yoinka

Sr MSIAM SOC Engineer (Unit 42)

Palo Alto Networks

Office - Israel - Tel AvivSeniorH-1B sponsor company
Sign in to applyVerified 1h ago
Location
Office - Israel - Tel Aviv
Work model
On-Site
Level
Senior
H-1B history
168 approvals (FY2023)
Posted
Sep 17, 2026

Skills

CybersecurityPython

About this role

Our Mission

At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.

Who We Are

In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us! We believe collaboration thrives in person. That’s why most of our teams work from the office full time, with flexibility when it’s needed. This model supports real-time problem-solving, stronger relationships, and the kind of precision that drives great outcomes.

Job Summary

As a Senior SOC Engineer within Unit 42 at Palo Alto Networks, you will drive the creation, validation, and optimization of custom detection rules and automated playbooks across our global customer base. Acting as a trusted advisor, you will collaborate closely with clients to maximize their security posture using Cortex XSIAM and Unit 42 expertise. This highly analytical role leverages your deep understanding of detection lifecycles, proactive automation, and threat intelligence to secure enterprise environments. You will architect end-to-end security lifecycles that seamlessly connect data ingestion with high-fidelity detection engineering.

Key Responsibilities

Own the full lifecycle of custom detections and response automations, deploying them as high-fidelity Cortex XSIAM correlation rules and playbooks through a rigorous engineering process of development, testing, staging, and soft implementation. Drive the continuous refinement of correlation rules to ensure strict standards for performance, accuracy, and operational relevance. Translate Unit 42 threat intelligence research and emerging adversary TTPs into actionable, robust detection logic. Champion proactive automation by engineering sophisticated playbooks to resolve emerging security challenges and optimize operational workflows ahead of demand. Architect the end-to-end security lifecycle within Cortex XSIAM, seamlessly connecting data ingestion, high-fidelity detection engineering, and sophisticated response automation.

Qualifications

Required Qualifications 5+ years of hands-on experience in a Senior SOC, Detection Engineering, or Security Architecture role utilizing SIEMs, firewalls, EDR, sandboxes, and SOAR platforms in complex enterprise environments. Proven mastery of the Detection Engineering lifecycle, including experience with rule testing frameworks, soft-deployment strategies, and continuous tuning. Demonstrated experience reviewing and QA-ing detection logic written by others, with the ability to provide constructive optimization feedback. Exceptional consultative and communication skills, with the confidence to guide enterprise customers through complex architectural and workflow decisions. Proactive engineering mindset with a track record of designing complex automation playbooks (Cortex XSOAR or similar) based on anticipated threat vectors, not just reactive requests. Strong background in incident response, threat hunting, and translating threat intelligence into actionable defense mechanisms. Software development experience with a strong proficiency in Python for security automation and scripting.

Preferred Qualifications

Previous hands-on experience utilizing and optimizing Cortex XSIAM. Our Commitment We’re trailblazers that

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Sr MSIAM SOC Engineer (Unit 42) at Palo Alto Networks, Office - Israel - Tel Aviv | Yoinka