3+ Web AppSec / AppSec Engineering / SSDLC ~ Modern web tech incl. .NET (C# MVC, WCF), HTML5,...Full time
- ...teams support the federal government’s most critical national security and defense priorities, helping protect the nation, strengthen... ...mission begins. Ardent is seeking a Web Developer Security Engineer to join our team. This position is based in Washington, DC...Full timeLocal areaRemote workFlexible hours
$165k - $215k
...and problem solvers to help us create it. Who you are Metropolis is seeking a highly technical, developer-oriented Senior Security Engineer to focus on securing our software engineering and product environments across web applications, mobile applications, APIs, AI/...Temporary workWork at officeLocal area- ...MANTECH seeks a motivated, career and customer-oriented Information System Security Engineer (ISSE) to join our team in Washington, D.C., Chantilly, VA, Quantico, VA, or Huntsville, AL. Responsibilities include, but are not limited to: Identify information...Work at office
$107.9k - $195.05k
Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires... ...tenant, particularly in a federal agency context. This senior engineering role sits at the center of the organization’s device, identity...Full timeNight shift$221.2k - $387.1k
...It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy... ...people. Job Description About SSO The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions...Permanent employmentFull timeWork at officeImmediate startRemote workFlexible hoursShift work$168k - $198k
...from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. Our prevention-first approach safeguards... ...What you bring to the table ~5+ years of engineering and pre-sales experience ~ Possess strong analytical and problem...Full timeTemporary workWorldwide$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you’ll collaborate with...Work at officeRemote work$75k - $80k
...Job Description Job Description Cloud Network Security Engineer Bethesda, MD Must be a US Citizen, able to obtain Public Trust Clearance @Orchard LLC is searching for a driven and dynamic Security Engineer to join our growing team . This position is based...Flexible hours- ...contractor that provides services and solutions in: National Security Programs Professional, Administrative, and Management... ...Time Position Status: Contingent Position Title: Security Engineer (Mobile) Location:Arlington, VA Security Clearance:Secret...Full timeFor contractors
$237.6k - $297k
...Security Engineer, Detection & Response We are seeking a Senior Security Engineer with a specialty in Detection and Incident Response to join our Security Engineering team. This role sits at the intersection of security operations and software engineering — you won'...Full time$140k - $190k
...Security Engineer As a Security Engineer at Method Security, you will be instrumental in expanding the capabilities of our product, designing tools and workflows that enhance the AI-driven defenses our platform offers. This role requires a unique blend of security engineering...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cortex XSIAM Security Engineer. Be the first to apply!
Related searches
- offensive security engineer Washington DC
- cloud security engineer Washington DC
- IT security engineer Washington DC
- information technology security engineer Washington DC
- security engineer Washington DC
- senior application security engineer Washington DC
- sr information security engineer Washington DC
- sr security engineer Washington DC
- security software engineer Washington DC
- physical security engineer Washington DC




