Senior Cyber Security Engineer

Visa Hunt

United States

Hybrid

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Visa Hunt is seeking a Senior Cyber Security Engineer in Wilmington, DE with hybrid/remote work options. You will lead platform engineering for Cortex XSIAM, building detections across endpoint, network, cloud, and identity sources to reduce risk and noise.

You will translate threat intel into detections, develop automation, and mentor SOC teammates while scaling security analytics and mean time to respond in a fast-paced enterprise environment.

Qualifications

  • Minimum 5+ years in Security Operations, Detection Engineering, or SIEM/SOAR engineering.
  • Hands-on with Cortex XSIAM or strong XDR/XSOAR ramp-up experience.
  • Strong knowledge of SIEM/XDR, log analytics, and incident response workflows.
  • Proficiency with XQL, KQL, SPL, or similar query languages.
  • Experience integrating data from endpoint, network, cloud, and identity platforms.
  • Strong scripting experience (Python).
  • Experience in securing enterprise-scale environments.
  • Certifications in security (preferred).

Responsibilities

  • Design, deploy, and maintain Cortex XSIAM detections and analytics across data sources.
  • Develop and maintain custom detections using XQL; conduct threat hunting and investigations.
  • Design automated response playbooks to accelerate containment and remediation.
  • Collaborate with SOC analysts and engineers on investigations and response activities.

Skills

Security operations
Threat hunting
SIEM / SOAR
XQL / KQL / SPL
Python scripting
Data analytics
Enterprise-scale experience

Education

Bachelor’s degree in computer science or related field

Tools

Palo Alto Networks Cortex XSIAM
Palo Alto Networks Cortex XDR

Job description

Senior Cyber Security Engineer
Wilmington, DE
Monday – Friday 8:00 – 5:00 ET
Hybrid/Remote

We are seeking a Senior Cyber Security Engineer to play a pivotal role in advancing our detection, response, and automation capabilities across a modern enterprise security stack. In this role, you will serve as a hands-on technical leader responsible for designing, engineering, and optimizing Cortex XSIAM to deliver high-fidelity detections, scalable automation, and rapid incident response. You will work with rich telemetry spanning endpoint, network, cloud, and identity data to turn adversary behavior into actionable analytics that measurably reduce risk.

This position is ideal for an experienced detection or security operations engineer who thrives at the intersection of platform engineering and threat expertise. You will collaborate closely with SOC analysts, incident responders, and fellow engineers, influence detection strategy, and mentor others while working on creative solutions that matter at enterprise scale. You’ll have the opportunity to shape how security operations evolves, driving improvements in signal quality, automation maturity, and mean time to respond, while continuously expanding your technical depth in XSIAM, XQL, and advanced security analytics.

Some of the things you’ll be doing:
  • Platform Engineering: Design, deploy, and maintain Cortex XSIAM detections, correlations, and analytics across endpoint, network, cloud, and identity data sources. Build and tune detection logic to reduce noise while improving true positive rates. Perform ongoing platform optimization, including ingest management, rule tuning, and performance improvements.
  • Detection Engineering & Threat Hunting: Develop and maintain custom detections using XQL (Cortex Query Language). Conduct proactive threat hunting and investigations using XSIAM analytics and telemetry. Translate threat intelligence and adversary techniques into actionable detections aligned to MITRE ATT&CK.
  • Automation & Response: Design and maintain automated response playbooks to accelerate incident containment and remediation. Integrate XSIAM with enterprise tooling (e.g., identity, EDR, ticketing, cloud, network security platforms). Support continuous improvement of MTTR through automation and orchestration.
  • Operations & Collaboration: Partner with SOC analysts, incident responders, and engineering teams on investigations and response activities. Support post-go-live enhancements, backlog grooming, and technical debt reduction initiatives. Provide technical guidance and mentorship to engineers and analysts.

What technical skills, experience and qualifications do you need?

  • Minimum 5+ years of experience in Security Operations, Detection Engineering, or SIEM/SOAR engineering
  • Hands-on experience with Palo Alto Networks Cortex XSIAM (or strong XDR/XSOAR experience with rapid XSIAM ramp-up)
  • Strong working knowledge of SIEM/XDR concepts and log analytics, incident response and threat detection workflows, and automation and orchestration use cases
  • Proficiency with XQL, KQL, SPL, or similar security query languages
  • Experience integrating data from endpoint, network, cloud, and identity platforms
  • Strong scripting experience (Python preferred)
  • Experience operating security platforms at enterprise scale
  • Preferred experience with endpoint security (Cortex XDR, Defender, CrowdStrike, etc.), cloud security telemetry (AWS, Azure, GCP), identity and access logs (AD, Azure AD, IAM)
  • Familiarity with MITRE ATT&CK and threat intelligence frameworks
  • Experience supporting a 24/7 SOC or global security operations team
  • Bachelor’s degree in computer science, information assurance, MIS or equivalent industry experience.
  • Palo Alto Networks Certified XSIAM Engineer or Analyst certification preferred.
  • Additional industry certifications are a plus (i.e., CEH, CISM, etc.)
#CSC #CSCCareers

Originally posted on Himalayas

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Security Engineer
Senior Cyber Security Engineer

CSC • Wilmington (DE)

Hybrid
USD 100,000 - 130,000
Annual leave
Tuition reimbursement
Referral bonuses
+1
Cortex XSIAM Security Engineer
Cortex XSIAM Security Engineer

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 100,000 - 130,000
401(k)
Competitive salary
Dental insurance
+3
Senior Security Operations Platform Engineer
Senior Security Operations Platform Engineer

OtB Tech LLC • New York (NY)

Hybrid
USD 130,000 - 170,000
Security Analyst / Engineer - Threat & Cortex XSIAM (Hybrid)
Security Analyst / Engineer - Threat & Cortex XSIAM (Hybrid)

WaveStrong, Inc. • Los Angeles (CA)

On-site
USD 100,000 - 120,000
Senior Cortex XSIAM Detection & Automation Engineer
Senior Cortex XSIAM Detection & Automation Engineer

Visa Hunt • United States

Hybrid
USD 120,000 - 180,000
Principal Consultant – SOC Transformation and XSIAM Deployment
Principal Consultant – SOC Transformation and XSIAM Deployment

Palo Alto Networks • California (MO)

Remote
USD 163,000 - 184,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Senior Cyber Security Engineer - SIEM and Automation
Senior Cyber Security Engineer - SIEM and Automation

corebridgefinancial • Jersey City (NJ)

On-site
USD 168,000 - 195,000
Sr. Technical Support Engineer (Cortex XSIAM)
Sr. Technical Support Engineer (Cortex XSIAM)

Palo Alto Networks, Inc. • Plano (TX)

On-site
USD 103,000 - 167,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000