Skip to main content
Bespin Global US

Senior Security Architect — Managed Security Services

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior Security Architect needed for a managed security services provider. You will engineer the platform for SIEM/SOAR, EDR, and other security services, and act as the senior technical advisor to customers. Requires 7+ years in security engineering/operations/consulting with hands-on SIEM and EDR experience, plus cloud security fundamentals and customer-facing skills.

Core skills

Google SecOpsSentinelOneCrowdStrike

Required skills

SIEMSOAREDRCSPMElasticCoralogixWizBindPlaneTailscaleAWSGCPAzurePythonPowerShellinfrastructure-as-codeMITRE ATT&CKNIST CSFCIS BenchmarksSOC 2

Optional skills

MSSPMSPconsultingincident responseOpenTelemetryCriblzero-trustmesh networking

Required languages

English

What you'll do

  • Own the architecture and build-out of the multi-tenant SIEM and SOAR environments underpinning our managed detection services — primarily Google SecOps, with Elastic and Coralogix supporting customer-specific and log analytics use cases
  • Design and deploy EDR tooling across customer estates using SentinelOne and CrowdStrike; standardize policies, exclusions, and response actions
  • Build and maintain detection content — correlation rules, analytics, and use cases mapped to MITRE ATT&CK — and tune continuously to reduce false positives
  • Develop SOAR playbooks that automate triage, enrichment, containment, and notification workflows
  • Engineer log ingestion and normalization pipelines with BindPlane across cloud, endpoint, identity, and network sources; manage data volume, routing, and ingest cost
  • Stand up and maintain Wiz for cloud security posture management across AWS, Google Cloud, and Azure; define policy baselines, risk prioritization, and remediation guidance
  • Design and maintain secure connectivity into customer environments using Tailscale, keeping collector and management access least-privilege and auditable
  • Automate deployment and configuration through infrastructure-as-code and scripting rather than manual, per-customer work
  • Evaluate new security tooling and make build-vs-buy recommendations for the practice
  • Lead technical discovery and scoping for prospective customers; translate their environment and risk profile into a service design
  • Own the technical execution of customer onboarding — from log source integration through first tuned detections and validated response workflows
  • Serve as the escalation point and trusted advisor for the customer's security stakeholders after go-live
  • Conduct security assessments and cloud posture reviews; present findings and prioritized remediation roadmaps to technical and executive audiences
  • Partner with sales on solution design, technical proposals, and statements of work
  • Produce reference architectures, runbooks, and documentation that let the SOC and delivery teams operate what you build

What they require

  • 7+ years in security engineering, security operations, or security consulting, including hands-on ownership of a SIEM platform
  • Deep, hands-on experience with at least one modern SIEM — Google SecOps (Chronicle), Elastic, or Coralogix strongly preferred — including data onboarding, parsing and normalization, and detection authoring
  • Hands-on experience deploying and operating EDR/XDR platforms; SentinelOne and CrowdStrike specifically preferred
  • Experience with a CSPM/CNAPP platform such as Wiz, including policy baselines and risk-based remediation workflows
  • Working knowledge of SOAR platforms and automation of security workflows
  • Strong cloud security fundamentals across AWS, Google Cloud, or Azure — native security services, identity, and posture management — with the ability to work in at least two
  • Scripting and automation skills (Python, PowerShell, or equivalent) and comfort with infrastructure-as-code
  • Demonstrated ability to communicate directly with customers — running technical workshops, presenting findings, and handling escalations with credibility
  • Working familiarity with common frameworks and standards (MITRE ATT&CK, NIST CSF, CIS Benchmarks, SOC 2)

Benefits

  • You will have real ownership over how a growing managed security practice is built — not a narrow slice of someone else's platform.
  • The work spans engineering depth and customer impact, and you will see the results of both across every account we run.
  • Bespin Global US is an equal opportunity employer. We consider all qualified applicants without regard to any characteristic protected by applicable law.

Bespin Global is a top global cloud MSP recognized in the Gartner Magic Quadrant for 8 consecutive years. We also won the AWS MSP Partner of the Year globally and many Google Partner of the Year awards! We have 1,300+ “Bespineers” across 16 offices and 10 countries including the U.S., South Korea, Singapore, Dubai, Indonesia, China, and Tokyo, serving more than 4,500 customers worldwide.

Managed Security ServicesEnterprise
Salary not disclosed