Live opening · Posted 13 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Our Mission
At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.
Who We Are
In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!
This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.
Job Summary
Your Career
As a Senior SOC Engineer within Unit 42 at Palo Alto Networks, you will drive the creation, validation, and optimization of custom detection rules and automated playbooks across our global customer base. You will act as a trusted advisor, working closely with clients to maximize their security posture using Cortex XSIAM and Unit 42 expertise. This is a senior, highly analytical role requiring a deep understanding of detection lifecycles, proactive automation, and threat intelligence.
Your Impact
Own the full lifecycle of custom detections and response automations, deploying them as high-fidelity Cortex XSIAM correlation rules and playbooks through a rigorous engineering process of development, testing, staging, and soft implementation.
Drive the continuous refinement of correlation rules, ensuring all deployed detection logic meets strict standards for performance, accuracy, and operational relevance.
Translate Unit 42 threat intelligence research and emerging adversary TTPs into actionable, robust detection logic.
Champion proactive automation, engineering sophisticated playbooks to resolve emerging security challenges and optimize operational workflows ahead of demand.
Architect the end-to-end security lifecycle within Cortex XSIAM, seamlessly connecting data ingestion, high-fidelity detection engineering, and sophisticated response automation.
Qualifications
Your Experience
5+ years of hands-on experience in a Senior SOC, Detection Engineering, or Security Architecture role utilizing SIEMs, firewalls, EDR, sandboxes, and SOAR platforms.
Proven mastery of the Detection Engineering lifecycle, including experience with rule testing frameworks, soft-deployment strategies, and continuous tuning.
Demonstrated experience reviewing and QA-ing detection logic written by others, with the ability to provide constructive optimization feedback.
Proactive engineering mindset with a track record of designing complex automation playbooks (Cortex XSOAR or similar) based on anticipated threat vectors, not just reactive requests.
Strong background in incident response, threat hunting, and translating threat intelligence into actionable defense mechanisms.
Software development experience, with a strong proficiency in Python for security automation.
Exceptional consultative and communication skills, with the confidence to guide enterprise customers through complex architectural and workflow decisions.
Nice to have:
Previous experience with Cortex XSIAM.
Our Commitment
We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.
We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at accommodations@paloaltonetworks.com.
Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.
All your information will be kept confidential according to EEO guidelines.
Is role eligible for Immigration Sponsorship? No. Please note that we will not sponsor applicants for work visas for this position.
More openings worth a look
Recently tracked roles with full details and direct application links.