Senior Cyber Security Engineer

Embedded Shishya

Deutschland

Vor Ort

EUR 121.000 - 164.000

Vollzeit

Vor 10 Tagen

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Embedded Shishya seeks a Senior Cyber Security Engineer to drive detection, response, and automation across a modern security stack. You will design, implement, and optimize Cortex XSIAM to deliver high-fidelity detections and rapid incident response in a hands-on leadership role.

You will collaborate with SOC analysts and engineers, translate adversary techniques into detections aligned to MITRE ATT&CK, and mentor teammates while expanding expertise in XSIAM, XQL, and security analytics across

Qualifikationen

  • Minimum 5+ years in Security Operations, Detection Engineering, or SIEM/SOAR engineering.
  • Hands-on with Cortex XSIAM (or strong XDR/XSOAR with XSIAM ramp-up).
  • Strong knowledge of SIEM/XDR concepts, log analytics, incident response, and automation.
  • Proficiency in XQL, KQL, SPL or similar query languages.
  • Experience integrating data from endpoint, network, cloud, and identity platforms.
  • Scripting experience (Python preferred).
  • Enterprise-scale security platform operations experience.
  • Familiarity with MITRE ATT&CK and threat intelligence frameworks.
  • Experience supporting a 24/7 SOC or global security operations.
  • Bachelor’s degree; certifications preferred.

Aufgaben

  • Design, deploy, and maintain Cortex XSIAM detections, correlations, and analytics across data sources.
  • Develop and maintain custom detections using XQL; conduct threat hunting and investigations.
  • Design and maintain automated response playbooks; integrate XSIAM with enterprise tooling.
  • Collaborate with SOC analysts and engineers; mentor teammates; drive post-go-live enhancements.

Kenntnisse

Security Operations
Detection Engineering
SIEM/SOAR
XSIAM
Python scripting
Threat hunting
MITRE ATT&CK
Data integration
XQL/KQL/SPL
Enterprise-scale

Ausbildung

Bachelor’s degree in Computer Science or related

Tools

Palo Alto Cortex XSIAM
Cortex XDR
Defender/CrowdStrike
AWS/Azure/GCP telemetry

Jobbeschreibung

Senior Cyber Security Engineer

Wilmington, DE

Monday – Friday 8:00 – 5:00 ET

Hybrid/Remote

We are seeking a Senior Cyber Security Engineer to play a pivotal role in advancing our detection, response, and automation capabilities across a modern enterprise security stack. In this role, you will serve as a hands-on technical leader responsible for designing, engineering, and optimizing Cortex XSIAM to deliver high-fidelity detections, scalable automation, and rapid incident response. You will work with rich telemetry spanning endpoint, network, cloud, and identity data to turn adversary behavior into actionable analytics that measurably reduce risk.

This position is ideal for an experienced detection or security operations engineer who thrives at the intersection of platform engineering and threat expertise. You will collaborate closely with SOC analysts, incident responders, and fellow engineers, influence detection strategy, and mentor others while working on creative solutions that matter at enterprise scale. You’ll have the opportunity to shape how security operations evolves, driving improvements in signal quality, automation maturity, and mean time to respond, while continuously expanding your technical depth in XSIAM, XQL, and advanced security analytics.

Some of the things you’ll be doing:

  • Platform Engineering: Design, deploy, and maintain Cortex XSIAM detections, correlations, and analytics across endpoint, network, cloud, and identity data sources. Build and tune detection logic to reduce noise while improving true positive rates. Perform ongoing platform optimization, including ingest management, rule tuning, and performance improvements.
  • Detection Engineering & Threat Hunting: Develop and maintain custom detections using XQL (Cortex Query Language). Conduct proactive threat hunting and investigations using XSIAM analytics and telemetry. Translate threat intelligence and adversary techniques into actionable detections aligned to MITRE ATT&CK.
  • Automation & Response: Design and maintain automated response playbooks to accelerate incident containment and remediation. Integrate XSIAM with enterprise tooling (e.g., identity, EDR, ticketing, cloud, network security platforms). Support continuous improvement of MTTR through automation and orchestration.
  • Operations & Collaboration: Partner with SOC analysts, incident responders, and engineering teams on investigations and response activities. Support post-go-live enhancements, backlog grooming, and technical debt reduction initiatives. Provide technical guidance and mentorship to engineers and analysts.

What technical skills, experience and qualifications do you need?

  • Minimum 5+ years of experience in Security Operations, Detection Engineering, or SIEM/SOAR engineering
  • Hands-on experience with Palo Alto Networks Cortex XSIAM (or strong XDR/XSOAR experience with rapid XSIAM ramp-up)
  • Strong working knowledge of SIEM/XDR concepts and log analytics, incident response and threat detection workflows, and automation and orchestration use cases
  • Proficiency with XQL, KQL, SPL, or similar security query languages
  • Experience integrating data from endpoint, network, cloud, and identity platforms
  • Strong scripting experience (Python preferred)
  • Experience operating security platforms at enterprise scale
  • Preferred experience with endpoint security (Cortex XDR, Defender, CrowdStrike, etc.), cloud security telemetry (AWS, Azure, GCP), identity and access logs (AD, Azure AD, IAM)
  • Familiarity with MITRE ATT&CK and threat intelligence frameworks
  • Experience supporting a 24/7 SOC or global security operations team
  • Bachelor’s degree in computer science, information assurance, MIS or equivalent industry experience.
  • Palo Alto Networks Certified XSIAM Engineer or Analyst certification preferred.
  • Additional industry certifications are a plus (i.e., CEH, CISM, etc.)

#CSC #CSCCareers

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Cybersecurity Operations – Incident Response Lead
Cybersecurity Operations – Incident Response Lead

Jobtailor • Deutschland

Hybrid
EUR 90.000 - 130.000
Hybrid work model
Systems Engineer - SOC
Systems Engineer - SOC

Grohe • Deutschland

Vor Ort
EUR 60.000 - 90.000
Senior Information Security Operations Center Analyst
Senior Information Security Operations Center Analyst

Jobtailor • Deutschland

Remote
EUR 70.000 - 95.000
IT Security Analyst – Level 1
IT Security Analyst – Level 1

Jobtailor • Deutschland

Hybrid
EUR 45.000 - 65.000
Cybersecurity Incident Response Engineer
Cybersecurity Incident Response Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Cortex Cloud Sales Specialist
Cortex Cloud Sales Specialist

Jobtailor • Deutschland

Remote
EUR 120.000 - 180.000
Offensive Security Analyst
Offensive Security Analyst

Sonoco • Hub

Vor Ort
EUR 60.000 - 85.000
IS Principal Security Architect
IS Principal Security Architect

Jobtailor • Deutschland

Hybrid
EUR 130.000 - 190.000
Principal Consultant - SIEM | Remote, CAN
Principal Consultant - SIEM | Remote, CAN

Optiv • Deutschland

Hybrid
EUR 110.000 - 150.000
Work-life balance
Training resources
Creative problem solving
+2
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Riederich

Vor Ort
EUR 75.000 - 110.000