XSIAM Resident Engineer
Riyadh, Riyadh Province, Saudi Arabia · Contract
Be the first to apply
- Experience
- 4+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
We are currently seeking a seasoned Senior XSIAM Consultant/Engineer to join a high-profile cybersecurity transformation initiative for top banking clients in Saudi Arabia. This position involves supporting the deployment, configuration, and improvement of Palo Alto Cortex XSIAM, a cutting-edge SOC-centric security platform.
Key Responsibilities
- Architect, implement, configure, and maintain Palo Alto Cortex XSIAM solutions within complex enterprise systems.
- Integrate security data and telemetry from endpoints, network devices, cloud services, identity management systems, and third-party security tools.
- Design and refine detection use cases, correlation rules, automation playbooks, and incident response workflows.
- Improve Security Operations Center (SOC) effectiveness through automation and orchestration techniques.
- Conduct security incident investigations, threat analysis, and support incident response efforts.
- Manage and sustain integrations with SIEM, SOAR, XDR, cloud platforms, and other security monitoring solutions.
- Develop dashboards, generate reports, and monitor operational security metrics for relevant stakeholders.
- Collaborate with security architects and engineers to establish and adopt best practice methodologies.
- Assist in security monitoring, threat hunting, and continuous enhancement initiatives.
- Produce comprehensive technical documentation, training materials, and operational procedures.
- Engage actively in security workshops, client meetings, and solution design sessions.
Required Experience & Skills
- At least 4 years of direct experience with Palo Alto Cortex XSIAM.
- Proven expertise working with Security Operations Centre (SOC) platforms.
- Familiarity with Cortex XDR, Cortex XSOAR, SIEM technologies, and threat analytics.
- Deep understanding of SOC workflows, incident response processes, threat hunting, security monitoring, and cyber threat intelligence.
- Experience integrating telemetry from endpoints, networks, identity systems, and cloud environments.
- Strong knowledge of security frameworks and industry best practices.
- Expertise developing security automation workflows and playbooks for orchestration.
- Excellent problem-solving abilities and troubleshooting skills.
- Effective communication and the capability to manage stakeholders across different teams.
Preferred Qualifications
- Background in banking or financial services sectors.
- Experience operating in strictly regulated environments.
- Familiarity with cloud security platforms such as AWS, Azure, or GCP.
- Knowledge of the MITRE ATT&CK framework.
- Proficiency in scripting and automation, including Python, PowerShell, and API integrations.
- Relevant Palo Alto Networks security certifications.
Technical Environment
- Palo Alto Cortex XSIAM
- Cortex XDR
- Cortex XSOAR
- SIEM and SOAR platforms
- XDR technologies
- Security analytics and threat intelligence tools
- Endpoint, network, and identity security systems
- Cloud security monitoring
- Security automation and orchestration frameworks
Candidate Profile
The ideal candidate is a practical cybersecurity expert experienced in modern SOC environments, adept in operating Palo Alto security tools such as XSIAM, XSOAR, XDR, SIEM, or SOAR within rapidly evolving enterprise settings that demand efficient threat detection, incident management, and automated security operations. While experience in the banking industry is advantageous, it is not essential. Priority will be given to candidates with substantial hands-on Cortex XSIAM expertise.
Industry
Management Consulting