Senior Security Operations Platform Engineer

OtB Tech LLC

New York (NY)

Hybrid

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A prominent tech company in New York is seeking a Senior Security Operations Platform Engineer to lead the migration of SIEM/SOAR capabilities to XSIAM. The role includes partnering with leadership on SOC improvements, developing incident response strategies, and mentoring staff on XSIAM operations. The ideal candidate should have over 10 years in SOC roles, experience in enterprise-scale migrations, and strong knowledge of SOC processes. This position operates in a hybrid model and requires substantial expertise in relevant tools.

Qualifications

  • 10+ years in SOC roles (analyst/engineer/architect/consultant).
  • Experience in enterprise-scale SIEM/SOAR migration.
  • Strong knowledge of SOAR playbook design and workflow automation.

Responsibilities

  • Partner with SOC leadership to ensure measurable improvements.
  • Lead migration of SIEM/SOAR capabilities to XSIAM.
  • Advise on next-gen SOC design across processes and technology.

Skills

XSIAM deployment operations
QRadar expertise
SOAR playbook design
MITRE ATT&CK-based detection engineering
SOC operations knowledge

Tools

XSIAM
QRadar
CP4S

Job description

Senior Security Operations Platform Engineer

Location: New York, NY 10004 (Hybrid)

Experience: 10+ years in SOC roles (analyst/engineer/architect/consultant).

Responsibilities: As Senior Security Operations Platform Engineer, you will partner with SOC leadership, engineering, and stakeholders to ensure the migration is not a tool swap, but a measurable uplift in detection, response, and operational maturity.

Key Responsibilities
  • SOC Process Transformation: Assess current triage, escalation, SLAs, and operating rhythms. Redesign workflows to align with XSIAM (correlation, automated triage, AI-driven prioritization).
  • Build/implement incident response playbooks and automation rules in XSIAM.
  • Define KPIs, metrics, and dashboards to improve SOC visibility and performance.
  • Platform Migration & Deployment: Lead end-to-end migration of SIEM/SOAR capabilities from QRadar/CP4S to XSIAM.
  • Inventory and translate CP4S playbooks/runbooks into XSIAM automations.
  • Establish content lifecycle management for multi-tenancy, tuning, and optimization.
  • Define common workflows (incident/shift management, automation development, knowledge management).
  • Ensure alert fidelity, data integrity, and coverage continuity through cutover.
  • Modern SOC Architecture & Advisory: Advise on next-gen SOC design across people, process, technology, and governance.
  • Close detection gaps using XSIAM’s unified data model, UEBA, threat intel, and attack surface management.
  • Recommend SOC structure (tiering), automation-first strategies, and response patterns.
  • Mentor/upskill staff on XSIAM operations, XQL, and platform-native automation.
  • Produce migration plans, technical designs, runbooks, and post-implementation reporting.
  • Provide regular updates on progress, risks, and recommendations to senior leadership.
  • Coordinate with Palo Alto professional services and internal engineering as needed.
Required Skills
  • Proven deployment/operations of XSIAM (or Cortex XDR/XSOAR in an XSIAM context).
  • QRadar expertise (rules, log sources/flows, reference sets, AQL).
  • CP4S SOAR/case management experience; ability to translate workflows cross-platform.
  • Participation in at least one enterprise-scale SIEM/SOAR migration.
  • SIEM normalization, onboarding, and field mapping.
  • SOAR playbook design and workflow automation.
  • MITRE ATT&CK–based detection engineering and gap analysis.
  • Telemetry across cloud, endpoint, network, and identity.
  • Strong SOC operations knowledge (triage, hunting, IR, shift handover, tuning/FP reduction, threat intel operationalization).
Preferred Skills
  • Palo Alto certs (PCCSA/PCNSA/XSIAM/XSOAR training).
  • Regulated industry experience (FSI, government, healthcare).
  • Purple team or detection-as-code background.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Security Engineer
Senior Cyber Security Engineer

CSC • Wilmington (DE)

Hybrid
USD 100,000 - 130,000
Annual leave
Tuition reimbursement
Referral bonuses
+1
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Visa Hunt • United States

Hybrid
USD 120,000 - 180,000
Cortex XSIAM Security Engineer
Cortex XSIAM Security Engineer

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 100,000 - 130,000
401(k)
Competitive salary
Dental insurance
+3
Principal Consultant – SOC Transformation and XSIAM Deployment
Principal Consultant – SOC Transformation and XSIAM Deployment

Palo Alto Networks • California (MO)

Remote
USD 163,000 - 184,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Sr. SOC Analyst
Sr. SOC Analyst

Insight Global • Santa Ana (CA)

On-site
USD 120,000 - 150,000
Principal Consultant – SOC Transformation and XSIAM Deployment
Principal Consultant – SOC Transformation and XSIAM Deployment

Palo Alto Networks • Santa Clara (CA)

Remote
USD 163,000 - 184,000
Competitive salary
Restricted stock units
Bonus potential
Senior XSIAM SOC Platform Architect
Senior XSIAM SOC Platform Architect

OtB Tech LLC • New York (NY)

Hybrid
USD 130,000 - 170,000
Senior SOC Analyst
Senior SOC Analyst

Soni • Philadelphia

On-site
USD 90,000 - 120,000
Principal Consultant – SOC Transformation and XSIAM Deployment
Principal Consultant – SOC Transformation and XSIAM Deployment

Palo Alto Networks • Atlanta (GA)

On-site
USD 163,000 - 225,000