CareerXperts Consulting
Website:
careerxperts.com
Job details:
About the Company
We are looking for a Solutions Architect who is the technical lead in our customerconversations: designing how fits a given environment, running evaluations andproof-of-value engagements, and making customer teams genuinely capable at operating anAI SOC.You will work directly with detection engineers, threat hunters, SOC leads and CISOs. Expectdeep technical discussions on telemetry design, analytic strategy, MITRE coverage andprioritisation logic, and expect to be the person who turns "here is our environment andhere is what we need to prioritize" into a working architecture. This is a hands-on individualcontributor role.
About the Role
We are looking for a Solutions Architect who is the technical lead in our customerconversations: designing how fits a given environment, running evaluations andproof-of-value engagements, and making customer teams genuinely capable at operating anAI SOC.You will work directly with detection engineers, threat hunters, SOC leads and CISOs. Expectdeep technical discussions on telemetry design, analytic strategy, MITRE coverage andprioritisation logic, and expect to be the person who turns "here is our environment andhere is what we need to prioritize" into a working architecture. This is a hands-on individualcontributor role.
Responsibilities
- Lead technical discovery: map available telemetry, retention, existing detectioncoverage and blind spots across a customer's estate.
- Design the analytic approach for each environment — which signals matter, whatruns as a real-time detection, and what runs as a hypothesis-driven hunt.
- Own technical evaluations and POVs end to end: agree success criteria, build theenvironment, run the scenarios, present the results.
- Run detection coverage and telemetry-gap analysis mapped to MITRE ATT&CK, andturn customer scenarios and post-incident retrospectives into concrete detection andhunt strategy.
- Configure the environment-specific context that makes analytics precise: privilegedand VIP accounts, critical assets, approved regions and service principals, sanctionedtooling.
- Build SOAR and automation integrations that connect findings to thecustomer's response tooling, and support onboarding across connectors, data paths,authentication and multi-tenant design.
- Run workshops and technical deep dives, and maintain the demo environments,reference architectures and scenario walkthroughs behind them.
- Bring field evidence back to Product and Engineering to shape detection content and roadmap priorities.
Qualifications
- 7+ years in security operations, detection engineering, threat hunting, incident response or security architecture, including customer-facing or consulting experience.
Required Skills
- Hands-on background building and tuning detection content — you have written rules, measured how they performed, and improved them in production.
- Strong working knowledge of MITRE ATT&CK: technique mapping, coverage analysisand gap identification. Familiarity with MITRE ATLAS for AI and agent threats is a plus.
- Clear grasp of when a problem calls for deterministic detection logic and when it callsfor baseline, rarity or behavioural analytics.
- Hands-on SOAR and security automation experience (XSOAR, Splunk SOAR, Tines,Torq); you have built and maintained integrations and playbooks, not just operatedthem.
- Hands-on with several of: SIEM (Sentinel, Splunk, Chronicle/Google SecOps, Elastic),EDR/XDR, identity providers and IdP audit telemetry, CSPM/CNAPP, firewall andproxy — plus cloud security grounding in AWS, Azure or GCP.
- Comfortable reading and writing detection logic in a query language (KQL, SPL,Lucene, SQL), with Sigma or a similar portable format, and self-sufficient in Pythonfor enrichment, scripting and API work.
- Solid networking and endpoint fundamentals across Windows and Linux.
- Excellent written and verbal communication, with the range to move between a huntquery and a broader risk conversation.
- Comfortable working in a startup environment with high ownership.
Preferred Skills
- Background in an MSSP or with multi-tenant, content-centric security platforms.
- Exposure to agentic AI systems, LLM-driven investigation workflows, or AI security.
- Detection-as-code experience: Git-based workflows, CI/CD, versioned and testedcontent.
- Certifications such as GCIA, GCTI, GCFA, CISSP or a cloud security specialty.
Do you fit? then DM your resume to rajeshwari.vh@careerxperts.com
Click on Apply to know more.