SIEM/ SOAR Engineer
The engineer will deploy, manage, and optimize the Cortex XSIAM environment while integrating logs and telemetry from various platforms. They are also responsible for developing detection rules, building automated playbooks, and maintaining system documentation.
- On-site
- Montréal, QC
- Posted Mar 19, 2026
- 1 position
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Job summary
Summary: We are seeking an experienced Cortex XSIAM Engineer to join our cybersecurity team. This role is pivotal in deploying, managing, and optimizing our Cortex XSIAM environment to enhance our security operations. The ideal candidate will have a strong background in cybersecurity analytics and be adept at using Palo Alto Networks technologies. Responsibilities: Deploy, configure, and manage Cortex XSIAM, focusing on data lake, analytics, and automation. Onboard and integrate logs and telemetry from various platforms including Cortex XDR, NGFW, Prisma Cloud, O365, AWS, Azure, GCP, Okta, and CrowdStrike. Ensure data quality, ingestion health, and system performance are maintained. Develop and fine-tune XQL detections, correlation rules, and behavioral analytics in alignment with MITRE ATT&CK framework. Build and enhance Cortex XSOAR playbooks and automated workflows for robust automation and integration. Integrate new APIs and security tools into the XSIAM ecosystem. Create dashboards and reports to demonstrate detection coverage, rule performance, and platform health. Maintain comprehensive documentation including runbooks, diagrams, and engineering documentation. Required Skills: 5–9 years of experience in SOC engineering, SIEM/SOAR, or cybersecurity analytics. At least 2 years of hands-on experience with Palo Alto Cortex XSIAM, including deployment, detections, and onboarding. Strong knowledge of SIEM pipelines, event correlation, and log normalization. Expertise in XQL, Python, JSON, and REST APIs. Good understanding of cloud telemetry and modern SOC technologies like XDR, UEBA, EDR, WAF, and CASB. Relevant certifications such as PCDRE, PCSAE, PCNSE, GCDA, or other GIAC certifications are preferred. AT SIA Innovations, we offer more than just a job, we offer the opportunity to be part of a diversified team! We provide a collaborative and innovative work environment, also the opportunity for professional growth. SIA Innovations adheres to the principles of equal employment. All qualified applications will be given careful consideration without regards to ethnicity, color, religion, gender, sexual orientation or identity, nation origin, age, disability or any other characteristic protected by law.
What you’ll do
The engineer will deploy, manage, and optimize the Cortex XSIAM environment while integrating logs and telemetry from various platforms. They are also responsible for developing detection rules, building automated playbooks, and maintaining system documentation.
Requirements
Candidates must have 5-9 years of experience in SOC engineering or cybersecurity analytics, with at least 2 years specifically in Palo Alto Cortex XSIAM. Proficiency in XQL, Python, and REST APIs is required, along with a strong understanding of SIEM pipelines and modern security technologies.
Benefits
• Collaborative work environment • Innovative work environment • Professional growth opportunities
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cortex XSIAM
- Cortex XSOAR
- Cybersecurity analytics
- SIEM
- SOAR
- XQL
- Python
- JSON
- REST APIs
- Log normalization
- Event correlation
- MITRE ATT&CK
- Cloud telemetry
- XDR
- UEBA
- EDR
Job areas
- Security & Safety
- Technology
- Software
- Data & Analytics
- Engineering
Additional details
- Minimum education
- Professional degree
- Minimum experience
- 5+ years
- Posting language
- English
- Working hours
- 40 hours per week
