SecOps Security Architect - North Central region (Remote in the U.S.)
General Description
We are looking for an experienced Security Operations and Data Architect to support presales, solution architecture, engagement scoping, and technical delivery across SecOps and Data Analytics services. This role will engage in the development of target architectures, professional-services solutions, and technology roadmaps while providing “Wow Them” service to clients, internal customers, and co-workers.
The Security Operations and Data Architect must demonstrate strong architecture, consulting, presales, and executive communication skills. The architect must lead through influence and apply strong business and financial acumen when developing solutions that align delivery objectives, client priorities, technical feasibility, level of effort, delivery risk, and expected business outcomes.
About the North Central region SecOps Practice
The Security Operations Practice is responsible for helping clients design, implement, optimize, and mature the technologies and operating models used to manage security and operational data. We deliver advisory and engineering services across SOC, SIEM, SOAR, security telemetry, data analytics, observability, detection engineering, automation, and emerging AI-enabled Security Operations.
Our team of architects, consultants, SecOps engineers, data engineers, and platform specialists focuses on architecture, technical delivery, platform integration, data quality, detection coverage, automation, and operational maturity. We partner with account executives, project managers, technology providers, client leadership, and engineering teams to develop practical and supportable solutions.
Key areas of focus include:
Connecting client requirements to appropriate technologies and service offerings.
Improving the accuracy and consistency of technical scoping and delivery.
Developing repeatable architectures, estimation models, and implementation standards.
Roles and Responsibilities:
Lead technical discovery and translate client objectives, environments, constraints, and risks into current-state and target-state architectures.
Provide presales support by developing solution approaches, architecture diagrams, technical presentations, proposals, and responses to client requirements.
Define engagement scope, activities, assumptions, dependencies, responsibilities, exclusions, deliverables, acceptance criteria, and level-of-effort estimates.
Provide architectural leadership and technical oversight across SecOps Engineering and Data Analytics engagements.
Evaluate SIEM, SOAR, data pipeline, observability, automation, AI, and related technologies against client use cases, integration requirements, operating models, and existing investments.
Develop and maintain reference architectures, discovery questionnaires, scoping tools, estimation models, implementation patterns, and technical standards.
Mentor SecOps Engineers and SecOps Data Engineers while reviewing designs and deliverables for technical accuracy, scope alignment, and maintainability.
Partner with account executives and regional sales teams to qualify opportunities, shape services, identify technical risks, and establish realistic client expectations.
Support strategic client engagements, architecture workshops, technical escalations, and delivery-quality reviews.
Maintain awareness of regional pipeline, delivery capacity, technology demand, and skills requirements to help align opportunities with available practice capabilities.
Required Experience and Education:
Seven to ten years of experience in security operations, security architecture, SIEM engineering, data engineering, observability, consulting, or related fields.
Demonstrated experience designing or leading SIEM, SOAR, security telemetry, data pipeline, observability, or security analytics engagements.
Experience conducting client discovery, developing solution architectures, scoping professional-services engagements, and estimating engineering effort.
Advanced understanding of SOC operating models, SIEM, SOAR, detection engineering, automation, security telemetry, data pipelines, and observability.
Experience identifying technical assumptions, dependencies, delivery risks, acceptance criteria, and scope boundaries.
Working knowledge of cloud architecture, APIs, authentication, networking, data formats, schemas, integration patterns, and access-control concepts.
Ability to review technical queries, scripts, transformations, detection logic, automation workflows, and architecture documentation.
Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related field, or equivalent professional and military experience.
Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes.
Preferred Experience and Education
Security architecture certification such as CISSP, ISSAP, SABSA, or a comparable credential.
SIEM certification from Splunk, Microsoft, Google, Elastic, Palo Alto Networks, CrowdStrike, Rapid7, Sumo Logic, or Datadog.
SOAR or automation certification from Splunk SOAR, XSOAR, Fusion, SentinelOne HyperAutomation, Torq, or Tines.
Data pipeline or observability certification from Cribl, Onum, Databahn, Datadog, Dynatrace, Splunk, or Elastic.
Cloud architecture or security certification from AWS, Microsoft Azure, or Google Cloud.
Experience supporting account executives through technical presales, proposal development, and client presentations.
Experience developing service offerings, estimation models, reference architectures, or reusable consulting methodologies.
Travel Requirements:
Up to 10% travel
Physical Requirements:
Sedentary work
Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day