
- • Jul 15-17, 2026 · Live Remote Online
- • Sep 16-18, 2026 · Live Remote Online
XSIAM-SOIA Cortex XSIAM: Security Operations, Integration and Automation
Course Duration
3 Days
Audience
Employees of federal, state and local governments; and businesses working with the government.
Prerequisites
Participants should have a foundational understanding of cybersecurity principles and experience with network and endpoint security fundamentals.
Course Description
The Cortex XSIAM: Security Operations, Integration and Automation (XSIAM-SOIA) course is a three-day, instructor-led training designed for cybersecurity professionals in SOC, CERT, and CSIRT engineering roles. The course covers XSIAM from fundamental components to advanced configuration, including how to configure security integrations with third-party tools, develop automation workflows, manage indicators, and optimize dashboards for enhanced security operations. Students will develop the skills needed to build and operate XSIAM as a production SOC platform.
Learning Objectives
- Describe Cortex XSIAM components and their roles in the security operations platform
- Configure security integrations to ingest data from third-party tools and platforms
- Develop and deploy automation workflows to accelerate threat detection and response
- Manage threat indicators and apply them within XSIAM detection policies
- Create and optimize dashboards for SOC situational awareness and operational metrics
- Configure alert rules and correlation policies within XSIAM
- Tune automation playbooks and integrations for operational efficiency
Course Outline
Course Topics
- XSIAM Platform Components and Architecture
- Configuring Security Integrations
- Data Ingestion and Normalization
- Automation Workflow Development
- Indicator Management
- Alert Rules and Correlation Policies
- Dashboard Creation and Optimization
- Playbook Tuning and Operational Best Practices
Frequently Asked Questions
What does the Cortex XSIAM Security Operations, Integration and Automation course cover?
This course covers configuring and operating Cortex XSIAM as a production SOC platform — security integrations, data ingestion, automation workflow development, indicator management, alert correlation, and dashboard optimization. It is designed for SOC engineers and security operations professionals.
How does this course differ from the XSIAM Investigation and Analysis course?
The Investigation and Analysis course (XSIAM-IA) focuses on analyst skills for investigating incidents. The Security Operations, Integration and Automation course (XSIAM-SOIA) focuses on engineering — configuring the platform, building integrations, developing automation, and optimizing the SOC environment.
How long is the Cortex XSIAM Security Operations course?
The course is 3 days. It is available as live remote online instruction or on-site at your facility.
Is this course available as live remote online training?
Yes. IT Dojo offers this course as live remote online training with multiple scheduled dates throughout the year. On-site delivery is also available.
How do I register for this course?
IT Dojo training is employer-sponsored — your organization registers and pays for seats. Contact IT Dojo via the Request Training form or call 757-216-3656 to schedule for your team.