Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
XSIAM Detection Engineer image - Rise Careers
Job details

XSIAM Detection Engineer

Who We Are

Red Canary was founded to create a world where every organization can make its greatest impact without fear of cyber threats. We’re a cyber security company who protects, supports and empowers organizations to make better security decisions so they can focus on their mission without fear of cyber threats.


The combination of our market-defining technology and expertise prevents breaches every day and sets a new standard for partnership in the industry. We’re united in our commitment to customers and grounded in our values, which earned us a place on the Forbes Best Start-up Employers 2022 list.  If our mission resonates with you, let’s talk.


What We Believe In

- Do what’s right for the customer

- Be kind and authentic

- Deliver great quality

- Be relentless


Challenges You Will Solve

The security landscape is always shifting and introducing new adversaries. The Red Canary XSIAM Detection Engineering & Response team operates 24/7 to track down threats in source signal data and deliver fast and actionable detections to our customers.


The XSIAM Detection Engineer will configure a Security Information and Event Management (SIEM) system for our customers. Using SIEM technology, you will investigate and triage alarms related to relevant security data/threats/events. In addition, you will write scripts to automate solutions for alarms and threats from enterprise systems. XSIAM Detection Engineers will write and tune advanced detectors and correlation rules to identify threats in customers’ environments. 


This is not a role where you are encouraged to passively accept the current state. At Red Canary, you are empowered to actively identify and research opportunities to automate threat detection and response activities.


What You'll Do
  • Use Palo Alto’s XSIAM platform, source signal data, and external resources to uncover threats and tell the story of what occurred in a customer environment.
  • Build new detection capabilities into the XSIAM platform based on your research of new attack techniques.
  • Leverage previous security operations experience to enhance the XSIAM Detection Engineering & Response teams knowledge-base and expertise.
  • Initiate and undertake tasks of writing XQL logic in the XSIAM platform to improve operational workflows.
  • Create and tune customer facing playbooks for SOAR functionality.


What You'll Bring
  • Core requirements every candidate must possess:
  • 1+ years experience working hands-on in Information Security SIEM administration, parser development, cybersecurity content development, creating queries, alerting, and log analysis (or similar analysis role).
  • 1+ years experience in scripting/process automation. 
  • 1+ years experience operating and supporting a large enterprise environment.
  • Experience with security configuration of operating systems, network devices, etc. 
  • Demonstrated experience with at least one programming/scripting language.
  • Demonstrated experience in understanding networking technologies and protocols.
  • Demonstrated systems administration experience with Windows and Linux/UNIX-based operating systems.
  • Participated in an on-call schedule responsible for responding to high-priority issues.
  • Must have a passion for technology and stay current with emerging security trends.
  • Excellent verbal & written communication and presentation skills. 


Bonus Points
  • Experience with Palo Alto XSIAM (or next-gen SIEM).
  • Experience with EDR technologies.
  • Familiarity with standard logs from different systems: Windows/Linux/Cloud, etc. 
  • Advanced scripting – Python, Go, Javascript.


Targeted base salary range: $95,400 - $118,000. This role is eligible for participation in the company's bonus program. This role is also eligible for a grant of stock options, subject to the approval of the company's board of directors.


**this position will be supporting a 5am to 3pm MT shift, Sunday through Wednesday.


Benefit Highlights:

- 100% Paid Premiums:  Red Canary offers a 100% paid plan option for medical, dental and vision for you and your dependents. No waiting period.

- Health & Wellness - Access to mental health services, Employee Assistance Program and additional programs to incentivize healthy habits.  

- Fertility Benefits: All new hires are eligible for benefits as of their first day.

- Flexible Time Off: Take the time you need to recharge including vacation, sick, bereavement, jury duty, and holidays. 

- Paid Parental Leave- Full base pay to bond/care for your new child.

- Pre-Tax Plans - Red Canary offers a variety of plans to fit you and your dependent specific needs including FSA, HRA and HSA, with employer funding to offset out of pocket health care expenses. 

- Flexible Work Environment- With 60% remote workforce, Canaries can work virtually from almost anywhere in the US.


The application deadline is January 10th, 2025.


Why Red Canary?

Red Canary is where people embody our mission to improve security outcomes for all. People work hard to maintain a culture that encourages authenticity in order to do your best work. Our people are driven and committed to finding the best security outcomes, delivering real and actionable answers, and being transparent along the way. 


At Red Canary, we offer a very rich benefits program to our full-time team members so they can focus on their families and improving our customers’ security. For a full list of benefits, please review our Benefits Summary:

https://resource.redcanary.com/rs/003-YRU-314/images/RedCanary_2025BenefitsSummary.pdf?version=0


Individuals seeking employment at Red Canary are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Red Canary Glassdoor Company Review
3.7 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Red Canary DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Red Canary
Red Canary CEO photo
Brian Beyer
Approve of CEO

Average salary estimate

$106700 / YEARLY (est.)
min
max
$95400K
$118000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About XSIAM Detection Engineer, Red Canary

Join the dynamic team at Red Canary as an XSIAM Detection Engineer and play a vital role in our mission to keep organizations safe from cyber threats! Working remotely, you'll help craft and optimize security detection capabilities using Palo Alto's XSIAM platform. This isn't just a job; it's an opportunity to engage with the latest in cybersecurity technology to uncover and mitigate threats before they escalate. You'll investigate security alarms, tune advanced detectors, and even write scripts to automate solutions, all while collaborating with a passionate team dedicated to making a difference. With your hands-on experience in SIEM administration and cybersecurity content development, you'll be instrumental in providing our customers with actionable insights. The challenges you tackle daily will keep you on your toes as you adapt to a constantly evolving threat landscape. If you thrive on innovation, love working with cutting-edge tools, and are eager to dive into the world of cybersecurity, Red Canary is the perfect place for you to shine. Join us, and let's work together to empower organizations to focus on their missions without fear of cyber threats!

Frequently Asked Questions (FAQs) for XSIAM Detection Engineer Role at Red Canary
What are the key responsibilities of the XSIAM Detection Engineer at Red Canary?

As an XSIAM Detection Engineer at Red Canary, you'll play a crucial role in configuring the SIEM system for our clients, investigating security alarms, and writing scripts to automate solutions for detected threats. Your responsibilities will also include crafting and tuning advanced detectors and correlation rules to identify vulnerabilities in customer environments.

Join Rise to see the full answer
What qualifications are required for the XSIAM Detection Engineer position at Red Canary?

The ideal candidate for the XSIAM Detection Engineer role at Red Canary should have at least one year of experience in SIEM administration or a similar analysis role, alongside scripting and process automation expertise. You should also possess a solid understanding of network technologies and have systems administration experience with both Windows and Linux/UNIX-based systems.

Join Rise to see the full answer
What does the work environment look like for a Red Canary XSIAM Detection Engineer?

Working remotely as an XSIAM Detection Engineer at Red Canary means enjoying a flexible work environment where about 60% of the workforce operates virtually. This setup encourages collaboration while allowing you to maintain a work-life balance.

Join Rise to see the full answer
What kind of tools will the XSIAM Detection Engineer use at Red Canary?

In your role as an XSIAM Detection Engineer at Red Canary, you'll primarily use Palo Alto’s XSIAM platform for threat detection. Your work will involve leveraging various signal data sources to uncover potential threats, utilizing advanced scripting for automation, and actively contributing to the cybersecurity knowledge base within the team.

Join Rise to see the full answer
What benefits does Red Canary offer for the XSIAM Detection Engineer role?

Joining Red Canary as an XSIAM Detection Engineer comes with a comprehensive benefits package, including 100% paid premiums for medical, dental, and vision insurance, flexible time off, paid parental leave, and support for mental health services. You'll also have access to pre-tax plans to help manage healthcare costs, plus many more perks to support your well-being.

Join Rise to see the full answer
Common Interview Questions for XSIAM Detection Engineer
Can you describe your experience with SIEM tools in regard to the XSIAM Detection Engineer position?

When answering this question, highlight your hands-on experience with various SIEM tools, particularly Palo Alto's XSIAM platform if applicable. Describe specific tasks you performed, challenges faced, and how you contributed to enhancing security protocols in your previous roles.

Join Rise to see the full answer
How do you approach scripting for alert automation as an XSIAM Detection Engineer?

Discuss your familiarity with programming languages and scripting for automation. Provide examples of scripts you've written to enhance operational workflows or improve detection capabilities, emphasizing the impact of your work on incident response times.

Join Rise to see the full answer
What steps do you take to stay updated on new security threats and technologies?

Emphasize your commitment to continuous learning by mentioning resources you utilize, such as online courses, forums, and cybersecurity publications. Mention any relevant certifications, workshops, or conferences you attend to stay current in the field.

Join Rise to see the full answer
How do you prioritize tasks when responding to security incidents?

Explain your process for assessing the severity of incidents and how you allocate your time based on the potential impact. Provide an example of a situation where you successfully managed multiple incidents simultaneously.

Join Rise to see the full answer
Can you provide an example of a time you improved a detection system?

Detail a specific example where you successfully recognized a gap in a detection system and took initiative to enhance it. Describe the steps you took and the results achieved, demonstrating your proactive approach.

Join Rise to see the full answer
How do you handle a high-pressure situation when a significant security threat is detected?

Share your strategies for maintaining composure under pressure. Discuss your methods for tracking down the threat, coordinating with your team, and communicating essential information to stakeholders.

Join Rise to see the full answer
Describe your experience with network technologies pertaining to threat detection.

Talk about your understanding of networking protocols and technologies, along with real-world scenarios where you've applied that knowledge in detecting security threats or managing incidents.

Join Rise to see the full answer
What tools or methodologies do you propose for developing advanced detection capabilities?

Discuss any preferred tools or approaches, such as specific detection methodology frameworks or programming languages, and how they can enhance the detection capabilities of an XSIAM environment.

Join Rise to see the full answer
How would you explain a complex security issue to someone without a technical background?

Illustrate your communication skills by providing a clear, concise example of how you've simplified complex security topics in the past. Focus on the importance of using relatable analogies and avoiding technical jargon.

Join Rise to see the full answer
What do you perceive as the biggest challenges facing XSIAM Detection Engineers today?

Share insights into the evolving threat landscape, including trends such as sophisticated cyber-attacks. Discuss what you believe XSIAM Detection Engineers can do to stay ahead and adapt to these challenges.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Red Canary Remote No location specified
Posted 6 days ago
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Posted 4 days ago
Posted 12 hours ago
Photo of the Rise User
CoreSite Remote No location specified
Posted 7 days ago
Photo of the Rise User
Trails Remote Remote - United States
Posted 2 days ago
Photo of the Rise User
BCC Software Remote 1890 S Winton Rd, Rochester, NY 14618, USA
Posted 11 days ago

Red Canary was founded to make security for every business better by protecting organizations around the world from cyber threats. Our combination of market-defining technology, processes, and expertise delivered using an innovative SaaS model is ...

45 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 25, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!