Cortex XSIAM Security Engineer
CELESTIAL INNOVATIONS GROUP LLC
Benefits:
401(k)
Competitive salary
Dental insurance
Health insurance
Paid time off
Vision insurance
Position Summary Celestial Innovations Group (CIG) is seeking a skilled Cortex XSIAM Security Engineer to deploy, configure, and operationalize Palo Alto Networks Cortex XSIAM for federal and enterprise clients. This role is at the center of CIG's AI-driven Security Operations practice, enabling clients to modernize their SOC by consolidating SIEM, XDR, SOAR, UEBA, ASM, and TIP capabilities into a single, converged platform.
The Cortex XSIAM Engineer will serve as a subject-matter expert (SME) throughout the full platform lifecycle: from requirements gathering and architecture design through deployment, integration, and continuous optimization — driving measurable improvements in threat detection and incident response times for our government and commercial clients.
Key Responsibilities
Platform Deployment & Integration
Lead end-to-end deployment of Cortex XSIAM for federal and enterprise clients, including data source onboarding, log ingestion, and normalization.
Integrate XSIAM with existing security ecosystem tools including firewalls, endpoints, cloud platforms, identity providers, and ticketing systems.
Configure data pipelines to ingest and normalize telemetry from diverse sources (endpoints, network, cloud, identity) into XSIAM's unified data model.
Migrate clients from legacy SIEM platforms to Cortex XSIAM, ensuring continuity of detection coverage and compliance reporting.
Detection Engineering & Analytics
Build and tune correlation rules, behavioral analytics, and ML-based detection models within XSIAM to reduce false positive rates and improve detection fidelity.
Develop and maintain XSIAM analytics leveraging XQL (Extended Query Language) to extract actionable insights from security telemetry.
Map detection content to MITRE ATT&CK framework, ensuring coverage across all relevant tactics, techniques, and procedures (TTPs).
Configure AI SmartScoring and technique-based incident grouping to reduce alert fatigue and prioritize analyst workload effectively.
Automation & Playbook Development
Design, build, and maintain SOAR automation playbooks within XSIAM to automate triage, enrichment, and remediation workflows.
Leverage Cortex Marketplace content packs and develop custom integrations as needed to support client-specific security processes.
Implement dev/prod playbook lifecycle management to ensure safe testing and controlled promotion of automation content.
Continuously improve automation coverage, targeting measurable reductions in manual analyst workload.
Incident Response & Threat Management
Serve as escalation point for complex incident investigations, using XSIAM causality chains and full attack-story visualizations to support rapid remediation.
Coordinate with client SOC teams during active incidents, leveraging XSIAM's embedded automation and enrichment capabilities.
Support Attack Surface Management (ASM) functions to proactively identify and remediate client exposure.
Utilize integrated Threat Intelligence Platform (TIP) capabilities, including Unit 42 threat feeds, to enrich alerts and inform response priorities.
Client Engagement & Advisory
Serve as a trusted technical advisor to federal and commercial clients on XSIAM capabilities, roadmap, and SOC modernization strategy.
Produce SOC performance dashboards, compliance reports, and executive summaries within XSIAM to support client governance requirements.
Conduct training and knowledge transfer sessions to build client SOC team proficiency on the XSIAM platform.
Support CIG business development efforts by contributing to proposals, demos, and technical capability briefings for prospective clients.
Required Qualifications
3+ years of hands-on experience with Palo Alto Networks Cortex XDR or Cortex XSIAM in an enterprise or federal environment.
Demonstrated experience deploying or administering SIEM platforms (Splunk, Microsoft Sentinel, IBM QRadar, or equivalent).
Proficiency with XQL or comparable query languages for log analysis and threat hunting.
Working knowledge of SOAR concepts and experience building security automation playbooks.
Understanding of EDR, NDR, and UEBA technologies and how they feed into a converged SOC platform.
Familiarity with MITRE ATT&CK framework and its application to detection engineering.
Active Secret clearance (minimum); TS/SCI preferred for federal engagements.
Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field, OR equivalent professional experience.
Preferred Qualifications
Palo Alto Networks Certified Security Automation Engineer (PCSAE) or Cortex XSIAM-specific certification.
Experience with federal compliance frameworks including NIST SP 800-53, RMF, DISA STIGs, and CDM program requirements.
Familiarity with Zero Trust Architecture principles (NIST SP 800-207, CISA ZT Maturity Model) and how XSIAM supports ZTA adoption.
Experience integrating Cortex XSIAM with Palo Alto Networks NGFW, Prisma Cloud, or Zscaler platforms.
Knowledge of cloud security telemetry sources (AWS, Azure, GCP) and their ingestion into XSIAM.
Exposure to Python or JavaScript for custom XSIAM integration development or automation scripting.
Prior experience supporting federal SOC operations or DHS CDM program environments.
CISSP, CEH, CompTIA Security+, or equivalent security certification.
Technical Skills & Tools
SOC Platforms
Cortex XSIAM / XDR
Cortex XSOAR
SIEM platforms
XQL query language
EDR / NDR / UEBA
Security Frameworks
MITRE ATT&CK
NIST SP 800-53 / RMF
NIST SP 800-207 (Zero Trust Architecture)
CISA Zero Trust Maturity Model
DISA STIGs
Integrations & Tools
Palo Alto NGFW / Prisma
Zscaler ZIA / ZPA
Microsoft Sentinel / Azure
ServiceNow / Ticketing systems
AWS / Azure / GCP
Flexible work from home options available.
$130k - $153.9k
...digital business and a more secure world, visit stratascale.com.... ...The Security Consultant - Engineering provides subject matter expertise... ...but not limited to, Palo Alto XSIAM Proactively identify... ...platforms, especially Palo Alto Cortex XSOAR and XSIAM. ~ Understanding...SuggestedWork experience placementRemote workHome officeFlexible hours- ...Evolver Federal is seeking a Senior Security Engineer to fulfill a requirement for a potential government client. The Senior Security Engineer... ...Hands-on experience with SIEM (Splunk, Elastic), SOAR (Cortex XSOAR), and EDR (CrowdStrike, Microsoft Defender). Expertise...SuggestedContract workFlexible hours
- ...business development efforts for upcoming opportunities with the U.S. Department of State's Bureau of Diplomatic Security (DS) - Training - Technical Security Engineering. The Advisor will play a critical role in refining our understanding of the client landscape, validating...SuggestedContract workWork at office
$186k - $255k
...Career We are seeking a Network Security Architect to manage and lead various... ...Act as a key consultant to our Sales Engineering and Learning & Enablement organizations... ...understanding of Palo Alto Cortex Platform: XDR, XSIAM, XSOAR and Cloud Experience in Python...SuggestedRemote workVisa sponsorshipWork visa$100k - $150k
...recommendations. These agents help businesses streamline operations, improve decision-making, and also empower government entities to enhance security, intelligence, and operational efficiency Position Description: This position is responsible for integrating Accrete...SuggestedWork experience placementWork at officeRemote workFlexible hours- ...Identity And Authentication Security Engineer Comtech is a woman-owned small business founded in 1998 and headquartered in Reston, VA. We offer IT solutions across the disciplines of program/project management, applications development, infrastructure, Cyber security...Remote work
$180k - $200k
.... If we’ve described you and your dream workplace, please apply and share in the many benefits and opportunities we offer. Security Engineer III Responsibilities: Leads enterprise security modernization initiatives. Defines Zero Trust-aligned architectures (...For contractors- ...Full-Time/Part-Time Full-Time Description RiVidium is seeking a Security Engineer (ISSE) to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data Operations - Core Operations...Full timeContract workPart time
$91k - $169k
...WAF Perimeter Security Engineer When we say, "the stuff dreams are made of," we're not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. Behind WBD's vast portfolio of iconic content and beloved brands, are the...Temporary workWork at officeLocal area- ...Security Engineer Detection & Response Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI's technology, people, and products. We are technical in what we build...
$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you'll collaborate with...Work at officeRemote work- ...Security Engineer Location: Washington, D.C (On-site M-F at JBAB) Duration: Full Time Clearance: Security Clearance: TS/SCI + required and able to receive their PSD/Yankee White, or Active Yankee White Clearance Company Description Our...Full time
- ...Security Engineer Washington, DC Type: Contract-to-Hire Category: Security Industry: Government Reference ID: JN -052026-106816 Date Posted: 05/07/2026 Shortcut: Description Recommended Jobs Description: Onsite in Washington, DC...Hourly payPermanent employmentContract workLocal area
$99k - $225k
...Virtru Security Engineer The Opportunity: As a Virtru Security Engineer you'll play a critical role in the world of zero t rus t. You will support the cyber architecture development, implementation, and sustainment across multiple networks of different classification...Full timeContract workPart timeWork at officeLocal areaRemote work- ...Everforth ECS Federal is seeking a Mid-Level Endpoint Security Engineer to support a mission-focused federal cybersecurity program in Washington DC. Please Note: This position is contingent upon contract award. Join Everforth ECS Federal to grow your endpoint...Contract work
- ...Threat Detection Security Engineer Job Description Overview CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100,...Full timeWork at officeWork from homeMonday to Thursday
$52 - $58 per hour
...Replies within 24 hours Job Description: Short Description: The Endpoint Engineer/Administrator shall assist with implementing and operating Endpoint Security infrastructure to protect the DCGOV IT infrastructure. The position is in the Citywide. Complete...Hourly payPermanent employment- ...OT Security Engineer 4032 | TS/SCI Job Description: An exciting DHS Customer is on contract to provide division-wide support for Federal Information Security Modernization Act (FISMA) compliance, execution of the Risk Management Framework (RMF) process to achieve...Contract workWork at office
- ...Security Engineer We are looking for a Security Engineer to join our team on an effort supporting our Federal Government Client in Washington, D.C. Position Overview: Top Secret Clearance is required. Create security guides (i.e. Educational material and step by step...
$98k - $163k
...Job Family: IT Cyber Security Travel Required: Up to 10% Clearance Required: Active Public Trust What You Will Do: Lead the design, deployment, and maintenance of Trellix security architecture. Monitor, analyze, and respond to security...Temporary workFlexible hours- ...Forbes Next Billion-Dollar Startups 2024," and Y Combinator's #1 GovTech startup. About the Role We're hiring a Founding Security Engineer to be our first dedicated security generalist who operates across the full security surface area - writing detection rules,...Permanent employmentFull timeWork at officeLocal areaFlexible hours
- ...Security Engineer - Zscaler ID 2026-9435 Type Full Time W/Benefits Ret Match Location : Location US-VA-Arlington Security Clearance DHS Suitability Overview/ Job Responsibilities The U.S. Cybersecurity and Infrastructure...Full timeNight shift
$63 - $70 per hour
...Security Engineer Tech Tammina LLC Job Description Hi, Trying to reach you.. I just came across your resume and want to see if you may be interested in the below job opportunity. If you are comfortable, please reply with your updated resume and contact details...Hourly payContract workRelocationWork visa- ...Identity And Authentication Security Engineer The Identity and Authentication Security Engineer/Admin will be responsible for technical support to security technologies supporting implementation and evolution and operations of the multi-layer authentication infrastructure...Work at officeRemote workNight shift
$175k - $195k
...Jito Security Engineer Jito builds the Market Layer of Solana: the execution systems, capital markets, and incentive mechanisms that power real markets on-chain. Our products process billions in daily transaction value. The Jito-Solana validator client runs on the vast...$114.39k - $240.35k
...information systems. The position provides certified and licensed security support to ensure systems meet FAA, federal, and NIST security... ...cycle. Position Summary The Information Systems Security Engineer/Analyst provides security engineering, analysis, and compliance...Full timeContract workPart timeLocal areaRemote work- About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity... ...customers in the public sector. As a Forward Deployed Security Engineer (FDSecE) you will be responsible for securing these novel...Work at officeRemote workRelocation package
$120k - $155k
...Responsibilities & Qualifications We are seeking a Lead – Security Engineer to join our team supporting the Transportation Team . REQUIRED QUALIFICATIONS Experience: ~8–10 years in cybersecurity ops with federal experience. ~ Demonstrated experience supporting...Full timeContract workTemporary workWork at officeLocal areaMonday to FridayWeekend workDay shiftAfternoon shift- ...A technology solutions provider is seeking an Identity and Authentication Security Engineer to support the implementation and operations of a multi-layer authentication infrastructure. You will manage security technologies, provide Tier 3 support, and troubleshoot complex...
$152.41k - $179.3k
...foster collaboration, connection, and alignment. Attendance is expected and fully supported. Coinbase Corporate Security (CorpSec) is seeking a Security Engineer to design, implement, and automate security solutions that protect corporate infrastructure, user devices,...Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cortex XSIAM Security Engineer. Be the first to apply!
- endpoint security engineer Washington DC
- senior cloud security engineer Washington DC
- security infrastructure engineer Washington DC
- security engineering manager Washington DC
- sr security engineer Washington DC
- senior security operations engineer Washington DC
- systems security engineer Washington DC
- security operations engineer Washington DC
- cloud security engineer Washington DC
- dlp security engineer Washington DC

