A career in IBM Consulting is built on long-term client relationships and close collaboration worldwide. You’ll work with leading companies across industries, helping them shape their hybrid cloud and AI journeys. With support from our strategic partners, robust IBM technology, and Red Hat, you’ll have the tools to drive meaningful change and accelerate client impact. At IBM Consulting, curiosity fuels success. You’ll be encouraged to challenge the norm, explore new ideas, and create innovative solutions that deliver real results. Our culture of growth and empathy focuses on your long-term career development while valuing your unique skills and experiences.
- Act as the subject matter expert (SME) for Palo Alto Cortex XDR and endpoint security.
- Lead investigation and response for advanced endpoint threats and alerts using XDR.
- Develop and fine-tune detection rules, response playbooks, and behavioral indicators.
- Integrate Cortex XDR with other security tools (SIEM, SOAR, firewalls, etc.).
- Analyze complex threat patterns, perform root cause analysis, and recommend mitigation strategies.
- Collaborate with SOC teams to escalate, triage, and resolve endpoint incidents.
- Create and maintain technical documentation, runbooks, and training materials.
- Support compliance and audit requirements for endpoint security.
- Provide L3 support and mentor junior team members.
5+ years of experience in Cybersecurity or Information Security.
Minimum 2+ years hands-on experience specifically with Palo Alto Cortex XDR (endpoint or extended detection and response).
Strong knowledge of endpoint detection and response (EDR) technologies and incident handling.
Experience in scripting (Python, PowerShell) for automation is a plus.
Familiarity with security frameworks such as MITRE ATT&CK.
Experience in working with SIEM and SOAR platforms.
Excellent analytical, communication, and troubleshooting skills.
Certifications like PCNSE, CISSP, CEH, or GCIA are advantageous.
3 - 6
