
Senior Security Architect – Managed Security Services
Posted Aug 18

Posted Aug 18
This is a fully remote position, open to applicants in United States.
• Take charge of the architecture and development of multi-tenant SIEM and SOAR environments for managed detection services.
• Design and implement EDR tools throughout customer environments utilizing SentinelOne and CrowdStrike.
• Create and sustain MITRE ATT&CK-aligned detection content and fine-tune it to minimize false positives.
• Develop SOAR playbooks for workflows involving triage, enrichment, containment, and notifications.
• Engineer log ingestion and normalization pipelines with BindPlane, covering cloud, endpoint, identity, and network sources.
• Set up and manage Wiz for cloud security posture management across AWS, Google Cloud, and Azure.
• Design and uphold secure, least-privilege connectivity for customers using Tailscale.
• Automate deployment and configuration through infrastructure-as-code and scripting.
• Assess security tools and provide recommendations for build-versus-buy decisions.
• Lead technical discovery and scoping for potential customers.
• Manage technical customer onboarding from log integration to tuned detections and validated response workflows.
• Act as an escalation point and trusted advisor for customer security stakeholders.
• Conduct security assessments and reviews of cloud posture.
• Present findings and prioritized remediation roadmaps to both technical and executive audiences.
• Collaborate with sales on solution design, technical proposals, and statements of work.
• Produce reference architectures, runbooks, and documentation for SOC and delivery teams.
• Lead the onboarding process for at least one new customer within the initial 90 days.
• Oversee the technical design of SIEM/SOAR platforms and enhance detection coverage and onboarding consistency.
• A minimum of 7 years in security engineering, security operations, or security consulting, with hands-on SIEM ownership.
• Practical experience with at least one modern SIEM, including data onboarding, parsing, normalization, and detection authoring.
• Preference for experience with Google SecOps (Chronicle), Elastic, or Coralogix.
• Hands-on experience in deploying and managing EDR/XDR platforms; familiarity with SentinelOne and CrowdStrike is preferred.
• Experience with a CSPM/CNAPP platform like Wiz, including policy baselines and risk-based remediation workflows.
• Working knowledge of SOAR platforms and automation of security workflows.
• Strong foundational knowledge in cloud security across AWS, Google Cloud, or Azure, with the capability to work in at least two of these environments.
• Proficiency in scripting and automation using Python, PowerShell, or equivalent languages.
• Comfort with infrastructure-as-code practices.
• Ability to engage directly with customers through technical workshops, presentations, and escalations.
• Familiarity with MITRE ATT&CK, NIST CSF, CIS Benchmarks, and SOC 2.
• Prior experience with MSSP, MSP, or consulting is preferred.
• Incident response experience is preferred.
• Multi-cloud experience across AWS, Google Cloud, and Azure is preferred.
• Familiarity with BindPlane, OpenTelemetry, Cribl, or similar telemetry tools is preferred.
• Knowledge of Tailscale or similar zero-trust/mesh networking tools is preferred.
• Certifications such as GCIA, GCIH, GCDA, CISSP, OSCP, or cloud security specialty credentials are preferred.
• Experience with detection-as-code and CI/CD for security content is preferred.
• Exposure to pre-sales solutioning and SOW development is preferred.
• Genuine ownership in shaping a growing managed security practice.
• Opportunities within a rapidly expanding company.
• Commitment to equal opportunity employment.
CrowdStrike
Triumph Enterprises, Inc.
LaunchDarkly
Staffbase
Get handpicked remote jobs straight to your inbox weekly.