Please note: LinkedIn does not offer a contract-to-hire employment type. This role is being posted as full-time, but the initial engagement will be contract-to-hire with planned FTE conversion in Feb/Mar 2027. Due to year-end hiring cycle and budget timing, the contract-to-hire structure is the fastest path to bring someone onto the team immediately, with the intent to convert once the new-year hiring cycle opens.
Our client is an award-winning business and technology consulting firm with a strong national footprint and a reputation for advising enterprise clients in complex, regulated industries. This is a high-impact consulting role focused on SOC modernization, AI-enabled security operations, SIEM/SOAR modernization, detection engineering, and Google SecOps or similar modern SOC platforms.
Quick Overview
- Location: Ideally Chicago, New York, Los Angeles, San Francisco, Washington DC, Seattle, or Dallas. Strong remote candidates may be considered.
- Background Preference: Consulting experience strongly preferred, ideally with enterprise, regulated industry, Energy & Utilities, critical infrastructure, financial services, or healthcare clients.
- Work Model: Hybrid if near a major office; remote may be considered for highly aligned candidates.
- Engagement Preference: Contract-to-hire preferred, though direct full-time hire may be possible for the right candidate.
- Pay Rate: Competitive and open to market rate.
- Full-Time Compensation Range: Approximately $193K–$262K, depending on location, experience, and fit.
- Travel: 10–20%, likely on the lower end.
The role
We’re seeking a Senior Cybersecurity Architect to help clients modernize security operations and move beyond traditional, manually intensive SOC environments. This role is focused on SOC modernization, SIEM/SOAR, detection engineering, security telemetry, automation, AI-enabled workflows, and SecOps tooling strategy.
This is not primarily an IT/OT security role. OT, Energy & Utilities, and critical infrastructure experience are helpful, but the main focus is SOC modernization and AI-enabled security operations.
What you’ll do
- Assess current-state SOC capabilities across people, process, tooling, data, automation, and governance
- Design future-state SOC operating models, analyst workflows, escalation paths, and SecOps processes
- Modernize SIEM/SOAR, detection engineering, case management, and detection/response capabilities
- Rationalize security tooling across SIEM, SOAR, XDR, EDR, IAM/PAM, cloud security, vulnerability management, threat intelligence, and ServiceNow SecOps
- Define telemetry and log ingestion strategies across cloud, endpoint, identity, network, SaaS, application, OT/ICS, and third-party data sources
- Identify practical AI-enabled SOC use cases, including alert summarization, investigation support, detection authoring, playbook execution, and analyst decision support
- Build SOC modernization roadmaps aligned to business risk, cyber maturity, regulatory needs, staffing models, and technology investments
- Lead executive workshops, architecture sessions, platform assessments, and client presentations
What you bring
- 7–10+ years in security architecture, SOC modernization, SecOps, SIEM/SOAR, detection engineering, incident response, security automation, or cybersecurity consulting
- Strong understanding of modern SOC operating models, detection/response workflows, alert triage, threat hunting, case management, and SecOps governance
- Experience designing or modernizing SOC capabilities in enterprise, regulated, or critical infrastructure environments
- Architecture-level exposure to SIEM, SOAR, XDR, EDR, telemetry, log ingestion, correlation, enrichment, and detection content
- Experience rationalizing cybersecurity tools and building practical modernization roadmaps
- Familiarity with AI-enabled or automation-enabled security operations
- Ability to advise CIOs, CISOs, SOC leaders, security engineers, and technology stakeholders
- Strong communication skills and ability to translate technical recommendations into executive-level narratives
Preferred
- Prior consulting experience in a client-facing advisory or delivery role
- Experience with Google Security Operations / Google SecOps, Chronicle SIEM, Chronicle SOAR, BigQuery, or Google Cloud security
- Experience with platforms such as Splunk, Microsoft Sentinel, Palo Alto Cortex, ServiceNow SecOps, CrowdStrike, Okta, SailPoint, CyberArk, Wiz, Prisma Cloud, or similar tools
- Experience with MITRE ATT&CK, detection-as-code, YARA-L, Sigma, SOAR playbooks, and detection lifecycle management
- Experience supporting Energy & Utilities, OT/ICS, critical infrastructure, or other highly regulated environments
- Familiarity with frameworks such as NIST, ISO 27001, NERC CIP, IEC 62443, HIPAA, GLBA, or PCI DSS
- Relevant certifications such as CISSP, CISM, CCSP, GSEC, GCIA, GCIH, GCFA, or Google Cloud security certifications