All Jobs Vacancy

XSIAM Automation Consultant

Posted 1 day ago by Exl Neo Technologies

Job Title: XSIAM Automation Consultant

Location: REMOTE

Employment Type: Long term contract

We are seeking a Professional Services Consultant - XSIAM Automation to join our cybersecurity Professional Services team.

This is a hands-on, customer-facing technical consulting role focused on designing, implementing, and optimizing security automation and orchestration solutions using Palo Alto Networks Cortex XSIAM and Cortex XSOAR.

The consultant will work with enterprise customers to assess SOC processes, identify automation opportunities, design and develop production-grade playbooks, build custom integrations, and operationalize security workflows. The role combines the technical depth of a Security Automation Engineer with the customer-facing responsibilities of a Professional Services Consultant.

Key Responsibilities

  • XSIAM / XSOAR Administration
  • Configure integrations, content packs, roles, permissions, and automation components.
  • Design scalable and maintainable automation architectures aligned with customer requirements.
  • Perform platform health checks and troubleshoot deployment, integration, and automation issues.
  • Support platform upgrades, maintenance, and ongoing optimization.
  • Validate end-to-end data flow, API connectivity, authentication, and workflow execution.

Automation & Playbook Development

  • Design, develop, test, and maintain production-grade automation playbooks.
  • Automate SOC processes across:
  • Alert triage
  • Investigation
  • IOC enrichment
  • Threat intelligence
  • Phishing response
  • Containment
  • Remediation
  • ITSM ticketing
  • Analyze manual SOC processes and transform them into scalable automated workflows.
  • Apply best practices for modularity, error handling, approvals, exception handling, auditability, and reusability.
  • Optimize playbooks for performance, maintainability, and operational effectiveness.
  • Manage and deploy content packs, automation assets, dashboards, and custom layouts.

Custom Integration & Automation Development

  • Develop custom integrations and automation using Python and, where applicable, JavaScript.
  • Build custom connectors when out-of-the-box integrations are unavailable.
  • Integrate XSIAM/XSOAR with third-party security and IT platforms.
  • Work with:
  • REST APIs
  • JSON
  • XML
  • OAuth
  • API tokens
  • Webhooks
  • Troubleshoot API connectivity, authentication, data transformation, and integration issues.
  • Develop reusable automation components to support customer-specific security workflows.

Security Operations & Automation Strategy

  • Assess customer SOC processes and identify opportunities for automation.
  • Translate manual security operations processes into automated workflows.
  • Develop automation strategies aligned with customer security objectives.
  • Design workflows covering incident enrichment, investigation, response, and remediation.
  • Work with SOC teams to improve analyst efficiency and reduce repetitive manual activities.
  • Apply knowledge of incident response, threat intelligence, and security operations best practices.
  • Leverage frameworks such as MITRE ATT&CK where appropriate.

Security Ecosystem Integration

  • Integrate Cortex XSIAM/XSOAR with enterprise security and IT platforms, including:
  • SIEM
  • EDR/XDR
  • IAM
  • ITSM
  • Email Security
  • Threat Intelligence Platforms
  • Vulnerability Management
  • Cloud Security Platforms
  • Network Security Platforms

Customer Consulting & Advisory

  • Conduct customer discovery and requirements-gathering workshops.
  • Understand existing SOC processes, challenges, and automation requirements.
  • Translate business and technical requirements into practical automation solutions.
  • Present solution designs, recommendations, implementation approaches, and trade-offs.
  • Serve as a technical advisor to customer SOC teams and security stakeholders.
  • Identify opportunities to improve security operations through automation and orchestration.

Demonstrations, Training & Knowledge Transfer

  • Demonstrate playbooks, integrations, dashboards, and automation workflows to customer stakeholders.
  • Conduct administrator and analyst training.
  • Deliver technical workshops and enablement sessions.
  • Develop knowledge-transfer materials to help customers manage and expand their automation environment.
  • Support transition of implemented solutions into customer operations.

Documentation

  • Create and maintain:
  • High-Level Design (HLD) documents
  • Low-Level Design (LLD) documents
  • Architecture diagrams
  • Integration documentation
  • Playbook design documentation
  • Runbooks
  • Deployment procedures
  • As-built documentation
  • Operational procedures
  • Maintain clear documentation of dependencies, configurations, workflows, and customer-specific requirements.

Required Qualifications

  • 5 - 12 years of experience in cybersecurity, security operations, security automation, SOAR, or Professional Services.
  • Strong hands-on experience with Cortex XSOAR and/or Cortex XSIAM.
  • Proven experience designing and implementing SOC automation workflows.
  • Strong proficiency in Python.
  • Strong knowledge of REST APIs, JSON, OAuth, API tokens, and webhooks.
  • Experience developing custom integrations or connectors.
  • Strong understanding of:
  • Security Operations
  • Incident Response
  • Threat Intelligence
  • SOC workflows
  • Security automation
  • Experience integrating security platforms and enterprise IT systems.
  • Ability to create and interpret technical design documentation.
  • Strong troubleshooting and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Prior customer-facing consulting or Professional Services experience.

Preferred Qualifications

  • Hands-on experience with Cortex XSIAM.
  • Experience with Cortex XDR.
  • Experience with other SOAR platforms such as:
  • Splunk SOAR / Phantom
  • IBM Resilient
  • Swimlane
  • Tines
  • Experience with enterprise SIEM platforms such as:
  • Splunk
  • QRadar
  • ArcSight
  • NetWitness
  • Experience with ServiceNow and Jira.
  • Experience with cloud platforms such as AWS, Azure, or Google Cloud Platform.
  • Knowledge of MITRE ATT&CK.
  • Experience with threat intelligence platforms.
  • Experience developing custom security integrations.
  • Palo Alto Networks certifications such as:
  • PCSAE
  • PCDRA
  • PCNSE
  • Specialized Cortex XSOAR/XSIAM certifications
  • CISSP, CISM, GIAC, or relevant cloud/security certifications.

Key Competencies

  • Cortex XSIAM/XSOAR expertise
  • Security automation and orchestration
  • Playbook design and development
  • Python development
  • API and integration development
  • SOC process optimization
  • Incident response
  • Structured problem-solving
  • Enterprise security architecture
  • Customer consulting
  • Technical documentation
  • Technical presentations and knowledge transfer
  • Ability to work independently in customer environments
Rate:
Not specified
Location:
Remote
IR35 Status:
Outside
Remote Status:
Remote
Industry:
Cybersecurity
Seniority Level:
Senior

Take-Home Pay

Not Available

Visit calculators for additional details

Create a free account to view the take-home pay for this contract

Share job