Skip to main content
AfterDuty

Cortex XSIAM SME / Engineer

Showtime Consulting · Canberra, Australian Capital Territory

Type
Full-time
Posted
8 days ago

Overview

Your investigative judgement and digital forensics discipline support detection rule development and incident response.

About this role

Company Description

Showtime Consulting is a leading provider of Shielded Cloud and Digital Solutions across Australia and New Zealand. We specialise in delivering secure, enterprise-scale technology solutions across cloud, infrastructure, cybersecurity, DevSecOps, software engineering, and digital transformation programs.

We partner with government and enterprise organisations to build high-performing technology teams that deliver secure, resilient, and scalable solutions within complex and highly regulated environments.

The Role

We are seeking an experienced Cortex XSIAM SME / Engineer to join a cybersecurity team delivering advanced security operations and threat detection capabilities.

This role will focus on the deployment, configuration, integration, and optimisation of Cortex XSIAM environments. You will work closely with security operations teams, cloud engineers, and stakeholders to onboard data sources, develop detection capabilities, automate security workflows, and improve overall visibility across enterprise environments.

Key Responsibilities

Deploy and configure Cortex XSIAM environments and supporting architecture.

Establish tenant configurations and cloud infrastructure connectivity.

Deploy Cortex XDR agents across endpoints, servers, and enterprise environments.

Onboard third-party logs, security events, network telemetry, and cloud data sources.

Develop and optimise detection rules, analytics, alerts, and correlation logic.

Build and maintain XQL queries to support threat detection and investigations.

Design and implement automated playbooks using Cortex XSOAR.

Integrate XSIAM with SIEM platforms, ticketing systems, and threat intelligence services.

Monitor platform health and troubleshoot data ingestion, agent, and detection issues.

Reduce false positives and improve alert quality across security operations.

Support incident investigation, security monitoring, and operational improvement initiatives.

Collaborate with internal stakeholders to improve security visibility and response capabilities.

Document technical solutions, configurations, and operational procedures.

What You'll Need

Experience within SIEM, SOC, XDR, or security operations environments.

Hands-on experience implementing and configuring Cortex XSIAM solutions.

Strong experience with Cortex XDR deployments and endpoint onboarding.

Proficiency with Cortex XSOAR is essential.

Strong knowledge of log parsing, regular expressions, and data normalisation.

Experience developing and optimising XQL queries.

Experience onboarding logs, telemetry, and cloud-native security data sources.

Knowledge of AWS, Azure, or Google Cloud security logging and monitoring is highly regarded.

Strong understanding of network security concepts including TCP/IP, DNS, firewalls, and proxy logs.

Experience integrating security platforms with enterprise tooling is advantageous.

Experience with automation and orchestration within security operations environments is highly desirable.

Knowledge of incident response methodologies and security operations processes is highly regarded.

Palo Alto Networks Cortex XSIAM Analyst or Engineer certifications are advantageous.

Strong analytical, troubleshooting, and problem-solving skills.

Excellent communication and stakeholder engagement abilities.

Why Join Us?

Work on leading-edge security operations and threat detection platforms.

Play a key role in Cortex XSIAM and XSOAR implementation initiatives.

Gain exposure to cloud security, automation, threat intelligence, and incident response.

Collaborate with experienced cybersecurity and engineering professionals.

Contribute to the modernisation of enterprise security operations capabilities.

Join a consulting culture focused on innovation, security, and technical excellence.

Apply for this role

First Name

Last Name

Email

Phone

Mobile

Clearance Level

Select

Baseline

NV1

NV2

TSPV

Do you currently live in Australia?

Select

Yes

No

This role is only available for Australian residents only.

Future Opportunities

Select

Yes

No

Cover Letter Option

Write Cover Note

Upload Cover Letter File

Cover Note

Upload Cover Letter (PDF / DOC / DOCX)

Resume (PDF / DOC / DOCX)

Submit ApplicationCancel

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Canberra

Why this fits a police background

  • Police experience explicitly valued
  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Security operations

More cyber security & digital forensics jobs for ex-police

  • GRC and Advisory Consultant

    DXC Technology · Canberra

    Full-time

    Job Description DXC Technology (NYSE: DXC) is a leading enterprise technology and innovation partner delivering software, services, and solutions to global enterprises and public sector organisations — helping them harness AI to drive outcomes at a time of exponential change with speed.

    Posted 5 days ago

  • Senior Cyber Security Governance Analyst

    radk tech pty ltd · Canberra

    Contract

    Your analytical discipline and experience with strict frameworks (e.g., PACE, CPIA) map well to governance and compliance in cyber security.

    Posted 6 days ago

  • Full-time

    Our Mission At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts.

    Posted 7 days ago

  • ICT Security Analyst

    Fujitsu · Canberra

    Full-time

    Your incident response and investigative skills from policing translate directly to managing security incidents and access controls.

    Posted 8 days ago