Senior Security Architect β€” Managed Security Services

🏒 Bespin Global · all Bespin Global jobs
πŸ“ United States
πŸ“… Posted 2026-08-19 Β· via Himalayas
🏷 Security-Architecture,Managed-Security-Services,Security-Engineering,SOC-Operations,Cloud-Security,Senior-Security-Architect,Senior-Security-Solutions-Architect,Senior-Solutions-Architect-Security,Senior-Cybersecurity-Solutions-Architect,Senior-Cloud-Security-Architect,Principal-Security-Architect,Security-Solutions-Architect,Security-Architect,Lead-Cloud-Security-Architect,Security-Architecture-Lead
Apply on original site β†—

A little bit about us

Bespin Global is a top global cloud MSP recognized in the Gartner Magic Quadrant for 8 consecutive years. We also won the AWS MSP Partner of the Year globally and many Google Partner of the Year awards!

We have 1,300+ β€œBespineers” across 16 offices and 10 countries including the U.S., South Korea, Singapore, Dubai, Indonesia, China, and Tokyo, serving more than 4,500 customers worldwide.

If you want a fun and exciting role at a fast-growing company with lots of opportunities, this is the place for you.

About the Role

Bespin Global US delivers managed security services to organizations that need enterprise-grade detection and response without building it themselves β€” endpoint detection and response (EDR), 24x7 SOC services, SIEM and SOAR management, security assessments, and cloud security posture management (CSPM).

This role sits at the center of that practice with a dual mandate. You will engineer the platform our services run on β€” the SIEM/SOAR pipelines, EDR deployments, detection content, and integrations that our analysts depend on β€” and you will be the senior technical voice with customers , scoping new engagements, leading onboarding, and advising security leaders on how to mature their programs.

This is not a shift-based SOC seat. You are the person who decides how the service works, then makes it work for each customer.

What You'll Do

Platform & Detection Engineering

- Own the architecture and build-out of the multi-tenant SIEM and SOAR environments underpinning our managed detection services β€” primarily Google SecOps, with Elastic and Coralogix supporting customer-specific and log analytics use cases

- Design and deploy EDR tooling across customer estates using SentinelOne and CrowdStrike; standardize policies, exclusions, and response actions

- Build and maintain detection content β€” correlation rules, analytics, and use cases mapped to MITRE ATT&CK β€” and tune continuously to reduce false positives

- Develop SOAR playbooks that automate triage, enrichment, containment, and notification workflows

- Engineer log ingestion and normalization pipelines with BindPlane across cloud, endpoint, identity, and network sources; manage data volume, routing, and ingest cost

- Stand up and maintain Wiz for cloud security posture management across AWS, Google Cloud, and Azure; define policy baselines, risk prioritization, and remediation guidance

- Design and maintain secure connectivity into customer environments using Tailscale, keeping collector and management access least-privilege and auditable

- Automate deployment and configuration through infrastructure-as-code and scripting rather than manual, per-customer work

- Evaluate new security tooling and make build-vs-buy recommendations for the practice

Customer-Facing Delivery & Advisory

- Lead technical discovery and scoping for prospective customers; translate their environment and risk profile into a service design

- Own the technical execution of customer onboarding β€” from log source integration through first tuned detections and validated response workflows

- Serve as the escalation point and trusted advisor for the customer's security stakeholders after go-live

- Conduct security assessments and cloud posture reviews; present findings and prioritized remediation roadmaps to technical and executive audiences

- Partner with sales on solution design, technical proposals, and statements of work

- Produce reference architectures, runbooks, and documentation that let the SOC and delivery teams operate what you build

The Stack You'll Work With

Layer

Platforms

SIEM / detection & response

Google SecOps, Elastic, Coralogix

Endpoint

SentinelOne, CrowdStrike

Cloud security posture

Wiz

Telemetry pipeline

BindPlane

Secure access

Tailscale

Cloud platforms

AWS, Google Cloud, Azure

We are not tool-agnostic for the sake of it β€” we run a deliberate stack and expect you to help shape where it goes next.

← All remote jobs