SOC Cortex XSIAM Analyst
Indexed description
TCS is looking for a SOC Cortex XSIAM Analyst
Work modality: Hybrid
(Candidate needs to be located or relocate to Querétaro, CDMX, Guadalajara or Monterrey, it will be requested to attend office at least 3 day per week)
Role Purpose
The SOC Cortex XSIAM Analyst monitors, investigates, and responds to cybersecurity threats using Palo Alto Networks Cortex XSIAM within Customer's global iSOC. The role uses XDR, automation, threat intelligence, and structured incident response practices to identify, contain, and mitigate threats while improving the quality, consistency, and efficiency of security operations.
Experience and Behavioral Competencies
- Advance English communication
- 2-4 years of experience in SOC operations, XDR, SIEM, or Incident Response, with experience calibrated to role seniority.
- Practical Cortex XSIAM, Cortex XDR, or closely related Palo Alto security operations experience is strongly preferred.
- Strong analytical thinking, disciplined documentation, customer focus, ownership, and attention to detail.
- Clear written and verbal communication, collaboration across global teams, and composure during high-severity incidents.
- Ability and willingness to work within an approved 24x7 rotational shift model.
Fundamental and Required Technical Skills
- Hands-on security monitoring and incident investigation using Cortex XSIAM, Cortex XDR, or comparable enterprise XDR technology.
- Understanding of SIEM/XDR concepts, alert triage, event correlation, investigation timelines, and evidence handling.
- Working knowledge of MITRE ATT&CK and a structured Incident Response lifecycle; familiarity with NIST 800-61 is preferred.
- Foundational knowledge of TCP/IP, DNS, HTTP/S, email security, firewalls, proxies, VPNs, and common network attack patterns.
- Working knowledge of Windows, Linux, Active Directory, endpoint telemetry, authentication events, and privilege-related threats.
- Experience creating and maintaining high-quality incident records in ServiceNow or a comparable ITSM platform.
- Awareness of cloud security monitoring concepts across Azure, AWS, or GCP environments.
Core Operational Responsibilities
- Perform continuous monitoring of security alerts, incidents, and events through Cortex XSIAM.
- Analyze and correlate security telemetry from endpoints, networks, cloud platforms, identity services, and integrated security tools.
- Triage alerts, determine validity, scope, business impact, and severity, and document the investigation rationale.
- Reduce false positives by identifying tuning opportunities and providing evidence-based recommendations to the engineering team.
- Escalate incidents to L2/L3, Major Incident Management, or other resolver groups according to playbooks and escalation matrices.
- Execute approved containment or response actions, including automated actions where authorized by the applicable playbook.
- Maintain accurate incident records, investigation notes, evidence, timestamps, ownership, and handover details in ServiceNow.
- Provide clear shift handovers and support follow-the-sun continuity across global delivery locations.
What we offer to you:
- Direct contract (indeterminate time with initial probation period)
- Full payroll scheme
- Benefits of the law and above
Tata Consultancy Services is an equal opportunity employer, our commitment to diversity & inclusion drives our efforts to provide equal opportunity to all candidates who meet our required knowledge & competency needs, irrespective of any socio-economic background, race, color, national origin, religion, sex, gender identity/expression , age, marital status, disability, sexual orientation or any others. We encourage anyone interested to build a career in TCS to participate in our recruitment & selection process.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search