Palo Alto Cortex XSIAM and XDR platform engineer W-2 ONLY at United Global Technologies
Columbia, SC
$166,400–$187,200
Jul 14, 2026
Columbia, SC
Jul 21, 2026
What this job asks for AI summary
A remote, W-2 engineer role focused on building and sustaining enterprise SIEM and extended detection and response capabilities — primarily on Palo Alto Cortex XSIAM and Cortex XDR — across a multi-tenant, multi-agency security operations environment. Day-to-day work spans platform engineering, detection development, log pipeline management via CRIBL, playbook automation, and direct support of SOC analysts across all tiers, including participation in a 24x7 on-call rotation.
Senior level · 5+ years · Remote · Contract
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 18,300 people nationally plausibly meet what this posting asks for (information security analysts). range 5,400–27,400
Applicant volume Heavy — This req sits in a large pool with little in its requirements to thin it, and auto-apply tools fire at everything in the occupation. Applying early and leading with the rare skills below is what gets read.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (12)
The posting is W-2 only (no subcontractors, no sponsorship), indicating a contract/staff-augmentation engagement rather than a direct full-time hire — classified as Contract accordingly.
The degree requirement (Bachelor's in IT/Information Security) is waivable with 8+ years of relevant experience, so the degree requirement is set to None.
The role sits at the intersection of security engineering (SIEM/XDR platform build-out) and security operations (SOC support, incident response), making 15-1212 the best fit; 15-1299 is the runner-up given the heavy platform-engineering and automation workload.
Python and Bash are listed together as interchangeable scripting options for automation/playbook development; Python is named first and carries the requirement, with Bash in alternatives.
CISSP, Security+, and GIAC are listed under Preferred Skills as certification options — treated as a single preferred requirement with alternatives.
Palo Alto Cortex/CRIBL certifications are listed under Preferred Skills and are optional.
Detection engineering is retained as a skill because it refers to a concrete, named discipline (writing correlation rules, analytics, threat-hunting queries) that functions as a gating capability in this role, not a generic soft skill or methodology.
No compensation figures are provided in the posting.
Caller instruction confirmed: remote=true, no metro inferred.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Palo Alto Cortex XSIAM, detection engineering.
Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.