SIEM Subject Matter Expert (Palo Alto Networks Cortex XSIAM) - Contract

Contract Type:

Location:

Sydney - NSW 

Industry:

IT

Category:

Consultant

Contact Name:

Emily

Contact Email:

emily.cawley@pra.com.au

Date Published:

07-Sep-2026

About the Role
 
3 Month Contract 
Sydney 

Our client is seeking an experienced SIEM Subject Matter Expert with deep Palo Alto Networks Cortex XSIAM expertise for an initial 3-month contract engagement with strong potential for extension.
 
In this hands-on delivery role, you will take end-to-end ownership of the enterprise SIEM data pipeline, from log source onboarding, parsing and normalisation through to telemetry enrichment, alert fidelity tuning and platform health management. Combining deep technical capability with an automation mindset, you'll streamline how new data sources are connected to ensure security analysts have complete, high-quality context directly within the platform.
 
Key Responsibilities
  • Log Source Onboarding: Onboard diverse enterprise log sources, leading log parsing, field extraction, data modelling and normalisation to common information models
  • Automation & Tooling: Design, build and maintain automated onboarding tooling (via scripting, APIs or native capabilities) to reduce manual effort and accelerate data connection times
  • Telemetry Enrichment: Manage enrichment pipelines that append critical context (asset ownership, identity, business criticality and threat intelligence) to raw log events, eliminating the need for analysts to pivot between tools
  • Detection & Alert Tuning: Fine-tune SIEM configurations and detection content to measurably reduce false positives and elevate overall signal quality
  • Platform Lifecycle Management: Proactively oversee SIEM platform health, performance monitoring, capacity management, connector/collector maintenance and platform upgrades
Core Requirements
  • Demonstrated hands-on experience with Palo Alto Networks Cortex XSIAM, including log ingestion using Broker VMs, XDR Collectors and custom ingestion methods
  • Proven capability developing SIEM data models, field mapping, enrichment and schema standardisation across varied enterprise data feeds
  • Experience leveraging scripting, APIs or native tools to automate log source onboarding workflows
  • Strong proficiency in regular expressions (Regex), JSON parsing, structured log analysis and telemetry enrichment
  • Track record of optimising detection content to reduce false positives and managing capacity, performance and collector maintenance
  • Must be based in Sydney (or able to work hybrid onsite) and hold full, unrestricted Australian working rights
Desirable Skills
  • Palo Alto Networks certifications (e.g. PCSAE or equivalent Cortex credentials)
  • Proficiency in XQL or similar log query languages
  • Familiarity with the MITRE ATT&CK framework
  • Exposure to adjacent SIEM technologies (e.g. Splunk, Microsoft Sentinel, IBM QRadar)
  • Prior background working within an enterprise SOC, MSSP or complex security operations environment
APPLY NOW
APPLY NOW
Apply With Button

Share this job

Interested in this job?
Save Job
Create As Alert

Similar Jobs

SCHEMA MARKUP ( This text will only show on the editor. )