Job Description Your Career As a Principal Professional Services Architect for Cortex XSIAM, you will serve as a senior technical and strategic leader, bridging complex service delivery with long-term customer success outcomes. In this hybrid role, you will spend your time delivering billable engagements such as data onboarding, correlation engineering, and automation design. You would partner with customers as their strategic advisor and architect, driving platform adoption, maturity, and measurable security outcomes. You'll engage with CISOs, SOC leaders, and security engineering teams at some of our largest and most strategic customers to design scalable ingestion architectures, help customers evolve their detection strategy, and partner with them on SOC transformation initiatives. Your work will focus on co-creating solutions with customers — refining existing processes, aligning them with XSIAM capabilities, and providing best-practice recommendations to accelerate adoption and value realization. Your Impact Billable Engagements (~45%) Architect and deliver data ingestion pipelines, ensuring telemetry from diverse sources (endpoint, network, cloud, identity) is normalized, high-quality, and aligned with best practices Design and implement custom correlation logic detections to address customer-specific use cases, leveraging platform capabilities and reference content — not building detections from scratch Advise on detection strategies by mapping customer threat models and operational needs to actionable detection use cases, ensuring alignment with Cortex's research-driven detection content Review, refine, and recommend improvements to existing incident response workflows and automation playbooks, aligning them with XSIAM capabilities and industry best practices while respecting established customer processes Mentor and enable customer SOC teams on alert triage optimization, enrichment strategies, and continuous detection tuning Produce and deliver technical documentation, architecture diagrams, runbooks, and operational guides that support ongoing SOC operations Conduct workshops and hands-on sessions to transfer knowledge and upskill customer teams on the effective use of XSIAM. Principal Customer Success Architect (~55%) Serve as a trusted advisor to CISOs, SOC Directors, and security engineering leaders, shaping their long-term XSIAM adoption strategy and architecture roadmap Lead architecture design sessions, maturity assessments, and strategic workshops to translate business objectives into actionable technical plans Design and deliver reference architectures, best-practice frameworks, and operational blueprints in collaboration with customer teams, enabling them to evolve and sustain their SOC capabilities Provide strategic recommendations to enhance SOC maturity, including ingestion strategies, detection priorities, automation approaches, and operational workflows Identify opportunities for optimization, automation, and expansion within the customer environment, guiding them toward continuous improvement and advanced use of XSIAM features Act as the technical escalation point and strategic liaison across customer, product, and internal engineering teams to ensure platform adoption and success metrics are achieved Capture and relay customer feedback to internal product and engineering teams, influencing roadmap priorities and feature evolution.