Cortex XSIAM Security Engineer
CELESTIAL INNOVATIONS GROUP LLC
Benefits:
401(k)
Competitive salary
Dental insurance
Health insurance
Paid time off
Vision insurance
Position Summary Celestial Innovations Group (CIG) is seeking a skilled Cortex XSIAM Security Engineer to deploy, configure, and operationalize Palo Alto Networks Cortex XSIAM for federal and enterprise clients. This role is at the center of CIG's AI-driven Security Operations practice, enabling clients to modernize their SOC by consolidating SIEM, XDR, SOAR, UEBA, ASM, and TIP capabilities into a single, converged platform.
The Cortex XSIAM Engineer will serve as a subject-matter expert (SME) throughout the full platform lifecycle: from requirements gathering and architecture design through deployment, integration, and continuous optimization — driving measurable improvements in threat detection and incident response times for our government and commercial clients.
Key Responsibilities
Platform Deployment & Integration
Lead end-to-end deployment of Cortex XSIAM for federal and enterprise clients, including data source onboarding, log ingestion, and normalization.
Integrate XSIAM with existing security ecosystem tools including firewalls, endpoints, cloud platforms, identity providers, and ticketing systems.
Configure data pipelines to ingest and normalize telemetry from diverse sources (endpoints, network, cloud, identity) into XSIAM's unified data model.
Migrate clients from legacy SIEM platforms to Cortex XSIAM, ensuring continuity of detection coverage and compliance reporting.
Detection Engineering & Analytics
Build and tune correlation rules, behavioral analytics, and ML-based detection models within XSIAM to reduce false positive rates and improve detection fidelity.
Develop and maintain XSIAM analytics leveraging XQL (Extended Query Language) to extract actionable insights from security telemetry.
Map detection content to MITRE ATT&CK framework, ensuring coverage across all relevant tactics, techniques, and procedures (TTPs).
Configure AI SmartScoring and technique-based incident grouping to reduce alert fatigue and prioritize analyst workload effectively.
Automation & Playbook Development
Design, build, and maintain SOAR automation playbooks within XSIAM to automate triage, enrichment, and remediation workflows.
Leverage Cortex Marketplace content packs and develop custom integrations as needed to support client-specific security processes.
Implement dev/prod playbook lifecycle management to ensure safe testing and controlled promotion of automation content.
Continuously improve automation coverage, targeting measurable reductions in manual analyst workload.
Incident Response & Threat Management
Serve as escalation point for complex incident investigations, using XSIAM causality chains and full attack-story visualizations to support rapid remediation.
Coordinate with client SOC teams during active incidents, leveraging XSIAM's embedded automation and enrichment capabilities.
Support Attack Surface Management (ASM) functions to proactively identify and remediate client exposure.
Utilize integrated Threat Intelligence Platform (TIP) capabilities, including Unit 42 threat feeds, to enrich alerts and inform response priorities.
Client Engagement & Advisory
Serve as a trusted technical advisor to federal and commercial clients on XSIAM capabilities, roadmap, and SOC modernization strategy.
Produce SOC performance dashboards, compliance reports, and executive summaries within XSIAM to support client governance requirements.
Conduct training and knowledge transfer sessions to build client SOC team proficiency on the XSIAM platform.
Support CIG business development efforts by contributing to proposals, demos, and technical capability briefings for prospective clients.
Required Qualifications
3+ years of hands-on experience with Palo Alto Networks Cortex XDR or Cortex XSIAM in an enterprise or federal environment.
Demonstrated experience deploying or administering SIEM platforms (Splunk, Microsoft Sentinel, IBM QRadar, or equivalent).
Proficiency with XQL or comparable query languages for log analysis and threat hunting.
Working knowledge of SOAR concepts and experience building security automation playbooks.
Understanding of EDR, NDR, and UEBA technologies and how they feed into a converged SOC platform.
Familiarity with MITRE ATT&CK framework and its application to detection engineering.
Active Secret clearance (minimum); TS/SCI preferred for federal engagements.
Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field, OR equivalent professional experience.
Preferred Qualifications
Palo Alto Networks Certified Security Automation Engineer (PCSAE) or Cortex XSIAM-specific certification.
Experience with federal compliance frameworks including NIST SP 800-53, RMF, DISA STIGs, and CDM program requirements.
Familiarity with Zero Trust Architecture principles (NIST SP 800-207, CISA ZT Maturity Model) and how XSIAM supports ZTA adoption.
Experience integrating Cortex XSIAM with Palo Alto Networks NGFW, Prisma Cloud, or Zscaler platforms.
Knowledge of cloud security telemetry sources (AWS, Azure, GCP) and their ingestion into XSIAM.
Exposure to Python or JavaScript for custom XSIAM integration development or automation scripting.
Prior experience supporting federal SOC operations or DHS CDM program environments.
CISSP, CEH, CompTIA Security+, or equivalent security certification.
Technical Skills & Tools
SOC Platforms
Cortex XSIAM / XDR
Cortex XSOAR
SIEM platforms
XQL query language
EDR / NDR / UEBA
Security Frameworks
MITRE ATT&CK
NIST SP 800-53 / RMF
NIST SP 800-207 (Zero Trust Architecture)
CISA Zero Trust Maturity Model
DISA STIGs
Integrations & Tools
Palo Alto NGFW / Prisma
Zscaler ZIA / ZPA
Microsoft Sentinel / Azure
ServiceNow / Ticketing systems
AWS / Azure / GCP
Flexible work from home options available.
$130k - $153.9k
...digital business and a more secure world, visit stratascale.com.... ...SummaryThe Security Consultant - Engineering provides subject matter... ...knowledge of Palo Alto Networks XSIAM: Hands-on experience with XSIAM... ..., especially Palo Alto Cortex XSOAR and XSIAM.Understanding...SuggestedWork experience placementRemote workHome officeFlexible hours- ...Evolver Federal is seeking a Senior Security Engineer to fulfill a requirement for a potential government client. The Senior Security Engineer... ...Hands-on experience with SIEM (Splunk, Elastic), SOAR (Cortex XSOAR), and EDR (CrowdStrike, Microsoft Defender). Expertise...SuggestedContract workFlexible hours
$80k - $120k
...facilitate maintaining and enhancing the security posture of DOT information systems and... ...a must Experience with Palo Alto Cortex XDR / XSIAM Platforms is highly preferred... ...most complex modernization and systems engineering challenges across the defense, space,...Suggested$159.3k - $202.4k
...Amazon's Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering undetected threat activities at petabyte scale. In this role, you will work alongside other Threat Hunting engineers to proactively...SuggestedFlexible hoursShift work$237.6k - $297k
...Security Engineer, Product Security We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security...SuggestedFull time$136k - $184k
...At Amazon Healthcare Security, we are on a mission to make healthcare secure and easy. We are developing a patient-centric healthcare... ...personal, transparent, and convenient. We are looking for a Security Engineer to join our team. As a Security Engineer, your...Temporary workInternshipFlexible hours- ...business development efforts for upcoming opportunities with the U.S. Department of State's Bureau of Diplomatic Security (DS) - Training - Technical Security Engineering. The Advisor will play a critical role in refining our understanding of the client landscape, validating...Contract workWork at office
$159.3k - $202.4k
...Description Amazon Healthcare Security's (HealthSec) AI team is hiring a Security Engineer II to secure GenAI applications and enable secure AI adoption across Amazon Health Services (AHS). You will work at the intersection of AI for Security and Security for AI—securing...Flexible hours$178.4k - $226.7k
...Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience... ...Services. Apart from work, we provide opportunities for our engineers to pursue projects they are passionate about while maintaining...InternshipFlexible hours$99k - $225k
...Virtru Security Engineer The Opportunity: As a Virtru Security Engineer you'll play a critical role in the world of zero trust. You will support the cyber architecture development, implementation, and sustainment across multiple networks of different classification...Full timeContract workPart timeLocal areaRemote work$180k - $200k
.... If we've described you and your dream workplace, please apply and share in the many benefits and opportunities we offer. Security Engineer III Responsibilities: Leads enterprise security modernization initiatives. Defines Zero Trust-aligned architectures (...For contractors$40 per hour
...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback... ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some...Hourly payFull timePart timeRemote work- ...Description Employer: Amazon Development Center U.S., Inc. Position: Security Engineer III - AMZ25957.4 Location: Arlington, VA Multiple Positions Available: 1.Conduct comprehensive security review within the Secure Software Development Life Cycle (SDLC) for...
$197k - $266.8k
...developers have chosen Mapbox because of the platform’s flexibility, security and privacy compliance. Organizations use Mapbox applications,... ...What We Do Mapbox is looking for a Staff Cloud Security Engineer to join our Security & Compliance team. As a member of our...Remote work$120k - $155k
...Responsibilities & Qualifications We are seeking a Lead – Security Engineer to join our team supporting the Transportation Team . REQUIRED QUALIFICATIONS Experience: ~8–10 years in cybersecurity ops with federal experience. ~ Demonstrated experience supporting...Full timeContract workTemporary workWork at officeLocal areaMonday to FridayWeekend workDay shiftAfternoon shift- ...Security Engineer Tech tammina solutions Job Description The security engineering position provides support to a Security Operation Center of a federal agency. Ideal candidate will have comprehensive knowledge of Windows and UNIX-based system administration, network...
$100k - $130k
...Dedicated Security Engineer AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation. At AHEAD, we prioritize...Work experience placementWork at office$152.41k - $179.3k
...foster collaboration, connection, and alignment. Attendance is expected and fully supported. Coinbase Corporate Security (CorpSec) is seeking a Security Engineer to design, implement, and automate security solutions that protect corporate infrastructure, user devices,...Local area$140k - $190k
...Security Engineer As a Security Engineer at Method Security, you will be instrumental in expanding the capabilities of our product, designing tools and workflows that enhance the AI-driven defenses our platform offers. This role requires a unique blend of security engineering...- ...Identity And Authentication Security Engineer The Identity and Authentication Security Engineer/Admin will be responsible for technical support to security technologies supporting implementation and evolution and operations of the multi-layer authentication infrastructure...Work at officeRemote workNight shift
- ...Security Engineer Washington, DC Type: Contract-to-Hire Category: Security Industry: Government Reference ID: JN -052026-106816 Date Posted: 05/07/2026 Shortcut: Description Recommended Jobs Description: Onsite in Washington, DC...Hourly payPermanent employmentContract workLocal area
- ...responsibility seriously. We are an ambitious and committed team of engineers, AI specialists and customer-facing program managers. We are... ...an early member of this team, you'll be pivotal in building a secure foundation for our applications and cloud architecture. You...Local areaRemote workFlexible hours
$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you'll collaborate with...Work at officeRemote work- ...Threat Detection Security Engineer Job Description Overview CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100,...Full timeWork at officeWork from homeMonday to Thursday
$99k - $225k
...Job Number: R0231042 Virtru Security Engineer The Opportunity: As a Virtru Security Engineer you'll play a critical role in the world of zero trust. You will support the cyber architecture development, implementation, and sustainment across multiple networks of...Full timeContract workPart timeWork at officeLocal areaRemote work$52 - $58 per hour
...Replies within 24 hours Job Description: Short Description: The Endpoint Engineer/Administrator shall assist with implementing and operating Endpoint Security infrastructure to protect the DCGOV IT infrastructure. The position is in the Citywide. Complete...Hourly payPermanent employment- ...OT Security Engineer 4032 | TS/SCI Job Description: An exciting DHS Customer is on contract to provide division-wide support for Federal Information Security Modernization Act (FISMA) compliance, execution of the Risk Management Framework (RMF) process to achieve...Contract workWork at office
- ...Identity And Authentication Security Engineer Comtech is a woman-owned small business founded in 1998 and headquartered in Reston, VA. We offer IT solutions across the disciplines of program/project management, applications development, infrastructure, Cyber security...Remote work
$114.39k - $240.35k
...information systems. The position provides certified and licensed security support to ensure systems meet FAA, federal, and NIST security... ...cycle. Position Summary The Information Systems Security Engineer/Analyst provides security engineering, analysis, and compliance...Full timeContract workPart timeLocal areaRemote work- ...Security Engineer We are seeking a highly skilled Security Engineer with strong DevOps experience and an active U.S. Government security clearance to support and secure cloud environments across AWS GovCloud, Azure Government, and DoD environments. The ideal candidate...Contract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cortex XSIAM Security Engineer. Be the first to apply!
- information system security engineer Washington DC
- staff security engineer Washington DC
- senior application security engineer Washington DC
- sr information security engineer Washington DC
- security engineering manager Washington DC
- security operations engineer Washington DC
- cloud security engineer Washington DC
- endpoint security engineer Washington DC
- physical security engineer Washington DC
- systems security engineer Washington DC

