About Us:
Saddleback Solutions offer Consultancy and Professional Services to our Partners and Clients. We partner Palo Alto Networks, Juniper Networks and Arista worldwide, and we indirectly Partner AWS, so there are always lots of varying opportunities that come up.
We have long standing and close relationships with our consultants and our partners so we can represent you fully. We offer free training for all our consultants should they wish to expand their knowledge and profiles while with us.
We have an education services arm also, so our consultants once qualified can also offer their services running workshops or bootcamps between projects or even full time.
We will support you the best way we know how.
Tasks
- Lead the Kickoff and Planning Phase for XSIAM deployments, defining project scope, objectives, timelines, and resource requirements.
- Conduct comprehensive Architectural Discovery sessions to understand client environments, security requirements, and integration points for XSIAM.
- Oversee and actively participate in the Deployment of Cortex XSIAM infrastructure, including complex multi-tenant deployments with child tenants.
- Provide expert guidance and hands-on support for Data Source Onboarding, ensuring efficient and accurate ingestion of security telemetry into XSIAM.
- Specialize in Endpoints Tuning within the XSIAM ecosystem to optimize data quality and reduce noise for effective threat detection.
- Develop and implement sophisticated Correlation Rules to identify advanced threats and streamline alert generation.
- Leverage and configure Attack Surface Management (ASM) capabilities within XSIAM to provide clients with comprehensive visibility into their digital attack surface.
- Design, develop, and refine Data Models/Parsers to ensure accurate and actionable data representation within XSIAM.
- Collaborate with clients to identify opportunities for Alert Automation (PSC) and Playbook implementation, subject to discovery, and potentially supported by extended expertise.
- Advise on and implement best practices for Threat Intel Management within XSIAM, integrating various threat intelligence sources for enhanced detection.
- Work with clients to define requirements for and, as needed, contribute to the development of Custom Widgets and reports (to be further defined and potentially delivered through extended expertise).
- Lead and contribute to SOC Transformation initiatives, leveraging XSIAM to modernize security operations centers, streamline workflows, and enhance overall security posture.
- Produce high-quality, comprehensive Documentation throughout the project lifecycle, including architectural designs, configuration guides, and operational runbooks.
Requirements
- Education: Bachelor's degree in Computer Science, Information Security, or a related field; Master's degree preferred.
- Minimum of 8 years of experience in cybersecurity, with a strong focus on Security Operations Centers (SOC), incident response, and threat detection.
- Proven experience in leading and delivering complex cybersecurity extended expertise engagements.
- Demonstrable expertise in deploying, configuring, and optimizing Palo Alto Networks Cortex XSIAM.
- Extensive experience with SIEM platforms, SOAR technologies, and endpoint security solutions.
- Hands-on experience with data source integration, parsing, and data model creation.
- Proficiency in scripting languages (e.g., Python) for automation and data manipulation is a plus.
- Technical Skills:
- Deep understanding of security frameworks (e.g., MITRE ATT&CK, NIST).
- Expertise in network security, endpoint security, cloud security, and threat intelligence.
- Strong analytical and problem-solving skills with the ability to troubleshoot complex technical issues.
- Familiarity with cloud platforms (AWS, Azure, GCP) and containerization technologies is highly desirable.
Soft Skills:
- Exceptional communication (written and verbal) and presentation skills.
- Strong interpersonal skills with the ability to build rapport and trust with clients.
- Excellent organizational and project management abilities.
- Ability to work independently and as part of a distributed team.
- A proactive, results-oriented mindset with a commitment to client success.
Certifications (Preferred):
- Palo Alto Networks Certified Network Security Engineer (PCNSE)
- Palo Alto Networks Certified Security Automation Engineer (PCSAE)
- Relevant industry certifications (e.g., CISSP, CISM, GCIH, GCFA)
If you have hands-on Cortex XSIAM experience and are looking for an opportunity to work on an enterprise cybersecurity project with Palo Alto Networks, we'd love to hear from you.
