Senior Cyber Security Engineer

CSC

Wilmington (DE)

Hybrid

USD 100,000 - 130,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Annual leave
Tuition reimbursement
Referral bonuses
Success Sharing and bonuses

Job summary

CSC is seeking a Senior Cyber Security Engineer to advance detection and response capabilities across its security stack. The role involves engineering Cortex XSIAM, developing custom detections, and automating incident response processes. Candidates must have a minimum of 5 years' experience in Security Operations and hands-on knowledge of XSIAM. The position offers hybrid or remote work schedules, comprehensive benefits, including annual leave and tuition reimbursement, making it a great opportunity for seasoned professionals.

Qualifications

  • Minimum 5+ years of experience in Security Operations, Detection Engineering, or SIEM/SOAR engineering.
  • Hands-on experience with Palo Alto Networks Cortex XSIAM or rapid XSIAM ramp-up.
  • Strong working knowledge of SIEM/XDR concepts and log analytics.

Responsibilities

  • Design, deploy, and maintain Cortex XSIAM detections and analytics.
  • Develop and maintain custom detections using XQL.
  • Design and maintain automated response playbooks.

Skills

Security Operations
Detection Engineering
Palo Alto Networks Cortex XSIAM
XQL
Scripting in Python
Incident Response

Education

Bachelor’s degree in computer science or MIS

Tools

Cortex XSIAM
SIEM/XDR

Job description

Senior Cyber Security Engineer

We are seeking a Senior Cyber Security Engineer to play a pivotal role in advancing our detection, response, and automation capabilities across a modern enterprise security stack. In this role, you will serve as a hands‑on technical leader responsible for designing, engineering, and optimizing Cortex XSIAM to deliver high‑fidelity detections, scalable automation, and rapid incident response. You will work with rich telemetry spanning endpoint, network, cloud, and identity data to turn adversary behavior into actionable analytics that measurably reduce risk.

Responsibilities
  • Platform Engineering: Design, deploy, and maintain Cortex XSIAM detections, correlations, and analytics across endpoint, network, cloud, and identity data sources. Build and tune detection logic to reduce noise while improving true‑positive rates. Perform ongoing platform optimization, including ingest management, rule tuning, and performance improvements.
  • Detection Engineering & Threat Hunting: Develop and maintain custom detections using XQL. Conduct proactive threat hunting and investigations using XSIAM analytics and telemetry. Translate threat intelligence and adversary techniques into actionable detections aligned to MITRE ATT&CK.
  • Automation & Response: Design and maintain automated response playbooks to accelerate incident containment and remediation. Integrate XSIAM with enterprise tooling such as identity, EDR, ticketing, cloud, and network security platforms. Support continuous improvement of MTTR through automation and orchestration.
  • Operations & Collaboration: Partner with SOC analysts, incident responders, and engineering teams on investigations and response activities. Support post‑go‑live enhancements, backlog grooming, and technical debt reduction initiatives. Provide technical guidance and mentorship to engineers and analysts.
Qualifications
  • Minimum 5+ years of experience in Security Operations, Detection Engineering, or SIEM/SOAR engineering.
  • Hands‑on experience with Palo Alto Networks Cortex XSIAM (or strong XDR/XSOAR experience with rapid XSIAM ramp‑up).
  • Strong working knowledge of SIEM/XDR concepts and log analytics, incident response and threat detection workflows, and automation and orchestration use cases.
  • Proficiency with XQL, KQL, SPL, or similar security query languages.
  • Experience integrating data from endpoint, network, cloud, and identity platforms.
  • Strong scripting experience (Python preferred).
  • Experience operating security platforms at enterprise scale.
  • Preferred experience with endpoint security, cloud security telemetry, and identity and access logs.
  • Familiarity with MITRE ATT&CK and threat intelligence frameworks.
  • Experience supporting a 24/7 SOC or global security operations team.
  • Bachelor’s degree in computer science, information assurance, MIS or equivalent industry experience.
  • Palo Alto Networks Certified XSIAM Engineer or Analyst certification preferred.
  • Additional industry certifications are a plus (CEH, CISM, etc.).
Benefits
  • Hybrid or remote work schedules available.
  • Comprehensive benefits package that includes annual leave, tuition reimbursement, referral bonuses, and more.
  • Employees are eligible for Success Sharing, bonuses, or commission plans based on role and individual performance.

Disclaimer: The information above describes the general nature and level of work performed by employees in this role. It is not intended to describe all duties, responsibilities, and qualifications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cortex XSIAM Security Engineer
Cortex XSIAM Security Engineer

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 100,000 - 130,000
401(k)
Competitive salary
Dental insurance
+3
Senior Security Operations Platform Engineer
Senior Security Operations Platform Engineer

OtB Tech LLC • New York (NY)

Hybrid
USD 130,000 - 170,000
SIEM Engineer - Cortex
SIEM Engineer - Cortex

Trantor • United States

On-site
USD 120,000 - 180,000
Senior Cortex XSIAM Engineer — Detection & Automation
Senior Cortex XSIAM Engineer — Detection & Automation

CSC • Wilmington (DE)

Hybrid
USD 100,000 - 130,000
Sr. Technical Support Engineer (Cortex XSIAM)
Sr. Technical Support Engineer (Cortex XSIAM)

Palo Alto Networks • Plano (TX)

On-site
USD 103,000 - 167,000
Security Analyst / Engineer - Threat & Cortex XSIAM (Hybrid)
Security Analyst / Engineer - Threat & Cortex XSIAM (Hybrid)

WaveStrong, Inc. • Los Angeles (CA)

On-site
USD 100,000 - 120,000
Principal Consultant – SOC Transformation and XSIAM Deployment
Principal Consultant – SOC Transformation and XSIAM Deployment

Palo Alto Networks • California (MO)

Remote
USD 163,000 - 184,000
Senior Product Intelligence (Cortex XSIAM)
Senior Product Intelligence (Cortex XSIAM)

Palo Alto Networks • San Jose (CA)

Remote
USD 150,000 - 191,000
Competitive salary
Stock options
Flexible working arrangements
Principal Consultant – SOC Transformation and XSIAM Deployment
Principal Consultant – SOC Transformation and XSIAM Deployment

Palo Alto Networks • Chicago (IL)

On-site
USD 163,000 - 225,000
Cyber Threat Response Analyst
Cyber Threat Response Analyst

Centraprise • Cleveland (OH)

On-site
USD 85,000 - 115,000