Haystack
← Back to Jobs
Remote
Other
EN

XSIAM Automation Consultant

Exl Neo TechnologiesUnited States🇺🇸United StatesPosted 4 Sept 2026

Why This Role Stands Out

This remote XSIAM Automation Consultant role offers a fantastic opportunity to deepen your expertise in cutting-edge cybersecurity automation and directly impact enterprise security operations. You'll thrive here if you possess a blend of technical skill in automation development and a passion for client engagement, making you an invaluable asset to Exl Neo Technologies. Apply today to shape the future of security with a leading firm!

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
1 week ago
AWSOAuthSplunkAzureGoogle CloudJavaScriptJiraPythonRESTServiceNowTriage

Job Description

Job Title: XSIAM Automation Consultant

Location: REMOTE

Employment Type: Long term contract



We are seeking a Professional Services Consultant - XSIAM Automation to join our cybersecurity Professional Services team.

This is a hands-on, customer-facing technical consulting role focused on designing, implementing, and optimizing security automation and orchestration solutions using Palo Alto Networks Cortex XSIAM and Cortex XSOAR.

The consultant will work with enterprise customers to assess SOC processes, identify automation opportunities, design and develop production-grade playbooks, build custom integrations, and operationalize security workflows. The role combines the technical depth of a Security Automation Engineer with the customer-facing responsibilities of a Professional Services Consultant.

The ideal candidate should be equally comfortable discussing automation strategy with a customer's SOC team and writing Python code to implement a complex integration or automation workflow.


Key Responsibilities


1. XSIAM / XSOAR Administration

Configure integrations, content packs, roles, permissions, and automation components.

Design scalable and maintainable automation architectures aligned with customer requirements.

Perform platform health checks and troubleshoot deployment, integration, and automation issues.

Support platform upgrades, maintenance, and ongoing optimization.

Validate end-to-end data flow, API connectivity, authentication, and workflow execution.


2. Automation & Playbook Development

Design, develop, test, and maintain production-grade automation playbooks.

Automate SOC processes across:

Alert triage

Investigation

IOC enrichment

Threat intelligence

Phishing response

Containment

Remediation

ITSM ticketing

Analyze manual SOC processes and transform them into scalable automated workflows.

Apply best practices for modularity, error handling, approvals, exception handling, auditability, and reusability.

Optimize playbooks for performance, maintainability, and operational effectiveness.

Manage and deploy content packs, automation assets, dashboards, and custom layouts.


3. Custom Integration & Automation Development

Develop custom integrations and automation using Python and, where applicable, JavaScript.

Build custom connectors when out-of-the-box integrations are unavailable.

Integrate XSIAM/XSOAR with third-party security and IT platforms.

Work with:

REST APIs

JSON

XML

OAuth

API tokens

Webhooks

Troubleshoot API connectivity, authentication, data transformation, and integration issues.

Develop reusable automation components to support customer-specific security workflows.


The emphasis on custom connectors, Python/JavaScript, REST APIs, OAuth, JSON, and webhooks is drawn from the EE-XSOAR Automation requirements.


4. Security Operations & Automation Strategy

Assess customer SOC processes and identify opportunities for automation.

Translate manual security operations processes into automated workflows.

Develop automation strategies aligned with customer security objectives.

Design workflows covering incident enrichment, investigation, response, and remediation.

Work with SOC teams to improve analyst efficiency and reduce repetitive manual activities.

Apply knowledge of incident response, threat intelligence, and security operations best practices.

Leverage frameworks such as MITRE ATT&CK where appropriate.


5. Security Ecosystem Integration

Integrate Cortex XSIAM/XSOAR with enterprise security and IT platforms, including:

SIEM

EDR/XDR

IAM

ITSM

Email Security

Threat Intelligence Platforms

Vulnerability Management

Cloud Security Platforms

Network Security Platforms


6. Customer Consulting & Advisory

Conduct customer discovery and requirements-gathering workshops.

Understand existing SOC processes, challenges, and automation requirements.

Translate business and technical requirements into practical automation solutions.

Present solution designs, recommendations, implementation approaches, and trade-offs.

Serve as a technical advisor to customer SOC teams and security stakeholders.

Identify opportunities to improve security operations through automation and orchestration.


7. Demonstrations, Training & Knowledge Transfer

Demonstrate playbooks, integrations, dashboards, and automation workflows to customer stakeholders.

Conduct administrator and analyst training.

Deliver technical workshops and enablement sessions.

Develop knowledge-transfer materials to help customers manage and expand their automation environment.

Support transition of implemented solutions into customer operations.


8. Documentation

Create and maintain:

High-Level Design (HLD) documents

Low-Level Design (LLD) documents

Architecture diagrams

Integration documentation

Playbook design documentation

Runbooks

Deployment procedures

As-built documentation

Operational procedures

Maintain clear documentation of dependencies, configurations, workflows, and customer-specific requirements.


Required Qualifications

5 - 12 years of experience in cybersecurity, security operations, security automation, SOAR, or Professional Services.

Strong hands-on experience with Cortex XSOAR and/or Cortex XSIAM.

Proven experience designing and implementing SOC automation workflows.

Strong proficiency in Python.

Strong knowledge of REST APIs, JSON, OAuth, API tokens, and webhooks.

Experience developing custom integrations or connectors.

Strong understanding of:

Security Operations

Incident Response

Threat Intelligence

SOC workflows

Security automation

Experience integrating security platforms and enterprise IT systems.

Ability to create and interpret technical design documentation.

Strong troubleshooting and problem-solving skills.

Excellent written and verbal communication skills.

Prior customer-facing consulting or Professional Services experience.


Preferred Qualifications

Hands-on experience with Cortex XSIAM.

Experience with Cortex XDR.

Experience with other SOAR platforms such as:

Splunk SOAR / Phantom

IBM Resilient

Swimlane

Tines

Experience with enterprise SIEM platforms such as:

Splunk

QRadar

ArcSight

NetWitness

Experience with ServiceNow and Jira.

Experience with cloud platforms such as AWS, Azure, or Google Cloud Platform.

Knowledge of MITRE ATT&CK.

Experience with threat intelligence platforms.

Experience developing custom security integrations.

Palo Alto Networks certifications such as:

PCSAE

PCDRA

PCNSE

Specialized Cortex XSOAR/XSIAM certifications

CISSP, CISM, GIAC, or relevant cloud/security certifications.


The broader XSOAR/SIEM JD supports including SIEM, detection engineering, threat hunting, cloud platforms, and security certifications as preferred areas rather than making them mandatory.


Key Competencies

Cortex XSIAM/XSOAR expertise

Security automation and orchestration

Playbook design and development

Python development

API and integration development

SOC process optimization

Incident response

Structured problem-solving

Enterprise security architecture

Customer consulting

Technical documentation

Technical presentations and knowledge transfer

Ability to work independently in customer environments

Similar jobs