Senior Security Architect — Managed Security Services
- Role
- Security
- Experience
- Senior
- Employment
- Full-time
- Company size
- Enterprise
Open to US only. Set where you work from to check your eligibility.
No BS summary
Senior Security Architect needed for a managed security services provider. You will engineer the platform for SIEM/SOAR, EDR, and other security services, and act as the senior technical advisor to customers. Requires 7+ years in security engineering/operations/consulting with hands-on SIEM and EDR experience, plus cloud security fundamentals and customer-facing skills.
Core skills
Required skills
Optional skills
Required languages
**A little bit about us
**Bespin Global is a top global cloud MSP recognized in the Gartner Magic Quadrant for 8 consecutive years. We also won the AWS MSP Partner of the Year globally and many Google Partner of the Year awards!
**We have 1,300+ “Bespineers” across 16 offices and 10 countries including the U.S., South Korea, Singapore, Dubai, Indonesia, China, and Tokyo, serving more than 4,500 customers worldwide.
**If you want a fun and exciting role at a fast-growing company with lots of opportunities, this is the place for you.
About the Role
Bespin Global US delivers managed security services to organizations that need enterprise-grade detection and response without building it themselves — endpoint detection and response (EDR), 24x7 SOC services, SIEM and SOAR management, security assessments, and cloud security posture management (CSPM).
This role sits at the center of that practice with a dual mandate. You will **engineer the platform our services run on — the SIEM/SOAR pipelines, EDR deployments, detection content, and integrations that our analysts depend on — and you will be the **senior technical voice with customers, scoping new engagements, leading onboarding, and advising security leaders on how to mature their programs.
This is not a shift-based SOC seat. You are the person who decides how the service works, then makes it work for each customer.
What You'll Do
Platform & Detection Engineering
- Own the architecture and build-out of the multi-tenant SIEM and SOAR environments underpinning our managed detection services — primarily Google SecOps, with Elastic and Coralogix supporting customer-specific and log analytics use cases
- Design and deploy EDR tooling across customer estates using SentinelOne and CrowdStrike; standardize policies, exclusions, and response actions
- Build and maintain detection content — correlation rules, analytics, and use cases mapped to MITRE ATT&CK — and tune continuously to reduce false positives
- Develop SOAR playbooks that automate triage, enrichment, containment, and notification workflows
- Engineer log ingestion and normalization pipelines with BindPlane across cloud, endpoint, identity, and network sources; manage data volume, routing, and ingest cost
- Stand up and maintain Wiz for cloud security posture management across AWS, Google Cloud, and Azure; define policy baselines, risk prioritization, and remediation guidance
- Design and maintain secure connectivity into customer environments using Tailscale, keeping collector and management access least-privilege and auditable
- Automate deployment and configuration through infrastructure-as-code and scripting rather than manual, per-customer work
- Evaluate new security tooling and make build-vs-buy recommendations for the practice
Customer-Facing Delivery & Advisory
- Lead technical discovery and scoping for prospective customers; translate their environment and risk profile into a service design
- Own the technical execution of customer onboarding — from log source integration through first tuned detections and validated response workflows
- Serve as the escalation point and trusted advisor for the customer's security stakeholders after go-live
- Conduct security assessments and cloud posture reviews; present findings and prioritized remediation roadmaps to technical and executive audiences
- Partner with sales on solution design, technical proposals, and statements of work
- Produce reference architectures, runbooks, and documentation that let the SOC and delivery teams operate what you build
The Stack You'll Work With
| **Layer | **Platforms |
|---|---|
| SIEM / detection & response | Google SecOps, Elastic, Coralogix |
| Endpoint | SentinelOne, CrowdStrike |
| Cloud security posture | Wiz |
| Telemetry pipeline | BindPlane |
| Secure access | Tailscale |
| Cloud platforms | AWS, Google Cloud, Azure |
We are not tool-agnostic for the sake of it — we run a deliberate stack and expect you to help shape where it goes next.
What You Bring
**Required
- 7+ years in security engineering, security operations, or security consulting, including hands-on ownership of a SIEM platform
- Deep, hands-on experience with at least one modern SIEM — Google SecOps (Chronicle), Elastic, or Coralogix strongly preferred — including data onboarding, parsing and normalization, and detection authoring
- Hands-on experience deploying and operating EDR/XDR platforms; SentinelOne and CrowdStrike specifically preferred
- Experience with a CSPM/CNAPP platform such as Wiz, including policy baselines and risk-based remediation workflows
- Working knowledge of SOAR platforms and automation of security workflows
- Strong cloud security fundamentals across AWS, Google Cloud, or Azure — native security services, identity, and posture management — with the ability to work in at least two
- Scripting and automation skills (Python, PowerShell, or equivalent) and comfort with infrastructure-as-code
- Demonstrated ability to communicate directly with customers — running technical workshops, presenting findings, and handling escalations with credibility
- Working familiarity with common frameworks and standards (MITRE ATT&CK, NIST CSF, CIS Benchmarks, SOC 2)
**Preferred
- Prior experience in an MSSP, MSP, or consulting environment supporting multiple customers concurrently
- Incident response experience, including leading investigations end to end
- Multi-cloud breadth across AWS, Google Cloud, and Azure
- Experience with telemetry pipeline tooling (BindPlane, OpenTelemetry, Cribl, or similar) and log cost optimization
- Familiarity with zero-trust or mesh networking tools such as Tailscale for customer environment access
- Certifications such as GCIA, GCIH, GCDA, CISSP, OSCP, or cloud security specialty credentials
- Experience with detection-as-code practices and CI/CD for security content
- Exposure to pre-sales solutioning and SOW development
What Success Looks Like
- **First 90 days: fluent in our service stack and delivery model; leading onboarding for at least one new customer; first detection content improvements shipped
- **First 6 months: owning the technical design of the SIEM/SOAR platform; measurable reduction in false-positive volume; recognized as the escalation point across the delivery team
- **First year: onboarding is faster and more repeatable than when you arrived; detection coverage is measurably broader; customers name you as a reason they stay
Why Bespin
You will have real ownership over how a growing managed security practice is built — not a narrow slice of someone else's platform. The work spans engineering depth and customer impact, and you will see the results of both across every account we run.
_Bespin Global US is an equal opportunity employer. We consider all qualified applicants without regard to any characteristic protected by applicable law.
What you'll do
- Own the architecture and build-out of the multi-tenant SIEM and SOAR environments underpinning our managed detection services — primarily Google SecOps, with Elastic and Coralogix supporting customer-specific and log analytics use cases
- Design and deploy EDR tooling across customer estates using SentinelOne and CrowdStrike; standardize policies, exclusions, and response actions
- Build and maintain detection content — correlation rules, analytics, and use cases mapped to MITRE ATT&CK — and tune continuously to reduce false positives
- Develop SOAR playbooks that automate triage, enrichment, containment, and notification workflows
- Engineer log ingestion and normalization pipelines with BindPlane across cloud, endpoint, identity, and network sources; manage data volume, routing, and ingest cost
- Stand up and maintain Wiz for cloud security posture management across AWS, Google Cloud, and Azure; define policy baselines, risk prioritization, and remediation guidance
- Design and maintain secure connectivity into customer environments using Tailscale, keeping collector and management access least-privilege and auditable
- Automate deployment and configuration through infrastructure-as-code and scripting rather than manual, per-customer work
- Evaluate new security tooling and make build-vs-buy recommendations for the practice
- Lead technical discovery and scoping for prospective customers; translate their environment and risk profile into a service design
- Own the technical execution of customer onboarding — from log source integration through first tuned detections and validated response workflows
- Serve as the escalation point and trusted advisor for the customer's security stakeholders after go-live
- Conduct security assessments and cloud posture reviews; present findings and prioritized remediation roadmaps to technical and executive audiences
- Partner with sales on solution design, technical proposals, and statements of work
- Produce reference architectures, runbooks, and documentation that let the SOC and delivery teams operate what you build
What they require
- 7+ years in security engineering, security operations, or security consulting, including hands-on ownership of a SIEM platform
- Deep, hands-on experience with at least one modern SIEM — Google SecOps (Chronicle), Elastic, or Coralogix strongly preferred — including data onboarding, parsing and normalization, and detection authoring
- Hands-on experience deploying and operating EDR/XDR platforms; SentinelOne and CrowdStrike specifically preferred
- Experience with a CSPM/CNAPP platform such as Wiz, including policy baselines and risk-based remediation workflows
- Working knowledge of SOAR platforms and automation of security workflows
- Strong cloud security fundamentals across AWS, Google Cloud, or Azure — native security services, identity, and posture management — with the ability to work in at least two
- Scripting and automation skills (Python, PowerShell, or equivalent) and comfort with infrastructure-as-code
- Demonstrated ability to communicate directly with customers — running technical workshops, presenting findings, and handling escalations with credibility
- Working familiarity with common frameworks and standards (MITRE ATT&CK, NIST CSF, CIS Benchmarks, SOC 2)
Benefits
- You will have real ownership over how a growing managed security practice is built — not a narrow slice of someone else's platform.
- The work spans engineering depth and customer impact, and you will see the results of both across every account we run.
- Bespin Global US is an equal opportunity employer. We consider all qualified applicants without regard to any characteristic protected by applicable law.
Bespin Global is a top global cloud MSP recognized in the Gartner Magic Quadrant for 8 consecutive years. We also won the AWS MSP Partner of the Year globally and many Google Partner of the Year awards! We have 1,300+ “Bespineers” across 16 offices and 10 countries including the U.S., South Korea, Singapore, Dubai, Indonesia, China, and Tokyo, serving more than 4,500 customers worldwide.