Enter a job title or keyword

Principal Security Platforms Engineer (XSIAM)

Redherd.io


Job Location:

Cape Town - South Africa

Monthly Salary: Not provided by the employer
Posted: 7 October 2026 (Yesterday)
Application Deadline: 4 January 2027
Vacancies: 1 Vacancy

Job Summary

Principal Security Platforms Engineer

Job Category: Cyber Security Engineering And Architecture
Location: South Africa - (CPT JHB DBN PE)

About Redherd

Redherd is a specialist technical cyber security recruitment business connecting security professionals with organisations seeking deep technical expertise.

About The Client

Our client is a managed security services provider supporting complex customer environments. Its security engineering teams build and maintain the platforms underpinning security monitoring threat detection and incident response.

Role Overview

Our client is seeking a Principal Security Platforms Engineer to provide technical leadership across Palo Alto Networks Cortex XSIAM and the wider security platform ecosystem.

This is a hands-on role combining security architecture platform engineering detection engineering and automation. You will help shape platform development improve customer onboarding and telemetry quality strengthen detection capabilities and support automation and Agentic AI initiatives.

You will also act as a senior technical escalation point and mentor to platform engineers detection engineers and SOC analysts.

Key Responsibilities

  • Support the architecture roadmap and ongoing development of Cortex XSIAM and associated security platforms.

  • Design and maintain multi-tenant service architectures supporting managed security customers.

  • Lead architecture reviews and recommend improvements to scalability performance resilience and cost.

  • Engineer customer onboarding and telemetry ingestion parsing and normalisation across security and cloud technologies.

  • Build and improve platform integrations automation workflows and new SOC service capabilities.

  • Support platform upgrades feature adoption and the evaluation of emerging capabilities including Agentic AI.

  • Develop and maintain XQL queries detection logic and security use cases.

  • Guide correlation rules suppression rules alert tuning and threat intelligence integrations.

  • Improve detection coverage against MITRE ATT&CK and reduce false positives using threat trends and SOC feedback.

  • Provide L4 escalation support for platform disruptions ingestion failures automation failures and detection gaps.

  • Work directly with vendor support and engineering teams to resolve complex technical issues.

  • Translate customer requirements into practical security monitoring strategies.

  • Maintain platform standards engineering procedures integration guides and operational documentation.

  • Mentor engineering and SOC teams and promote consistent technical practices.

Required Experience And Skills

  • 10 years of experience in cyber security engineering security operations or security architecture.

  • 2 years of hands-on experience with Palo Alto Networks Cortex XSIAM and/or Cortex XDR.

  • Experience supporting MSSP or enterprise SOC environments.

  • Strong understanding of SIEM SOAR EDR/XDR threat intelligence vulnerability management and modern SOC practices.

  • Practical experience onboarding and normalising security telemetry developing XQL queries and building correlation rules and detection content.

  • Experience with automation orchestration REST APIs Broker VMs and cloud-native integrations.

  • Scripting experience using Python or PowerShell alongside working knowledge of KQL and XQL.

  • Strong understanding of MITRE ATT&CK security event correlation and detection engineering.

  • Cloud security experience across Azure AWS and GCP.

  • Strong knowledge of network protocols Linux Windows and cloud infrastructure.

  • Experience troubleshooting large-scale platform and ingestion issues and working with security vendors.

  • Strong communication consulting stakeholder engagement and mentoring skills.

  • The ability to independently drive complex technical initiatives.

Qualifications And Certifications

  • Bachelors degree in Information Technology Cyber Security Computer Science or a related field.

  • Relevant cloud security certifications across Azure AWS or GCP.

  • Palo Alto Networks Cortex XSIAM Engineer certification is advantageous.

  • CISSP CISM CCSP or equivalent security certifications are preferred.