Security Architect Apply
We are seeking an experienced Security Architect to lead the design, deployment, and optimization of Palo Alto Cortex XDR across enterprise environments. The role requires deep expertise in SIEM and SOAR Platform, strong exposure to security automation, and hands-on experience integrating with SIEM platforms for centralized monitoring and incident response.The architect will drive advanced threat detection, automated response use cases, and SOC modernization initiatives while aligning security operations with best practices and zero-trust principles.Key ResponsibilitiesXDR Architecture & StrategyDesign and own the Cortex XDR architecture across endpoints, servers, and cloud workloadsDefine XDR onboarding strategy for endpoints, network, and cloud telemetryEstablish detection, prevention, and response standards aligned with MITRE ATT&CKLead XDR roadmap, capacity planning, and platform optimizationCortex XDR Implementation & OperationsArchitect and deploy Palo Alto Cortex XDR:Endpoint protection, behavioral analytics, and threat preventionIncident correlation and root cause analysisTune detection policies, alert thresholds, and prevention profilesOversee agent deployment, upgrades, and performance optimization Automation & SOARDesign and implement security automation and response workflowsIntegrate Cortex XDR with SOAR platforms (Cortex XSOAR preferred)Develop automated playbooks for:Alert triage and enrichmentContainment and remediation (endpoint isolation, user disablement, IOC blocking)Leverage APIs, scripting, and integrations to reduce manual SOC effort SIEM Integration & MonitoringIntegrate Cortex XDR with SIEM platforms (Splunk, Sentinel, QRadar, etc.)Design log ingestion, normalization, and correlation use casesBuild dashboards and alerts for SOC visibility and executive reportingOptimize signal-to-noise ratio across SIEM and XDR platformsThreat Detection & Incident ResponseDefine and validate advanced detection use casesLead threat hunting initiatives using XDR and SIEM telemetrySupport incident response investigations and post-incident reviewsContinuously improve detections based on emerging threats

