Cyber Palo Alto Networks Security Operations Senior Consultant
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
The team
Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.
Work You’ll Do
- Lead the design and deployment of Next-Generation SOC platforms, like Cortex XSIAM, including advanced detection rules and SOAR playbooks, and SIEM ingestion.
- Integrate diverse log and telemetry sources, ensuring data quality and normalization.
- Develop and optimize automated response workflows for incident containment and remediation.
- Advise clients on advanced use cases, threat detection, and automation strategies.
- Collaborate with cross-functional teams for solution enhancements and threat intelligence integration.
- Present technical findings and recommendations to stakeholders.
Required Qualifications
- BA/BS degree in a technical field (e.g., Computer Science, Cyber Security)
- 4-6 years of progressively responsible experience in cloud, network, or identity security domains, demonstrating increasing levels of responsibility, technical depth, and leadership over time
- 3-4 years of experience with Security Operations tools and platforms including Cortex XSIAM, Cortex XDR, Splunk, or similar SIEM technologies
- 3-4 years of Security Operations Center experience demonstrating expertise in detection engineering, automation and playbook development, or SOC maturity methodologies
- 3-4 years of experience with one or more cloud service providers (AWS, GCP, Azure) and native security tools
- 3-4 years of experience with management of log sources, data normalization, ingestion and manipulation of data
- 3-4 years of experience working with detection and response platforms (EDR) like Microsoft Defender, Cortex XDR, CrowdStrike
- 3-4 years of experience with governance, risk, or compliance initiatives involving common frameworks
- Certifications including Palo Alto Networks’ PCNSE or Certified Cybersecurity Associate or equivalent and/or similar cybersecurity certifications
- Ability to travel up to 50%, on average, based on the work you perform and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available
Preferred Qualifications
- Experience with Palo Alto Networks’ platform of solutions including, but not limited to, next-generation firewalls, Cortex & Prisma Cloud, and Prisma Access, XDR, etc.
- Strong understanding of vendor competitive analysis within Security Operations (e.g., competitive differences between competing SIEM solutions)
- Proficiency with advanced scripting, playbook development within a SIEM, SOAR or Security platform
- Basic proficiency with network routing protocols (e.g., BGP, ECMP) and network architecture concepts (e.g., network segmentation), in support of on-premise and secure cloud infrastructure use cases
- Ability to communicate and advise on solution design based on client use-cases, requirements, or other success criteria
- Previous consulting or “Big 4” experience
- Relevant advanced cybersecurity or related network engineering certifications (e.g., CISSP, CEH, CCSP)
The wage range for this role is $102,500 - $188,900. You may also be eligible to participate in a discretionary annual incentive program.
Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html