Cortex Platform Engineer

Reposted Yesterday
Be an Early Applicant
Hyderabad, Telangana, IND
Hybrid
Senior level
Cloud • Information Technology
The Role
The Cortex Platform Engineer will manage and optimize the Cortex ecosystem focusing on deployment, configuration, and engineering of Cortex XDR, while collaborating with SOC analysts and cloud teams for integrated security operations.
Summary Generated by Built In
AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.
 
At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD. 
 
We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived. 
 
We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD. 

We are looking for an experienced Cortex Platform Engineer with deep expertise in Palo Alto Networks’ Cortex ecosystem. Cortex XDR is the primary focus of this role — you will own its deployment, configuration, detection engineering, and day-to-day operations — but you will also bring working knowledge across Cortex XSOAR, XSIAM, Cortex Cloud, and Prisma Access to support a maturing, integrated security operations environment.

This is a hands-on, high-ownership role at the intersection of endpoint security, SOC automation, cloud security posture, and secure network access. You will partner closely with SOC analysts, security architects, and cloud engineering teams to drive platform adoption, improve detection coverage, and accelerate response across the full Cortex stack.


Core Responsibilities

    Cortex XDR — Primary Focus

  • Own end-to-end deployment, configuration, and lifecycle management of Cortex XDR across Windows, macOS, and Linux endpoints at enterprise scale.
  • Design and maintain agent policies, prevention profiles, and exclusion sets; manage multi-tenant or multi-instance architectures where applicable.
  • Develop, tune, and maintain BIOC rules, custom correlation policies, and Behavioral Threat Protection (BTP) configurations to maximize signal fidelity and minimize analyst fatigue.
  • Lead Tier 2/Tier 3 incident investigations using XDR’s causality analysis engine, storyline feature, and XQL-based threat hunting across endpoint, network, and cloud telemetry.
  • Coordinate response actions including endpoint isolation, process termination, and file quarantine; produce post-incident reports for technical and executive audiences.
  • Translate MITRE ATT&CK mappings and threat intelligence into actionable XDR detection logic; conduct regular alert reviews to identify tuning opportunities and coverage gaps.
  • Cortex XSOAR — Automation & Orchestration
  • Build, maintain, and optimize XSOAR playbooks for automated triage, enrichment, containment, and response workflows tied to XDR and other platform alerts.
  • Manage integration packs, custom scripts, and connector configurations to support bidirectional data flow between XSOAR and the broader security toolset.
  • Collaborate with SOC analysts to identify high-value automation candidates, reducing manual toil and accelerating mean time to respond (MTTR).
  • Maintain playbook documentation, versioning, and testing standards to ensure operational reliability
  • Cortex XSIAM — AI-Driven SOC Operations
  • Support the deployment and configuration of Cortex XSIAM as the organization’s AI-driven SOC platform, including data source onboarding and ingestion pipeline management.
  • Leverage XSIAM’s machine learning-driven alert correlation and incident scoring to reduce alert volume and prioritize analyst queues.
  • Assist in defining and tuning XSIAM detection rules, analytics models, and dashboard views aligned to SOC operational requirements.
  • Work with security leadership to evaluate XSIAM’s AI-generated insights and feed findings back into detection and response improvement cycles.
  • Cortex Cloud — Cloud Security Posture

  • Operate Cortex Cloud (CNAPP) to provide continuous visibility into cloud workload security posture across AWS, Azure, and GCP environments.
  • Manage cloud workload protection policies, vulnerability findings, and compliance benchmarks; triage and escalate high-severity findings to cloud engineering teams.
  • Integrate Cortex Cloud telemetry into XDR and XSIAM detection pipelines to extend threat visibility into cloud-native workloads and container environments.
  • Support cloud security assessments and assist in developing guardrails and policy-as-code aligned to organizational security standards.
  • Prisma Access — SASE & Secure Network Access

  • Support the administration and operational maintenance of Prisma Access for secure remote access, branch connectivity, and SASE policy enforcement.
  • Assist with policy configuration, user/tunnel management, and troubleshooting of Prisma Access deployments in coordination with network engineering.
  • Integrate Prisma Access logs and telemetry into XDR and XSIAM for unified visibility across network and endpoint data sources.
  • Participate in SASE architecture reviews and contribute security operations requirements to network and access design discussions.
  • Platform Integration & Governance

  • Architect and maintain integrations across the Cortex platform and adjacent tools including SIEM (Splunk, Sentinel, QRadar), ticketing systems, and identity providers.
  • Maintain platform health across all Cortex components: version management, licensing, policy compliance, and coverage gap reporting.
  • Define and track platform KPIs across detection effectiveness, automation rate, response time, and cloud posture; report to security leadership on a recurring cadence.
  • Produce and maintain runbooks, architecture documentation, and knowledge base content for SOC and engineering team use.
  •  

Required Qualifications

    Experience

  • 5+ years of hands-on cybersecurity experience in SOC engineering, security operations, or endpoint/cloud security roles.
  • 3+ years of direct, production experience operating Cortex XDR at enterprise scale — lab-only experience does not meet this requirement.
  • Demonstrated experience with at least two additional Cortex platform components (XSOAR, XSIAM, Cortex Cloud, or Prisma Access) in a production environment.
  • Proven ability to write and optimize XQL queries for threat hunting, detection tuning, and forensic investigation.
  • Hands-on experience with XSOAR playbook development and integration pack management.
  • Working knowledge of at least one SIEM platform (Splunk, Sentinel, or QRadar) with integration experience.
  • Technical Knowledge

  • Strong understanding of Windows, macOS, and Linux internals as they relate to endpoint telemetry, process execution, and persistence mechanisms.
  • Solid grasp of the MITRE ATT&CK framework with the ability to map detections to specific techniques and sub-techniques.
  • Familiarity with cloud security fundamentals across AWS, Azure, or GCP — IAM, workload security, network segmentation, and logging.
  • Understanding of SASE principles, zero-trust network access concepts, and secure remote access architectures.
  • Scripting competency in Python, PowerShell, or Bash for automation, log parsing, and platform integration development.

Preferred Qualifications

    Certifications

  • Palo Alto Networks Certified Detection and Response Analyst (PCDRA) — strongly preferred; expected within 90 days of hire if not already held.
  • Palo Alto Networks Certified Network Security Engineer (PCNSE) — advantageous given the breadth of Palo Alto platform coverage in this role.
  • Palo Alto Networks Certified Security Automation Engineer (PCSAE) for candidates with strong XSOAR focus.
  • GIAC GCED, GCIH, or equivalent incident response certification.
  • AWS, Azure, or GCP cloud security certifications (e.g., AWS Security Specialty, AZ-500, Google Professional Cloud Security Engineer).
  • Additional Technical Experience

  • Hands-on XSIAM deployment or migration experience, particularly from legacy SIEM or XDR-only environments.
  • Experience with Cortex Cloud’s CSPM, CWPP, or CDR capabilities in a multi-cloud environment.
  • Familiarity with Prisma SD-WAN or broader Palo Alto Networks network security portfolio.
  • Experience with threat intelligence platforms (MISP, ThreatConnect, Anomali) integrated into XSOAR or XSIAM workflows.
  • Background in managed detection and response (MDR) or MSSP environments with multi-tenant platform management experience.

Why AHEAD:
 
Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.
 
We fuel growth by stacking our office with top-notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.
 
India Employment Benefits include: 
Comprehensive health insurance coverage for employees, with options to extend coverage to dependents
Paid time off and company holidays, along with additional leave benefits as per policy
Flexible work arrangements, supporting work-life balance
Learning and development opportunities to support continuous growth and upskilling
Employee wellness initiatives and programs focused on physical and mental well-being
Retirement and statutory benefits in line with India regulations
Inclusive and people-first culture, with a strong focus on collaboration and ownership
 

Skills Required

  • 5+ years of hands-on cybersecurity experience
  • 3+ years of production experience operating Cortex XDR
  • Experience with at least two additional Cortex components
  • Ability to write and optimize XQL queries
  • Experience with XSOAR playbook development
  • Knowledge of at least one SIEM platform

AHEAD Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about AHEAD and has not been reviewed or approved by AHEAD.

  • Retirement Support 401(k) contributions are matched dollar-for-dollar on the first $5,000 each year, with matching made each pay period and immediate 100% vesting. This structure signals above-standard employer support for retirement savings.
  • Affordable Benefits Medical options include low employee premiums for PPO and HDHP plans, and the HDHP adds employer HSA funding plus a dollar-for-dollar HSA match up to stated amounts. Dental and vision plans list very low per-paycheck costs, helping keep overall healthcare spend manageable.
  • Wellbeing & Lifestyle Benefits No-cost telemedicine (including virtual mental health when enrolled), free Calm access for the employee and dependents, and an EAP with counseling are included. Company-paid life and disability plus voluntary protections (legal/ID, pet insurance) and other extras round out a comprehensive set of supports.

AHEAD Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
1,154 Employees
Year Founded: 2007

What We Do

AHEAD builds platforms for digital business. By weaving together cloud infrastructure, intelligent operations, and modern applications, we help enterprises deliver on the promise of digital transformation.

Similar Jobs

PureSpectrum Logo PureSpectrum

Senior Data Scientist

Big Data • Marketing Tech • Sales • Software • Analytics • Big Data Analytics
Hybrid
Hyderabad, Telangana, IND
283 Employees

Wise Logo Wise

Operations Associate

Fintech • Mobile • Payments • Software • Financial Services
Hybrid
Hyderabad, Telangana, IND
9000 Employees
650K-650K Annually

Wise Logo Wise

Head of KYC Operations - APAC

Fintech • Mobile • Payments • Software • Financial Services
Hybrid
Hyderabad, Telangana, IND
9000 Employees

Wise Logo Wise

Atlassian Engineering Lead

Fintech • Mobile • Payments • Software • Financial Services
Hybrid
Hyderabad, Telangana, IND
9000 Employees

Similar Companies Hiring

Amplify Platform Thumbnail
Fintech • Financial Services • Consulting • Cloud • Business Intelligence • Big Data Analytics
Scottsdale, AZ
62 Employees
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account