Principal Technical Consultant (XSIAM)-Network Delivery
United States
AHEAD
AHEAD accelerates the impact of technology on clients by engineering customized data, developer, and infrastructure platforms that improve IT operations.At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD.
We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived.
We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD.
The Principal Technical Consultant is a leading expert in cybersecurity and the Palo Alto Networks XSIAM platform. They will provide oversight and technical leadership for multiple complex XSIAM deployments, guiding both clients and consulting teams to successful outcomes. This role requires high-level to mastery expertise in several core XSIAM-related technology domains and a strong understanding of the broader cybersecurity landscape.
Requirements:
- Lead the charge on architecting and delivering complex Palo Alto Networks XSIAM solutions, from strategy and design through to implementation and operationalization, ensuring alignment with client business objectives.
- Act as the foremost technical expert for XSIAM engagements, guiding clients through data source integration, advanced parsing and data model creation, development of robust correlation rules, and implementation of effective automation playbooks.
- Provide strategic advisory services to clients on optimizing their SOC processes, leveraging XSIAM for enhanced threat detection, response, and overall security posture improvement.
- Mentor and develop other AHEAD consultants, building our collective XSIAM capabilities and fostering a collaborative team environment.
- Collaborate with AHEAD’s sales and solutions architecture teams to scope XSIAM opportunities, develop SOWs, and present our value proposition to clients.
- Drive the development of AHEAD’s XSIAM service offerings, best practices, and intellectual property.
- Ensure successful project delivery by managing technical risks, overseeing quality, and maintaining strong client relationships.
Qualifications
- A minimum of 10 years of experience in cybersecurity, with a strong emphasis on SIEM/SOAR platforms, EDR/XDR solutions, and modern SOC operations.
- At least 3 years of hands-on experience leading the architecture and implementation of Palo Alto Networks XSIAM or similar enterprise-scale security analytics and automation platforms.
- Expert-level knowledge and practical application in several of the following areas:
- o Log Management and SIEM (e.g., data ingestion, normalization, XDM)
- o Security Automation and Orchestration (SOAR)
- o Endpoint Detection & Response (EDR/XDR) using Cortex and CrowdStrike
- o Network Security principles and Palo Alto Networks NGFW
- o Cloud Security architecture and services (AWS, Azure, GCP)
- o Threat Intelligence integration and management
- o Attack Surface Management concepts and tools
- o Identity security and solutions like Cloud Identity Engine
- Proficiency in XQL, scripting (preferably Python), and working with APIs for security integrations.
- 7+ years of demonstrated threat intelligence and Incident response experience
- Demonstrated leadership capabilities with experience mentoring and guiding technical teams.
- Exceptional consulting skills, including strong analytical, communication, and client engagement abilities.
- Relevant industry certifications such as CISSP, CISM, and Palo Alto Networks (PCNSE, PCSAE) are strongly preferred.
Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.
We fuel growth by stacking our office with top-notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.
USA Employment Benefits include: - Medical, Dental, and Vision Insurance - 401(k) - Paid company holidays - Paid time off - Paid parental and caregiver leave - Plus more! See benefits https://www.aheadbenefits.com/ for additional details.
The compensation range indicated in this posting reflects the On-Target Earnings (“OTE”) for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate’s relevant experience, qualifications, and geographic location.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Analytics APIs Automation AWS Azure CISM CISSP Cloud CrowdStrike EDR GCP Incident response Network security NGFW Python Scripting SIEM SOAR SOC Strategy Threat detection Threat intelligence XDR
Perks/benefits: Career development Health care Insurance Medical leave Parental leave Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.