{"id":828436,"url":"https://alion.io/job/bespinglobal-senior-security-architect-managed-security-services","title":"Senior Security Architect — Managed Security Services","company":{"id":39461,"name":"Bespinglobal","domain":"bespinglobal.com","url":"https://alion.io/company/bespinglobal","size_band":null,"is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Rippling","truth_index":null},"role":"Security","role_family":"Security","seniority":"staff","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":140000,"max_usd":266000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":55},"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"CIS Benchmarks","optional":false},{"name":"Crowdstrike","optional":false},{"name":"GCP","optional":false},{"name":"Google SecOps","optional":false},{"name":"Least Privilege","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"NIST CSF","optional":false},{"name":"OpenTelemetry","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SentinelOne","optional":false},{"name":"SIEM","optional":false},{"name":"SOC 2","optional":false},{"name":"Wiz","optional":false},{"name":"Zero Trust","optional":false}],"status":"closed","first_seen_at":"2026-08-17T19:48:29Z","employer_posted_date":"2026-08-17","last_verified_at":"2026-09-24T22:47:05Z","board_verified":false,"closed_at":"2026-09-24T22:47:05Z","days_open":38,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":38},"description":"A little bit about us\nBespin Global is a top global cloud MSP recognized in the Gartner Magic Quadrant for 8 consecutive years. We also won the AWS MSP Partner of the Year globally and many Google Partner of the Year awards!\nWe have 1,300+ “Bespineers” across 16 offices and 10 countries including the U.S., South Korea, Singapore, Dubai, Indonesia, China, and Tokyo, serving more than 4,500 customers worldwide.\nIf you want a fun and exciting role at a fast-growing company with lots of opportunities, this is the place for you.\nAbout the Role\nBespin Global US delivers managed security services to organizations that need enterprise-grade detection and response without building it themselves - endpoint detection and response (EDR), 24x7 SOC services, SIEM and SOAR management, security assessments, and cloud security posture management (CSPM).\nThis role sits at the center of that practice with a dual mandate. You will engineer the platform our services run on - the SIEM/SOAR pipelines, EDR deployments, detection content, and integrations that our analysts depend on - and you will be the senior technical voice with customers, scoping new engagements, leading onboarding, and advising security leaders on how to mature their programs.\nThis is not a shift-based SOC seat. You are the person who decides how the service works, then makes it work for each customer.\nWhat You'll Do\nPlatform & Detection Engineering\nOwn the architecture and build-out of the multi-tenant SIEM and SOAR environments underpinning our managed detection services - primarily Google SecOps, with Elastic and Coralogix supporting customer-specific and log analytics use cases\nDesign and deploy EDR tooling across customer estates using SentinelOne and CrowdStrike; standardize policies, exclusions, and response actions\nBuild and maintain detection content - correlation rules, analytics, and use cases mapped to MITRE ATT&CK - and tune continuously to reduce false positives\nDevelop SOAR playbooks that automate triage, enrichment, containment, and notification workflows\nEngineer log ingestion and normalization pipelines with BindPlane across cloud, endpoint, identity, and network sources; manage data volume, routing, and ingest cost\nStand up and maintain Wiz for cloud security posture management across AWS, Google Cloud, and Azure; define policy baselines, risk prioritization, and remediation guidance\nDesign and maintain secure connectivity into customer environments using Tailscale, keeping collector and management access least-privilege and auditable\nAutomate deployment and configuration through infrastructure-as-code and scripting rather than manual, per-customer work\nEvaluate new security tooling and make build-vs-buy recommendations for the practice\nCustomer-Facing Delivery & Advisory\nLead technical discovery and scoping for prospective customers; translate their environment and risk profile into a service design\nOwn the technical execution of customer onboarding - from log source integration through first tuned detections and validated response workflows\nServe as the escalation point and trusted advisor for the customer's security stakeholders after go-live\nConduct security assessments and cloud posture reviews; present findings and prioritized remediation roadmaps to technical and executive audiences\nPartner with sales on solution design, technical proposals, and statements of work\nProduce reference architectures, runbooks, and documentation that let the SOC and delivery teams operate what you build\nThe Stack You'll Work With\nLayer\nPlatforms\nSIEM / detection & response\nGoogle SecOps, Elastic, Coralogix\nEndpoint\nSentinelOne, CrowdStrike\nCloud security posture\nWiz\nTelemetry pipeline\nBindPlane\nSecure access\nTailscale\nCloud platforms\nAWS, Google Cloud, Azure\nWe are not tool-agnostic for the sake of it - we run a deliberate stack and expect you to help shape where it goes next.\nWhat You Bring\nRequired\n7+ years in security engineering, security operations, or security consulting, including hands-on ownership of a SIEM platform\nDeep, hands-on experience with at least one modern SIEM - Google SecOps (Chronicle), Elastic, or Coralogix strongly preferred - including data onboarding, parsing and normalization, and detection authoring\nHands-on experience deploying and operating EDR/XDR platforms; SentinelOne and CrowdStrike specifically preferred\nExperience with a CSPM/CNAPP platform such as Wiz, including policy baselines and risk-based remediation workflows\nWorking knowledge of SOAR platforms and automation of security workflows\nStrong cloud security fundamentals across AWS, Google Cloud, or Azure - native security services, identity, and posture management - with the ability to work in at least two\nScripting and automation skills (Python, PowerShell, or equivalent) and comfort with infrastructure-as-code\nDemonstrated ability to communicate directly with customers - running technical workshops, presenting findings, and handling escalations with credibility\nWorking familiarity with common frameworks and standards (MITRE ATT&CK, NIST CSF, CIS Benchmarks, SOC 2)\nPreferred\nPrior experience in an MSSP, MSP, or consulting environment supporting multiple customers concurrently\nIncident response experience, including leading investigations end to end\nMulti-cloud breadth across AWS, Google Cloud, and Azure\nExperience with telemetry pipeline tooling (BindPlane, OpenTelemetry, Cribl, or similar) and log cost optimization\nFamiliarity with zero-trust or mesh networking tools such as Tailscale for customer environment access\nCertifications such as GCIA, GCIH, GCDA, CISSP, OSCP, or cloud security specialty credentials\nExperience with detection-as-code practices and CI/CD for security content\nExposure to pre-sales solutioning and SOW development\nWhat Success Looks Like\nFirst 90 days: fluent in our service stack and delivery model; leading onboarding for at least one new customer; first detection content improvements shipped\nFirst 6 months: owning the technical design of the SIEM/SOAR platform; measurable reduction in false-positive volume; recognized as the escalation point across the delivery team\nFirst year: onboarding is faster and more repeatable than when you arrived; detection coverage is measurably broader; customers name you as a reason they stay\nWhy Bespin\nYou will have real ownership over how a growing managed security practice is built - not a narrow slice of someone else's platform. The work spans engineering depth and customer impact, and you will see the results of both across every account we run.\nBespin Global US is an equal opportunity employer. We consider all qualified applicants without regard to any characteristic protected by applicable law.","description_format":"text","description_chars":6719,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Managed Security","IT Consulting","Managed IT Services","AI Consulting & Integration"],"lifecycle":[{"event":"open","at":"2026-09-12T15:36:31Z"},{"event":"close","at":"2026-09-24T22:47:05Z"}],"liveness":null,"pay":null,"html_url":"https://alion.io/job/bespinglobal-senior-security-architect-managed-security-services","json_url":"https://alion.io/job/bespinglobal-senior-security-architect-managed-security-services.json","meta":{"generated_at":"2026-09-24T22:59:48Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1217,"day_limit":5000,"remaining_today":3783,"minute_limit":60,"resets_at":"2026-09-25T00:00:00Z"}}}