Palo Alto XSIAM Senior EngineerKey skills: Administration Management, Integration, Custom Parser Development Technical Skills: PA XSIAM Cortex SIEM, PA XSIAM Cortex SOAR, PA Cortex EDR/XDR, Threat Intelligence, Security Monitoring Incident Response, Threat Hunting, KnowbBe4/Darktrace Antigena/Phish ER/XSIAM, VM Detailed JD Well versed with PA XSIAM solution. Install/configure/build/fine tune the SIEM tools to set up an effective information security support / operation. Proactive monitoring of security alerts and events within the provided platform. Real time threat detection and analysis. Incident response planning and executing including containment, eradication, and recovery. Data enrichment and development of correlations to implement refined alerting and incident triggers. Develop and maintain real time custom dashboards, metrics, and operational reports directly from the tool Provide recommendations for new policies, profiles, and procedures as it relates to the platform. Creation of requests for new Indicators of Compromise (IOC) to be added to the platform. Provide system operational health monitoring. Proactive communication of security advisories and best practices. Weekly, monthly, quarterly, and annual reporting summarizing security events, incidents, and trends. Report on SLA performance and adherence to agree upon SLAs. Regularly scheduled meetings and communication channels are to be established to inform Client Appliances of timely events and incidents. Development of custom scripts and integrations including maintenance of integrations for already connected data sources. Continuously update content packs to the latest versions. Updates, maintenance, and support on the SIEM tool. Write parsing logic for various custom log sources, as requested. Rich experience in log source integration with SIEM solution Coordinates with the other Infra teams to implement SIEM Logs Source Integration Management of SIEM Infrastructure Ability to develop solution architecture design and implementation for SIEM projects Hands on knowledge of developing content/use cases/Correlation rules creation Proficiency in scripting languages (Python, PowerShell, Linux CLI). Strong understanding of network protocols, firewalls, and security architectures.
Experience in incident response and threat detection using SIEM tools. Ability to troubleshoot integration issues between SIEM and other security tools.
Experience working in Security Operations Center (SOC) Incident Management desirable. Triage incoming support requests, prioritizing and categorizing issues effectively Analyze phishing emails by investigating the email headers and body, including attachments and URLs Maintain detection rules, improve filtering effectiveness, and contribute to automation of phishing response workflows Management of phishing detection and response technologies deployed by Client Appliances including email security gateways, sandboxes, and other relevant technologies. Maintain and update SOP documentation relating to phishing technologies utilized within customer environment. Regular reporting on phishing activity, incidents, and trends. Proficiency in use of SIEM/SOAR security monitoring platforms At least 4 years of hands on involvement in incident investigations, phishing analysis, or threat intelligence operations Familiarity with email security tools and email protocols, phishing indicators, and social engineering tactics. Collaborate with respective IT infrastructure teams to ensure sensors are properly positioned within the network for comprehensive vulnerability scans. Conduct regular vul
Palo Alto XSIAM Senior Engineer Technical Architect in louisville at Unknown Company
This position is listed as full time and onsite.