Full-Time

Cortex Platform Engineer

AHEAD

AHEAD

11-50 employees

Telehealth-based provider for remote mental health

No salary listed

Hyderabad, Telangana, India

Hybrid

Hybrid role requiring on-site presence in Hyderabad, India.

Category
DevOps & Infrastructure (1)
Required Skills
Prisma
PowerShell
Bash
Microsoft Azure
Python
AWS
Splunk
Linux/Unix
Google Cloud Platform
Requirements
  • 5+ years of hands-on cybersecurity experience in SOC engineering, security operations, or endpoint/cloud security roles
  • 3+ years of direct, production experience operating Cortex XDR at enterprise scale — lab-only experience does not meet this requirement
  • Demonstrated experience with at least two additional Cortex platform components (XSOAR, XSIAM, Cortex Cloud, or Prisma Access) in a production environment
  • Proven ability to write and optimize XQL queries for threat hunting, detection tuning, and forensic investigation
  • Hands-on experience with XSOAR playbook development and integration pack management
  • Working knowledge of at least one SIEM platform (Splunk, Sentinel, or QRadar) with integration experience
  • Strong understanding of Windows, macOS, and Linux internals as they relate to endpoint telemetry, process execution, and persistence mechanisms
  • Solid grasp of the MITRE ATT&CK framework with the ability to map detections to specific techniques and sub-techniques
  • Familiarity with cloud security fundamentals across AWS, Azure, or GCP — IAM, workload security, network segmentation, and logging
  • Understanding of SASE principles, zero-trust network access concepts, and secure remote access architectures
  • Scripting competency in Python, PowerShell, or Bash for automation, log parsing, and platform integration development
  • Palo Alto Networks Certified Detection and Response Analyst (PCDRA) — strongly preferred; expected within 90 days of hire if not already held
  • Palo Alto Networks Certified Network Security Engineer (PCNSE) — advantageous
  • Palo Alto Networks Certified Security Automation Engineer (PCSAE) for candidates with strong XSOAR focus
  • GIAC GCED, GCIH, or equivalent incident response certification
  • AWS, Azure, or GCP cloud security certifications (e.g., AWS Security Specialty, AZ-500, Google Professional Cloud Security Engineer)
Responsibilities
  • Own end-to-end deployment, configuration, and lifecycle management of Cortex XDR across Windows, macOS, and Linux endpoints at enterprise scale
  • Design and maintain agent policies, prevention profiles, and exclusion sets; manage multi-tenant or multi-instance architectures where applicable
  • Develop, tune, and maintain BIOC rules, custom correlation policies, and Behavioral Threat Protection (BTP) configurations to maximize signal fidelity and minimize analyst fatigue
  • Lead Tier 2/Tier 3 incident investigations using XDR’s causality analysis engine, storyline feature, and XQL-based threat hunting across endpoint, network, and cloud telemetry
  • Coordinate response actions including endpoint isolation, process termination, and file quarantine; produce post-incident reports for technical and executive audiences
  • Translate MITRE ATT&CK mappings and threat intelligence into actionable XDR detection logic; conduct regular alert reviews to identify tuning opportunities and coverage gaps
  • Build, maintain, and optimize XSOAR playbooks for automated triage, enrichment, containment, and response workflows tied to XDR and other platform alerts
  • Manage integration packs, custom scripts, and connector configurations to support bidirectional data flow between XSOAR and the broader security toolset
  • Collaborate with SOC analysts to identify high-value automation candidates, reducing manual toil and accelerating mean time to respond (MTTR)
  • Maintain playbook documentation, versioning, and testing standards to ensure operational reliability
  • Support the deployment and configuration of Cortex XSIAM as the organization’s AI-driven SOC platform, including data source onboarding and ingestion pipeline management
  • Leverage XSIAM’s machine learning-driven alert correlation and incident scoring to reduce alert volume and prioritize analyst queues
  • Assist in defining and tuning XSIAM detection rules, analytics models, and dashboard views aligned to SOC operational requirements
  • Work with security leadership to evaluate XSIAM’s AI-generated insights and feed findings back into detection and response improvement cycles
  • Operate Cortex Cloud (CNAPP) to provide continuous visibility into cloud workload security posture across AWS, Azure, and GCP environments
  • Manage cloud workload protection policies, vulnerability findings, and compliance benchmarks; triage and escalate high-severity findings to cloud engineering teams
  • Integrate Cortex Cloud telemetry into XDR and XSIAM detection pipelines to extend threat visibility into cloud-native workloads and container environments
  • Support cloud security assessments and assist in developing guardrails and policy-as-code aligned to organizational security standards
  • Support the administration and operational maintenance of Prisma Access for secure remote access, branch connectivity, and SASE policy enforcement
  • Assist with policy configuration, user/tunnel management, and troubleshooting of Prisma Access deployments in coordination with network engineering
  • Integrate Prisma Access logs and telemetry into XDR and XSIAM for unified visibility across network and endpoint data sources
  • Participate in SASE architecture reviews and contribute security operations requirements to network and access design discussions
  • Architect and maintain integrations across the Cortex platform and adjacent tools including SIEM (Splunk, Sentinel, QRadar), ticketing systems, and identity providers
  • Maintain platform health across all Cortex components: version management, licensing, policy compliance, and coverage gap reporting
  • Define and track platform KPIs across detection effectiveness, automation rate, response time, and cloud posture; report to security leadership on a recurring cadence
  • Produce and maintain runbooks, architecture documentation, and knowledge base content for SOC and engineering team use
Desired Qualifications
  • Palo Alto Networks Certified Detection and Response Analyst (PCDRA) — strongly preferred; expected within 90 days of hire if not already held
  • Palo Alto Networks Certified Network Security Engineer (PCNSE) — advantageous
  • Palo Alto Networks Certified Security Automation Engineer (PCSAE) for candidates with strong XSOAR focus
  • GIAC GCED, GCIH, or equivalent incident response certification
  • AWS, Azure, or GCP cloud security certifications (e.g., AWS Security Specialty, AZ-500, Google Professional Cloud Security Engineer)
  • Hands-on XSIAM deployment or migration experience, particularly from legacy SIEM or XDR-only environments
  • Experience with Cortex Cloud’s CSPM, CWPP, or CDR capabilities in a multi-cloud environment
  • Familiarity with Prisma SD-WAN or broader Palo Alto Networks network security portfolio
  • Experience with threat intelligence platforms (MISP, ThreatConnect, Anomali) integrated into XSOAR or XSIAM workflows
  • Background in managed detection and response (MDR) or MSSP environments with multi-tenant platform management experience

Ahead provided telehealth mental health services to offer accessible, quality, and judgment-free care for individuals seeking emotional support or managing mental health emergencies. The service connected patients with mental health professionals remotely, removing geographical barriers and reducing stigma associated with visiting clinics. Revenue came from a fee-for-service model for consultations and treatments, with payments processed through a third-party processor to avoid storing personal or financial information. Aimed to make mental healthcare easier to access, Ahead focused on delivering remote consultations and ongoing clinical support during its operation. While the service closed to new patients in April 2022, its mission remains focused on expanding access to mental health care and reducing barriers to seeking help.

Company Size

11-50

Company Stage

Seed

Total Funding

$9M

Headquarters

San Francisco, California

Founded

2007

Simplify Jobs

Simplify's Take

What believers are saying

  • Strategic consulting and managed services boost enterprise digital transformation.
  • Berkshire Partners backing fuels growth in cloud and security practices.
  • $2.1 billion revenue from 2020 mergers strengthens market position.

What critics are saying

  • Accenture steals healthcare clients with 30% faster AI transformations in 6-12 months.
  • IBM captures manufacturing with 25% cost savings in 3-9 months.
  • AWS undercuts retail scalability 50% more efficiently in 6-12 months.

What makes AHEAD unique

  • AHEAD weaves cloud infrastructure, automation, and analytics for digital platforms.
  • Deep data center expertise since 2007 drives IT optimization for enterprises.
  • Acquisitions like Data Blue in 2019 expanded coast-to-coast footprint.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at AHEAD who can refer or advise you

Benefits

Health Insurance

401(k) Retirement Plan

Paid Vacation

Paid Sick Leave

Growth & Insights and Company News

Headcount

6 month growth

6%

1 year growth

6%

2 year growth

6%
PR Newswire
May 16th, 2025
Scale Computing Announces Winners Of The 3Rd Annual Scale Computing Platform Summit Awards

LAS VEGAS, May 16, 2025 /PRNewswire/ -- Scale Computing Platform Summit -- Scale Computing , a market leader in edge computing, virtualization, and hyperconverged solutions, today announced the winners of its 2025 Scale Computing Platform Summit Awards. Winners were honored yesterday at the Scale Computing Platform Summit (Platform//2025) conference, the company's flagship event for IT professionals and partners, at Resorts World Las Vegas.These prestigious awards celebrate the outstanding achievements of Scale Computing's partners, IT leaders, and technology alliances, who have driven innovation, collaboration, and success within the Scale Computing ecosystem."We are thrilled to celebrate the 2025 Scale Computing Platform Summit Awards winners and finalists. We're proud to recognize the individuals and organizations whose unwavering commitment to innovation, collaboration, and growth perfectly reflects the heart of Scale Computing. A huge thank you to our partners, customers, and industry colleagues for joining us in Las Vegas this year for Platform//2025 and making the event such a success. We're counting down the days until Platform//2026 in April of next year," said Jeff Ready, CEO and co-founder of Scale Computing.The 2025 Platform Summit Awards winners and finalists include:Partner AwardsOutstanding Partner MomentumConnectionFive Star Technology SolutionsInternational Data LinkLes Olson CompanyOtava (winner)Edge Pioneer Partner of the YearAHEAD (winner)ArctiqBC TechnologiesKME SystemsServix InformáticaScale Computing Partner of the Year – North AmericaComputer Integration TechnologiesFive Star Technology Solutions (winner)KT ConnectionsLink Computer CorporationX10 TechnologiesScale Computing Partner of the Year – InternationalDatec ( Fiji ) Pte Limited (winner)Holistec SystemsNetwork Attached Storage (UK) LimitedSC IT Solutions Ltd.Network Attached Storage (UK) LimitedDistribution Partner of the Year – North AmericaClimb Channel SolutionsIngram Micro (winner)TD SynnexDistribution Partner of the Year – InternationalADN Advanced Digital Network Distribution AGCMS Distribution LtdTarsus DistributionTitan Data Solutions (winner)WiCom NetworksMSP LeadershipAscent Data (winner)Beck Computer SystemsMLBARBS ManagedSac Valley ITMVP SalesChris Keefer , Link Computer Corporation (winner)Dana Johnson , EOS Systems, EOS Systems Greg Simmons , Five Star Technology Solutions, Five Star Technology Solutions Jon Moore , ET Works, ET Works Wolfgang Zugarav, Boston Server & Storage Solutions GmbHMVP TechnicalGerry Solis , TurnKey Solutions, TurnKey Solutions Matt Gaudu , International Data Link (winner)Patrick Ware , Oriso Solutions, Oriso Solutions Steve Neverve , Nevtec, Nevtec Tim Green , QuadbridgeCustomer AwardsIT Leadership in EdgeAdrian Alb, SeaspanBen Corlett , Northern Marine, Northern Marine Jack Jenkins , Navigator Gas, Navigator Gas Jesse Wolcott & Jake Diana , Royal Farms (winner)Steve Henshaw , In N Out BurgersIT Leadership in Data CenterBreedon Aggregates (winner)Brado Logistics S.A.Cape RadiologyLanetco Computer Networks Inc.Oriso SolutionsTech LeadershipFrancois Michaud , Oriso Solutions, Oriso Solutions Frédéric Masson, UPCONSCALE (winner)Rahul Narsimhan , Hive Radar, Hive Radar Scott Ewing , Pelion IOT LtdMarketing InnovatorEdge on the Road, ET WorksLinkUp, Link Computer CorporationScale Computing BMW i3, Holistec (winner)Starnet Deadpool Premier EventPartnership ExcellenceEatonLenovo (winner)Mako NetworksParallelsSimply NUCScale Computing Customer Heroes Advocating Market Performance (CHAMP) – PartnerBrandon Brady , SHI, SHI Dana Johnson , EOS Systems, EOS Systems Darren Crann, SC IT Solutions LtdJeff Kirkton , CDW, CDW Josh Moore , Eleveity, Eleveity Mark Essayian , KME Systems, KME Systems Nathan Davidson , Five Star Technology Solutions, Five Star Technology Solutions Rodd Ahrenstorff, KT ConnectionsSteve Neverve , Nevtec, Nevtec Tim Morder , Link ComputersScale Computing Customer Heroes Advocating Market Performance (CHAMP) – CustomerBen Corlett , Northern Marine, Northern Marine Jake Diana , Royal Farms, Royal Farms Jesse Wolcott , Royal Farms, Royal Farms John Stuplich , Kolbe & Kolbe Millwork Co Inc, Kolbe & Kolbe Millwork Co Inc Josh Moreth , Interface, Interface Lee Hopley , Breedon Aggregates, Breedon Aggregates Shane Rogers , Harrison Steel Castings, Harrison Steel Castings Steven Henshaw , In-N-Out, In-N-Out Tevon McKenzie , In-N-Out, In-N-Out Wally Wheadon , Ventura FoodsPlatform//2025 featured live educational and best practices sessions, dedicated networking opportunities, the Platform//2025 Awards Dinner, and training and certification opportunities. Exemplifying this year's theme, "Let's innovate and transform together," panel discussions and presentations centered around innovations in virtualization technology, edge computing, hybrid cloud, AI, automation, data security, and more.Sponsors of Platform//2025 included Simply NUC , Mako Networks , AHEAD , Otava , Lenovo , Veeam , Kaseya , Eaton , 10ZiG , Acronis , Parallels , Bitdefender , The Functionary , Sidero , Ingram Micro , Rose Hulman Institute of Technology , OpenText , Unicom Engineering , Velasea , Oriso , Leostream , TD Synnex , Climb Channel Solutions , and Titan Data Solutions.To learn more about Scale Computing or how you can participate in next year's 2026 Scale Computing Platform Summit next April in Las Vegas, please email [email protected]

PR Newswire
Mar 19th, 2025
Ahead Named Nvidia 2025 Rising Star Partner Of The Year

CHICAGO, March 19, 2025 /PRNewswire/ -- AHEAD, a leading provider of AI solutions, announced it has been selected by NVIDIA for the 2025 Americas NPN Rising Star Partner of the Year Award.The award recognizes AHEAD's technical expertise in implementing NVIDIA AI solutions across enterprise environments.AHEAD accelerates enterprise AI adoption and value creation by bridging the gap between infrastructure capabilities and data engineering, supporting customers with the most critical requirements and use cases.Its infrastructure teams design, install and support custom NVIDIA accelerated solutions across public clouds, data centers and edge. AHEAD's AI Operating Model encompasses use case development, planning, data readiness, value extraction, data and infrastructure engineering, model selection and optimization along with managed services across the entire technology stack.This integrated approach, underscored by deep experience with application integration, automation and security, creates an AI-powered ecosystem that helps businesses quickly develop and implement AI strategies.The NVIDIA NPN Program provides partners with the expertise required to develop, deploy and maintain world-class accelerated computing solutions designed for today's most demanding machine learning and AI workloads."Recognition as an NVIDIA Rising Star validates AHEAD's commitment to accelerating business value with AI," said Tom Koppelman, vice president of Sales Strategy and Alliances at AHEAD. "Being part of the NVIDIA Partner Network has been instrumental in this journey, providing comprehensive training, certification pathways and collaboration with NVIDIA engineering expertise to better serve clients.""AI is transforming how businesses operate, enabling them to drive innovation and evolution across industries," said Craig Weinstein, vice president of the Americas Partner Organization at NVIDIA. "AHEAD is recognized as the NPN Americas Rising Star Partner of the Year for its leadership in enterprise AI adoption with its AI Operating Model, installing and supporting NVIDIA accelerated solutions from public clouds to on-premise enterprise data centers."The Rising Star award follows AHEAD's recent announcement of a new rack-scale integration facility, designed to meet the increasing demands of AI and high-performance computing workloads.Visit ahead.com/partner/nvidia/ for more information on AHEAD's partnership with NVIDIA.About AHEADWe build integrated platforms, digital backbones that power the most successful organizations in the world. Our consultative approach, technical expertise and innovative solutions combine to accelerate the impact of technology in every client we serve.SOURCE AHEAD

PR Newswire
Feb 10th, 2025
Ahead Among Elite 150 On Crn'S Msp 500 List For 2025

CHICAGO, Feb. 10, 2025 /PRNewswire/ -- AHEAD, a leading provider of enterprise cloud solutions, announced today that CRN®, a brand of The Channel Company, has recognized the company on its Managed Service Provider (MSP) 500 list in the Elite 150 category for 2025.CRN's annual MSP 500 list is a comprehensive guide to the leading MSPs in North America. These companies deliver essential managed services that enhance business efficiency, simplify IT, and optimize return on technology investments for their customers. The list showcases and celebrates MSPs that are driving growth and innovation. These solution providers empower businesses with complex technologies so they can achieve their business goals without stretching financial resources.AHEAD's comprehensive Managed Services portfolio spans Infrastructure, Cloud and DevOps, ServiceNow® and Security. Its Managed Services teams provide predictable operating costs, reduced risk, and the flexibility to meet unforeseen business obstacles.The company's Hybrid Infrastructure Managed Services offering was recently recognized as a Customers' Choice in a 2024 Gartner® Peer Insights™ Report

Hit Consultant
Dec 23rd, 2024
Why Healthcare Execs Are Hesitant To Embrace Long-Term Ai Contracts

Andy Sajous, Field CTO, AHEAD AI promises significant advances in patient care and healthcare operations, from improved diagnostics and personalized treatments plans to streamlining administrative tasks. Yet, a clear pattern has emerged in the decisions healthcare technology leaders are making around AI adoption within their organizations. Leaders are grappling with how to balance cutting-edge innovation with the risks and complexities of adopting an AI solution.Despite the enormous potential of AI, healthcare executives are hesitant to sign contracts with AI vendors that exceed 12 months. This behavior won’t change anytime soon and the pattern is likely to continue for the foreseeable future—at least the next 3-5 years. Let’s dig into why.A Constantly Shifting AI LandscapeThe reason for this reluctance comes down to the rapid pace of change in the AI market. AI solutions are evolving quickly, offering new opportunities and innovations that keep the landscape dynamic and full of potential

PR Newswire
Dec 20th, 2024
Ahead Is Recognized As A 2024 Gartner(R) Peer Insights(Tm) Customers' Choice For Data Center Outsourcing And Hybrid Infrastructure Managed Services, Worldwide

CHICAGO, Dec. 19, 2024 /PRNewswire/ -- AHEAD, a leading provider of cloud and digital infrastructure solutions, is excited to share that it was named a Customers' Choice in the 2024 Gartner Peer Insights 'Voice of the Customer': Data Center Outsourcing and Hybrid Infrastructure Managed Services, Worldwide. Gartner defines Data Center Outsourcing and Hybrid Infrastructure Managed Services as data center outsourcing services, managed services for hosted and private cloud infrastructure and managed services for public cloud and edge environments.Verified end users of AHEAD's services weighed in with their opinion, and 90 percent concluded that they would recommend AHEAD as of November 2024 based on 31 reviews."We see this recognition as a Gartner Customers' Choice for Data Center Outsourcing and Hybrid Infrastructure Managed Services a reflection of our relentless pursuit of high-impact business outcomes for our clients," said Keith Odom, EVP of Services at AHEAD. "We are grateful to our clients for their partnership and feedback and grateful to the AHEAD team for their unwavering commitment to service excellence."AHEAD offers complete asset management, cost optimization, monitoring, patching, advanced infrastructure optimization and business continuity services.Its Data Center and Infrastructure Managed Services organization manages infrastructure in client data centers and public cloud – as well as within their own data center – all with a cloud-operating-model-as-a-service. These offerings enable predictable operating costs, reduced risk, and the scale to meet client business needs.As an added benefit, client-specific Managed Services Accelerate Teams partner with organizations to optimize investments in cloud services across AWS, Microsoft Azure, ServiceNow and other platforms.The company offers a range of Managed Services including the following Infrastructure-specific services:Data Center Infrastructure ManagementPublic Cloud ManagementNetwork and Network Automation ManagementSystem AdministrationOS Patching & MaintenanceCompliance & Risk ManagementIn addition, AHEAD provides these Solution Accelerators, combining AHEAD tooling, intellectual property, and services into holistic managed solutions for clients:Cloud Operations & Management as a ServiceDevOps Platforms as a ServiceFinOps as a ServicePatching & Compliance as a ServiceEnd User Access as a ServiceSOC as a ServiceServiceNow Enterprise Platform ManagementThe "Voice of the Customer" is a document that applies a methodology (documented here) to aggregated Gartner Peer Insights' reviews in a market to provide an overall perspective for IT decision makers.Gartner® and Peer Insights™ are trademarks of Gartner, Inc. and/or its affiliates