Senior MSIAM SOC Engineer – Unit 42

🔥 11 minutes ago

🌲 North Carolina – Remote

infoinfo

💵 $134.6k - $217.8k / year

⏰ Full Time

🟠 Senior

🛡️ Security Operations

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Palo Alto Networks

Palo Alto Networks

10,000+ employees

🔒 Cybersecurity

🏢 Enterprise

💰 $1M Seed Round - Morta Security on 2013-02

Cybersecurity • Enterprise

Palo Alto Networks is a global cybersecurity company that provides AI-driven platforms, products, and services to protect networks, cloud workloads, endpoints, and applications. Its portfolio includes next-generation firewalls, SASE and Prisma Cloud (CNAPP) offerings, the Cortex security operations suite (XDR, XSOAR, XSIAM), and Unit 42 threat intelligence and incident response services. Palo Alto Networks helps enterprises secure AI deployments, automate SOC workflows, and prevent, detect, and respond to sophisticated threats across hybrid and multi-cloud environments.

📋 Description

• Continuously refine correlation rules to ensure detection logic meets standards for performance, accuracy, and operational relevance • Translate Unit 42 threat intelligence research and emerging adversary TTPs into actionable detection logic • Design sophisticated automation playbooks to resolve emerging security challenges and optimize operational workflows • Architect the end-to-end security lifecycle within Cortex XSIAM • Connect data ingestion, high-fidelity detection engineering, and response automation • Review and provide optimization feedback on detection logic written by others • Guide enterprise customers through complex architectural and workflow decisions • Collaborate remotely across geographies in a hybrid team environment

🎯 Requirements

• 5+ years of hands-on experience in a Senior SOC, Detection Engineering, or Security Architecture role • Experience utilizing SIEMs, firewalls, EDR, sandboxes, and SOAR platforms • Mastery of the Detection Engineering lifecycle • Experience with rule testing frameworks, soft-deployment strategies, and continuous tuning • Experience reviewing and QA-ing detection logic written by others • Experience designing complex automation playbooks, preferably with Cortex XSOAR or similar • Strong background in incident response and threat hunting • Experience translating threat intelligence into actionable defense mechanisms • Software development experience with strong proficiency in Python for security automation • Exceptional consultative and communication skills • Ability to guide enterprise customers through complex architectural and workflow decisions • Previous experience with Cortex XSIAM preferred • Applicants must not require immigration sponsorship; the position does not sponsor work visas

🏖️ Benefits

• Restricted stock units may be included • Bonus may be included • Employee benefits are offered; details are referenced via the employer’s benefits description • Reasonable accommodations for qualified individuals with disabilities or special needs

Apply Now

Similar Jobs

🔥 2 hours ago

Convergint

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

SOC Services Architect delivering PSIM, automation, analytics, and integrated security solutions for Convergint. Leading customer-facing technical delivery from pre-sales requirements through commissioning and acceptance.

🔥 3 hours ago

Conduent

10,000+ employees

🏥 Healthcare

📦 Logistics

💼 Consulting

Cyber Security Operations Engineer automating Conduent’s global cybersecurity operations. Building scripts, integrations, dashboards, and reporting for incident response and vulnerability management.

🔥 4 hours ago

Tokio Marine HCC

1001 - 5000

📦 Logistics

💼 Consulting

✈️ Travel

Security Operations Engineer supporting Vector3’s MDR customers with incident response, troubleshooting, and security operations. Helping cyber-insurance clients investigate, contain, and recover from BEC and ransomware incidents.

🗣️🇪🇸 Spanish Required

🔥 6 hours ago

SANS Institute

201 - 500

🔒 Cybersecurity

📚 Education

☁️ SaaS

Senior SOC Engineer building SANS’s agentic SOC, detection engineering, and security automation. Securing cloud, identity, applications, vulnerabilities, and incident response.

🕒 Yesterday

Valiant Solutions

201 - 500

💼 Consulting

🎖️ Defense

🔒 Cybersecurity

Tier III SOC Analyst conducting forensic investigations, detection engineering, and incident escalation. Supporting Valiant Solutions’ public-sector cybersecurity contracts through remote telework.