Remote XSIAM Automation Engineer (PANW)

Posted today

stopahackcomBrooklyn (NY)

SENIORITY

Senior

Apply

About the role

About the job: StopAHack.com® is seeking a hands-on XSIAM Automation Consultant to support enterprise customers through the design, implementation, and optimization of security automation workflows within the Palo Alto Networks Cortex ecosystem.
Who we are: StopAHack.com® is a veteran-founded cybersecurity and technology services company and a Great Place To Work® certified employer. We deliver hands-on expertise to client programs and partner-led engagements.
The role: This is a customer-facing consulting role focused on building automation playbooks, developing custom integrations, improving SOC efficiency, and serving as a trusted advisor on Cortex XSIAM and Cortex XSOAR automation best practices. The ideal candidate has strong hands-on experience with SOAR automation, Python scripting, REST APIs, JSON workflows, SOC use cases, and technical communication with enterprise security teams.
What you will do:
  • Design, build, and maintain automation playbooks that improve and accelerate incident response and security operations within Cortex XSIAMAnalyze manual SOC and incident response workflows, then transform them into scalable, repeatable automation solutions
  • Develop and maintain custom integrations using Python to connect XSIAM with third-party security tools and internal platforms
  • Leverage REST APIs and JSON data structures to support orchestration across security technologies
  • Manage and deploy content packs, dashboards, layouts, and related automation content aligned to customer use cases
  • Perform health checks, troubleshooting, and optimization of integrations, automation flows, and platform content
  • Act as a subject matter expert on XSIAM and XSOAR automation strategy, design, and operational best practices
  • Partner with customer security teams to define automation roadmaps, identify opportunities for efficiency, and improve security maturity
  • Deliver knowledge transfer, technical workshops, and enablement sessions for customer security teams
  • Document designs, implementation decisions, workflows, and best practices in a clear, customer-friendly manner
  • What you bring
  • Hands-on experience building automation playbooks and managing integrations within Cortex XSOAR and/or Cortex XSIAMStrong Python programming skills for automation, scripting, and integration development
  • Deep understanding of SOC workflows, incident response processes, and security operations use cases
  • Strong experience working with REST APIs, integrations, and JSON data handling
  • Ability to troubleshoot complex issues across automation workflows, integrations, and orchestration logic
  • Strong customer-facing communication skills with the ability to explain technical concepts clearly and effectively
  • Ability to operate independently and manage technical workstreams with minimal oversight
Nice to have:
  • Experience developing or supporting automation content in enterprise security environments
  • Palo Alto Networks certifications such as PCNSE, PCDRA, or other XSOAR/XSIAM-related credentials
  • Experience advising customers on automation strategy, roadmap development, and operational maturity
  • Strong workshop delivery, documentation, and technical enablement experience
  • Reporting and supervision
  • This role operates as part of a consulting delivery team supporting enterprise customer environments
  • Candidates should be comfortable working independently while collaborating with customer stakeholders, security teams, and technical leadership
  • Success in this role requires strong ownership, clear communication, and the ability to drive automation workstreams from design through delivery
  • Work model and hours
  • Remote within the United States
  • Customer-facing consulting role supporting enterprise security programs
  • Standard business hours, with flexibility as needed for customer meetings, delivery milestones, and project needs
  • Limited client travel may be required depending on engagement needs
  • Work authorization
Applicants must be authorized to work in the United States without current or future sponsorship.
Hiring process: StopAHack screening and technical interviews. Customer or partner alignment interviews, as applicable. Federal background checks and onboarding aligned to contract requirements. Assignment to active projects. EEO and accessibility StopAHack.com® is an Equal Opportunity Employer. We consider all applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other legally protected status. If you require a reasonable accommodation during the application or interview process, contact .NoteThis role supports partner-led and customer-facing cybersecurity engagements involving Palo Alto Networks Cortex XSIAM and Cortex XSOAR technologies. Candidates hired for this role are employed by StopAHack.com®.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this