Role Overview
We are seeking an experienced Cortex XDR Administrator to join our cybersecurity team. The ideal candidate will have strong expertise in deploying, configuring, and managing Palo Alto Networks Cortex XDR/EDR solutions, along with a solid background in incident detection, response, and security integrations. This role requires hands-on experience with threat detection technologies and the ability to collaborate across IT, SOC, and DevOps teams to strengthen the organizations security posture.
Key Responsibilities
Administer and manage EDR tool preferably Cortex XDR , including configuration, integration, and troubleshooting.
Monitor security events and alerts from Cortex and other platforms to detect, investigate, and respond to threats.
Perform incident response activities including triage, containment, forensic analysis, eradication, and recovery.
Develop and implement use cases, playbooks, and response workflows to improve SOC effectiveness.
Collaborate with cross-functional teams to investigate security issues and recommend remediation.
Produce incident reports, root cause analysis, and maintain proper documentation of security events.
Stay updated on emerging cyber threats, attack techniques, and defensive capabilities.
Required Skills & Experience
4 - 8 years of experience in administering and managing Cortex XDR or any other EDR tool is a must.
Strong background in incident response within a SOC environment.
Proficiency in analyzing logs, alerts, and events from multiple security tools (SIEM, EDR, IDS/IPS, firewalls, etc.).
Familiarity with malware analysis, endpoint security, and threat hunting methodologies.
Strong knowledge of networking concepts (TCP/IP, DNS, HTTP, VPNs).
Ability to handle escalated security incidents and work under pressure.
Good communication skills to collaborate with technical and non-technical teams.