高级 MSIAM SOC 工程师(Unit 42)
Senior MSIAM SOC Engineer (Unit 42)
我们的使命
在Palo Alto Networks®,我们因共同的使命而团结——保护我们的数字生活方式。我们在创新与影响的交汇点上蓬勃发展,用尖端技术与大胆的思维解决现实世界的问题。在这里,每个人都有发言权,每个想法都至关重要。如果你准备好与同样充满热情的人一起,开展职业生涯中最有意义的工作,那么你来对地方了。
我们是谁
为了成为首选的网络安全合作伙伴,我们必须开拓道路,塑造行业的未来。这是我们的员工每天都在努力实现的目标,由我们的价值观定义:颠覆、协作、执行、诚信和包容。我们将人工智能融入我们所做的每一件事,并利用它来增强每个人所能产生的影响。如果你热衷于解决现实问题,并与最优秀的人才一起构思创意,我们邀请你加入我们!
这个职位是远程办公,但距离不会阻碍影响力。我们的混合团队跨地域协作,解决重大问题,贴近客户,并共同成长。你将加入一个重视信任、责任和共同成功的文化,你的工作真正重要。
职位概览
主要职责
- 推动相关规则的持续优化,确保所有部署的检测逻辑符合性能、准确性和操作相关性的严格标准。
- 将Unit 42威胁情报研究和新兴对手战术、技巧与程序(TTPs)转化为可操作、稳健的检测逻辑。
- 倡导主动自动化,设计复杂的剧本以解决新兴安全挑战,并在需求出现前优化操作流程。
- 在Cortex XSIAM中构建端到端的安全生命周期,无缝连接数据摄入、高保真度检测工程和复杂的响应自动化。
任职要求
- 5年以上在高级SOC、检测工程或安全架构角色中的实际经验,使用过SIEM、防火墙、EDR、沙箱和SOAR平台。
- 在检测工程生命周期方面有扎实的掌握,包括规则测试框架、软部署策略和持续调优的经验。
- 有审查和质量保证他人编写的检测逻辑的经验,能够提供建设性的优化反馈。
- 具有主动工程思维,有设计复杂自动化剧本(Cortex X
查看英文原文
Our Mission
At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.
Who We Are
In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!
This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.Job Summary
Key Responsibilities
- Drive the continuous refinement of correlation rules, ensuring all deployed detection logic meets strict standards for performance, accuracy, and operational relevance.
- Translate Unit 42 threat intelligence research and emerging adversary TTPs into actionable, robust detection logic.
- Champion proactive automation, engineering sophisticated playbooks to resolve emerging security challenges and optimize operational workflows ahead of demand.
- Architect the end-to-end security lifecycle within Cortex XSIAM, seamlessly connecting data ingestion, high-fidelity detection engineering, and sophisticated response automation.
Qualifications
- 5+ years of hands-on experience in a Senior SOC, Detection Engineering, or Security Architecture role utilizing SIEMs, firewalls, EDR, sandboxes, and SOAR platforms.
- Proven mastery of the Detection Engineering lifecycle, including experience with rule testing frameworks, soft-deployment strategies, and continuous tuning.
- Demonstrated experience reviewing and QA-ing detection logic written by others, with the ability to provide constructive optimization feedback.
- Proactive engineering mindset with a track record of designing complex automation playbooks (Cortex XSOAR or similar) based on anticipated threat vectors, not just reactive requests.
- Strong background in incident response, threat hunting, and translating threat intelligence into actionable defense mechanisms.
- Software development experience, with a strong proficiency in Python for security automation.
- Exceptional consultative and communication skills, with the confidence to guide enterprise customers through complex architectural and workflow decisions.
Preferred Qualifications
- Previous experience with Cortex XSIAM.
Compensation Disclosure
The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.
$126,000.00 - $204,500.00/yrOur Commitment
We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.
We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at .
Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.
All your information will be kept confidential according to EEO guidelines.
Is role eligible for Immigration Sponsorship? No. Please note that we will not sponsor applicants for work visas for this position.Originally posted on Himalayas