Senior Security Architect — Managed Security Services

Rippling, Inc.

United States

Remote

USD 180,000 - 240,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Bespin Global US delivers managed security services, focusing on enterprise-grade SIEM and SOAR pipelines, EDR deployments, and CSPM across cloud environments. You will architect the service platform and act as senior technical voice with customers, scoping engagements, onboarding, and guiding security maturity.

The role centers on designing and operating the security stack, including detection content, playbooks, and secure connectivity, while advising customers and shaping the security program

Qualifications

  • 7+ years in security engineering, ops, or consulting with ownership of a SIEM platform.
  • Hands-on with at least one modern SIEM - Google SecOps/Chronicle, Elastic, or Coralogix.
  • Experience deploying and operating EDR/XDR platforms (SentinelOne, CrowdStrike).
  • Experience with CSPM/CNAPP like Wiz, policy baselines, remediation workflows.
  • Familiar with SOAR platforms and automation of security workflows.
  • Strong cloud security fundamentals across AWS, GCP, or Azure, at least two.
  • Scripting/automation skills (Python, PowerShell) and IaC exposure.
  • Excellent communication with customers; capable of workshops and escalations.
  • Familiarity with MITRE ATT&CK, NIST CSF, CIS Benchmarks, SOC 2

Responsibilities

  • Own the architecture and build-out of the multi-tenant SIEM and SOAR environments.
  • Design and deploy EDR tooling across customer estates (SentinelOne, CrowdStrike).
  • Build and maintain detection content mapped to MITRE ATT&CK; tune to reduce false positives.
  • Develop SOAR playbooks for triage, enrichment, containment, notification workflows.
  • Engineer log ingestion/normalization across cloud, endpoint, identity, network sources.
  • Stand up Wiz for CSPM across AWS, GCP, Azure; define baselines and remediation guidance.
  • Design secure connectivity into customer environments (Tailscale); enforce least privilege.
  • Automate deployment/configuration via IaC and scripting; avoid manual per-customer work.
  • Evaluate new tooling and advise build-vs-buy for the practice.
  • Lead technical discovery and scoping for prospective customers; translate risk into service design.
  • Own onboarding execution from log source integration to validated detections.
  • Serve as escalation point for customers post go-live.
  • Conduct security assessments and cloud posture reviews; present remediation roadmaps.
  • Partner with sales on solutions and SOWs; produce reference architectures and runbooks.

Skills

SIEM ownership
EDR/XDR tooling
CSPM/CNAPP
SOAR automation
Cloud security
Python/PowerShell
MITRE ATT&CK/NIST
Customer communication

Tools

Google SecOps/Chronicle
Elastic
Coralogix
SentinelOne
CrowdStrike
Wiz
Tailscale

Job description

Senior Security Architect — Managed Security Services

A little bit about us

Bespin Global is a top global cloud MSP recognized in the Gartner Magic Quadrant for 8 consecutive years. We also won the AWS MSP Partner of the Year globally and many Google Partner of the Year awards!

We have 1,300+ “Bespineers” across 16 offices and 10 countries including the U.S., South Korea, Singapore, Dubai, Indonesia, China, and Tokyo, serving more than 4,500 customers worldwide.

If you want a fun and exciting role at a fast-growing company with lots of opportunities, this is the place for you.

About the Role

Bespin Global US delivers managed security services to organizations that need enterprise-grade detection and response without building it themselves - endpoint detection and response (EDR), 24x7 SOC services, SIEM and SOAR management, security assessments, and cloud security posture management (CSPM).

This role sits at the center of that practice with a dual mandate. You will engineer the platform our services run on - the SIEM/SOAR pipelines, EDR deployments, detection content, and integrations that our analysts depend on - and you will be the senior technical voice with customers , scoping new engagements, leading onboarding, and advising security leaders on how to mature their programs.

This is not a shift-based SOC seat. You are the person who decides how the service works, then makes it work for each customer.

What You'll Do
Platform & Detection Engineering
  • Own the architecture and build-out of the multi-tenant SIEM and SOAR environments underpinning our managed detection services - primarily Google SecOps, with Elastic and Coralogix supporting customer-specific and log analytics use cases
  • Design and deploy EDR tooling across customer estates using SentinelOne and CrowdStrike; standardize policies, exclusions, and response actions
  • Build and maintain detection content - correlation rules, analytics, and use cases mapped to MITRE ATT&CK - and tune continuously to reduce false positives
  • Develop SOAR playbooks that automate triage, enrichment, containment, and notification workflows
  • Engineer log ingestion and normalization pipelines with BindPlane across cloud, endpoint, identity, and network sources; manage data volume, routing, and ingest cost
  • Stand up and maintain Wiz for cloud security posture management across AWS, Google Cloud, and Azure; define policy baselines, risk prioritization, and remediation guidance
  • Design and maintain secure connectivity into customer environments using Tailscale, keeping collector and management access least-privilege and auditable
  • Automate deployment and configuration through infrastructure-as-code and scripting rather than manual, per-customer work
  • Evaluate new security tooling and make build-vs-buy recommendations for the practice
Customer-Facing Delivery & Advisory
  • Lead technical discovery and scoping for prospective customers; translate their environment and risk profile into a service design
  • Own the technical execution of customer onboarding - from log source integration through first tuned detections and validated response workflows
  • Serve as the escalation point and trusted advisor for the customer's security stakeholders after go-live
  • Conduct security assessments and cloud posture reviews; present findings and prioritized remediation roadmaps to technical and executive audiences
  • Partner with sales on solution design, technical proposals, and statements of work
  • Produce reference architectures, runbooks, and documentation that let the SOC and delivery teams operate what you build
The Stack You'll Work With

Layer

Platforms

Cloud security posture

Telemetry pipeline

BindPlane

Secure access

Tailscale

We are not tool-agnostic for the sake of it - we run a deliberate stack and expect you to help shape where it goes next.

What You Bring

Required

  • 7+ years in security engineering, security operations, or security consulting, including hands-on ownership of a SIEM platform
  • Deep, hands-on experience with at least one modern SIEM - Google SecOps (Chronicle), Elastic, or Coralogix strongly preferred - including data onboarding, parsing and normalization, and detection authoring
  • Hands-on experience deploying and operating EDR/XDR platforms; SentinelOne and CrowdStrike specifically preferred
  • Experience with a CSPM/CNAPP platform such as Wiz, including policy baselines and risk-based remediation workflows
  • Working knowledge of SOAR platforms and automation of security workflows
  • Strong cloud security fundamentals across AWS, Google Cloud, or Azure - native security services, identity, and posture management - with the ability to work in at least two
  • Scripting and automation skills (Python, PowerShell, or equivalent) and comfort with infrastructure-as-code
  • Demonstrated ability to communicate directly with customers - running technical workshops, presenting findings, and handling escalations with credibility
  • Working familiarity with common frameworks and standards (MITRE ATT&CK, NIST CSF, CIS Benchmarks, SOC 2)

Preferred

  • Prior experience in an MSSP, MSP, or consulting environment supporting multiple customers concurrently
  • Incident response experience, including leading investigations end to end
  • Multi-cloud breadth across AWS, Google Cloud, and Azure
  • Experience with telemetry pipeline tooling (BindPlane, OpenTelemetry, Cribl, or similar) and log cost optimization
  • Familiarity with zero-trust or mesh networking tools such as Tailscale for customer environment access
  • Certifications such as GCIA, GCIH, GCDA, CISSP, OSCP, or cloud security specialty credentials
  • Experience with detection-as-code practices and CI/CD for security content
  • Exposure to pre-sales solutioning and SOW development
What Success Looks Like
  • First 90 days: fluent in our service stack and delivery model; leading onboarding for at least one new customer; first detection content improvements shipped
  • First 6 months: owning the technical design of the SIEM/SOAR platform; measurable reduction in false-positive volume; recognized as the escalation point across the delivery team
  • First year: onboarding is faster and more repeatable than when you arrived; detection coverage is measurably broader; customers name you as a reason they stay
Why Bespin

You will have real ownership over how a growing managed security practice is built - not a narrow slice of someone else's platform. The work spans engineering depth and customer impact, and you will see the results of both across every account we run.

Bespin Global US is an equal opportunity employer. We consider all qualified applicants without regard to any characteristic protected by applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Consulting Architect - Security (EMEA / Public Sector eligible )
Consulting Architect - Security (EMEA / Public Sector eligible )

United States Digital Space LLC • United States

On-site
USD 150,000 - 230,000
Senior Security Architect - MSSP Platform & Cloud Security
Senior Security Architect - MSSP Platform & Cloud Security

Rippling, Inc. • United States

Remote
USD 180,000 - 240,000
Security Operations Engineer
Security Operations Engineer

Yellow Card • Tulsa (OK)

On-site
USD 120,000 - 160,000
Manager, Security Engineering (MSSP Services)- Remote (USA)
Manager, Security Engineering (MSSP Services)- Remote (USA)

Echelon Risk + Cyber • Washington

On-site
USD 150,000 - 210,000
Health insurance
401(k) with employer matching
HSA eligibility
+2
Senior Cybersecurity Engineer, Managed Services
Senior Cybersecurity Engineer, Managed Services

Critical-Start- • Washington

On-site
USD 120,000 - 140,000
Competitive salary with bonuspotential
Comprehensive health benefits
Unlimited PTO
+3
Solutions Engineer
Solutions Engineer

GhostEye • New York (NY)

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

Partners In Performance International Pty Ltd • Palo Alto (CA)

On-site
USD 140,000 - 190,000
Security Operations Engineer (Europe - Remote)
Security Operations Engineer (Europe - Remote)

SpotMe • Indiana

Remote
USD 81,000 - 139,000
Sr. CyberSecurity Engineer
Sr. CyberSecurity Engineer

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Senior Cybersecurity Engineer, Managed Services
Senior Cybersecurity Engineer, Managed Services

Critical Start • Austin (TX)

On-site
USD 120,000 - 140,000
Unlimited PTO
Health benefits
401(k) with matching