Job Title: XSIAM Automation Consultant
Location: REMOTE
Employment Type: Long term contract
We are seeking a Professional Services Consultant - XSIAM Automation to join our cybersecurity Professional Services team.
This is a hands-on, customer-facing technical consulting role focused on designing, implementing, and optimizing security automation and orchestration solutions using Palo Alto Networks Cortex XSIAM and Cortex XSOAR.
The consultant will work with enterprise customers to assess SOC processes, identify automation opportunities, design and develop production-grade playbooks, build custom integrations, and operationalize security workflows. The role combines the technical depth of a Security Automation Engineer with the customer-facing responsibilities of a Professional Services Consultant.
The ideal candidate should be equally comfortable discussing automation strategy with a customer's SOC team and writing Python code to implement a complex integration or automation workflow.
Key Responsibilities
1. XSIAM / XSOAR Administration
Configure integrations, content packs, roles, permissions, and automation components.
Design scalable and maintainable automation architectures aligned with customer requirements.
Perform platform health checks and troubleshoot deployment, integration, and automation issues.
Support platform upgrades, maintenance, and ongoing optimization.
Validate end-to-end data flow, API connectivity, authentication, and workflow execution.
2. Automation & Playbook Development
Design, develop, test, and maintain production-grade automation playbooks.
Automate SOC processes across:
Alert triage
Investigation
IOC enrichment
Threat intelligence
Phishing response
Containment
Remediation
ITSM ticketing
Analyze manual SOC processes and transform them into scalable automated workflows.
Apply best practices for modularity, error handling, approvals, exception handling, auditability, and reusability.
Optimize playbooks for performance, maintainability, and operational effectiveness.
Manage and deploy content packs, automation assets, dashboards, and custom layouts.
3. Custom Integration & Automation Development
Develop custom integrations and automation using Python and, where applicable, JavaScript.
Build custom connectors when out-of-the-box integrations are unavailable.
Integrate XSIAM/XSOAR with third-party security and IT platforms.
Work with:
REST APIs
JSON
XML
OAuth
API tokens
Webhooks
Troubleshoot API connectivity, authentication, data transformation, and integration issues.
Develop reusable automation components to support customer-specific security workflows.
The emphasis on custom connectors, Python/JavaScript, REST APIs, OAuth, JSON, and webhooks is drawn from the EE-XSOAR Automation requirements.
4. Security Operations & Automation Strategy
Assess customer SOC processes and identify opportunities for automation.
Translate manual security operations processes into automated workflows.
Develop automation strategies aligned with customer security objectives.
Design workflows covering incident enrichment, investigation, response, and remediation.
Work with SOC teams to improve analyst efficiency and reduce repetitive manual activities.
Apply knowledge of incident response, threat intelligence, and security operations best practices.
Leverage frameworks such as MITRE ATT&CK where appropriate.
5. Security Ecosystem Integration
Integrate Cortex XSIAM/XSOAR with enterprise security and IT platforms, including:
SIEM
EDR/XDR
IAM
ITSM
Email Security
Threat Intelligence Platforms
Vulnerability Management
Cloud Security Platforms
Network Security Platforms
6. Customer Consulting & Advisory
Conduct customer discovery and requirements-gathering workshops.
Understand existing SOC processes, challenges, and automation requirements.
Translate business and technical requirements into practical automation solutions.
Present solution designs, recommendations, implementation approaches, and trade-offs.
Serve as a technical advisor to customer SOC teams and security stakeholders.
Identify opportunities to improve security operations through automation and orchestration.
7. Demonstrations, Training & Knowledge Transfer
Demonstrate playbooks, integrations, dashboards, and automation workflows to customer stakeholders.
Conduct administrator and analyst training.
Deliver technical workshops and enablement sessions.
Develop knowledge-transfer materials to help customers manage and expand their automation environment.
Support transition of implemented solutions into customer operations.
8. Documentation
Create and maintain:
High-Level Design (HLD) documents
Low-Level Design (LLD) documents
Architecture diagrams
Integration documentation
Playbook design documentation
Runbooks
Deployment procedures
As-built documentation
Operational procedures
Maintain clear documentation of dependencies, configurations, workflows, and customer-specific requirements.
Required Qualifications
5 - 12 years of experience in cybersecurity, security operations, security automation, SOAR, or Professional Services.
Strong hands-on experience with Cortex XSOAR and/or Cortex XSIAM.
Proven experience designing and implementing SOC automation workflows.
Strong proficiency in Python.
Strong knowledge of REST APIs, JSON, OAuth, API tokens, and webhooks.
Experience developing custom integrations or connectors.
Strong understanding of:
Security Operations
Incident Response
Threat Intelligence
SOC workflows
Security automation
Experience integrating security platforms and enterprise IT systems.
Ability to create and interpret technical design documentation.
Strong troubleshooting and problem-solving skills.
Excellent written and verbal communication skills.
Prior customer-facing consulting or Professional Services experience.
Preferred Qualifications
Hands-on experience with Cortex XSIAM.
Experience with Cortex XDR.
Experience with other SOAR platforms such as:
Splunk SOAR / Phantom
IBM Resilient
Swimlane
Tines
Experience with enterprise SIEM platforms such as:
Splunk
QRadar
ArcSight
NetWitness
Experience with ServiceNow and Jira.
Experience with cloud platforms such as AWS, Azure, or Google Cloud Platform.
Knowledge of MITRE ATT&CK.
Experience with threat intelligence platforms.
Experience developing custom security integrations.
Palo Alto Networks certifications such as:
PCSAE
PCDRA
PCNSE
Specialized Cortex XSOAR/XSIAM certifications
CISSP, CISM, GIAC, or relevant cloud/security certifications.
The broader XSOAR/SIEM JD supports including SIEM, detection engineering, threat hunting, cloud platforms, and security certifications as preferred areas rather than making them mandatory.
Key Competencies
Cortex XSIAM/XSOAR expertise
Security automation and orchestration
Playbook design and development
Python development
API and integration development
SOC process optimization
Incident response
Structured problem-solving
Enterprise security architecture
Customer consulting
Technical documentation
Technical presentations and knowledge transfer
Ability to work independently in customer environments