Administrator - Cortex XSIAM ,Cortex A, ADEM

Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · DevOps

In short

We are looking for a skilled Palo Alto Cortex XSIAM/XSOAR Engineer with at least 6 years of experience in SIEM and SOAR platforms. The role involves administering, configuring, and optimizing these platforms, developing automation playbooks, integrating security tools, and conducting threat hunting and incident investigations. This position requires strong scripting skills in Python and expertise in API integrations to enhance SOC efficiency.

Responsibilities

  • Administer, configure, and maintain Palo Alto Cortex XSOAR, Cortex XSIAM, and Cortex XDR platforms.
  • Design, develop, and optimize SOAR playbooks for automated incident response and security operations.
  • Integrate security tools including Firewalls, EDR, Threat Intelligence, IAM, Ticketing, and Cloud Security solutions with SOAR platforms.
  • Develop and maintain use cases, correlation rules, dashboards, alerts, and reports within SIEM environments.
  • Conduct threat hunting, incident analysis, root cause investigations, and forensic analysis.
  • Monitor security events and respond to incidents in alignment with organizational security policies and SLAs.
  • Fine-tune detection rules and reduce false positives to improve SOC efficiency.
  • Create custom automation scripts using Python, REST APIs, and JSON-based integrations.
  • Work closely with SOC analysts, Incident Response teams, Threat Intelligence teams, and IT operations teams.
  • Support security audits, compliance requirements, and reporting activities.
  • Develop operational runbooks, knowledge articles, and technical documentation.
  • Stay updated on emerging threats, vulnerabilities, and Palo Alto security technology advancements.

Requirements

  • Palo Alto Cortex XSIAM
  • Palo Alto Cortex XSOAR
  • 6+ years of experience in Cybersecurity Operations, SIEM, and SOAR technologies.
  • Strong experience with Palo Alto Cortex XSOAR and Cortex XSIAM deployment and administration.
  • Hands-on experience integrating third-party security products through APIs.
  • Experience in incident response, threat hunting, and SOC operations.
  • Python
  • REST APIs
  • JSON
  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related field.

Desired Qualifications

  • Splunk (preferred)
  • LogRhythm or ArcSight (good to have)
  • PowerShell (good to have)
  • AWS Security Services (Preferred)
  • Microsoft Azure Security (Preferred)
  • Google Cloud Platform Security (Preferred)
  • Palo Alto Networks Certified XSOAR Engineer
  • Palo Alto Networks Certified Cybersecurity Associate (PCCSA)
  • Palo Alto Networks Certified Network Security Engineer (PCNSE)
  • Splunk Core Certified Power User/Admin
  • Microsoft SC-200
  • CISSP
  • CEH
  • GCIH

Benefits

  • Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.
#SIEM#SOAR#Cybersecurity#Automation#Incident Response#Threat Hunting#Palo Alto#XSIAM#XSOAR#XDR
HCLTech Logo

Company

HCLTech

Job Posted

4 weeks ago

Employment Type

Full Time

WorkMode

On Site

Experience Level

Senior

Locations

Bangalore, India

Qualification

Bachelor

Applicants

Be an early applicant