> Markdown version of [/jobs/ext/2187700-security-architect-managed-security-services](https://www.wearedevelopers.com/jobs/ext/2187700-security-architect-managed-security-services). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - Managed Security Services - **Company:** Bespin Global U.S., Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $150,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Data Analysis, Software System Penetration Testing, Computer Vision, Microsoft Azure, Cloud Computing, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Mesh Networking, Parsing, Windows PowerShell, Red Team (Cyber Security), Zero Trust Network Access, Service Design, Security Information and Event Management, Web Testing, Google Cloud, Data Ingestion, Software Security, Mitre Att&ck, Multi-Cloud, Information Technology, Deployment Automation, CIS Benchmarks, SentinelOne Expertise - **Published:** August 22, 2026 - **Apply:** https://ats.rippling.com/bgus-job/jobs/e461227e-f32d-4f36-a8c7-7d40a741e2fb ## About the Role SIEM / detection & response Google SecOps, Elastic, Coralogix Endpoint SentinelOne, CrowdStrike Cloud security posture Wiz Telemetry pipeline, * 7+ years in security engineering, security operations, or security consulting, including hands-on ownership of a SIEM platform * Deep, hands-on experience with at least one modern SIEM - Google SecOps (Chronicle), Elastic, or Coralogix strongly preferred - including data onboarding, parsing and normalization, and detection authoring * Hands-on experience deploying and operating EDR/XDR platforms; SentinelOne and CrowdStrike specifically preferred * Experience with a CSPM/CNAPP platform such as Wiz, including policy baselines and risk-based remediation workflows * Working knowledge of SOAR platforms and automation of security workflows * Strong cloud security fundamentals across AWS, Google Cloud, or Azure - native security services, identity, and posture management - with the ability to work in at least two * Scripting and automation skills (Python, PowerShell, or equivalent) and comfort with infrastructure-as-code * Demonstrated ability to communicate directly with customers - running technical workshops, presenting findings, and handling escalations with credibility * Working familiarity with common frameworks and standards (MITRE ATT&CK, NIST CSF, CIS Benchmarks, SOC 2) Preferred * Prior experience in an MSSP, MSP, or consulting environment supporting multiple customers concurrently * Incident response experience, including leading investigations end to end * Multi-cloud breadth across AWS, Google Cloud, and Azure * Experience with telemetry pipeline tooling (BindPlane, OpenTelemetry, Cribl, or similar) and log cost optimization * Familiarity with zero-trust or mesh networking tools such as Tailscale for customer environment access * Certifications such as GCIA, GCIH, GCDA, CISSP, OSCP, or cloud security specialty credentials * Experience with detection-as-code practices and CI/CD for security content * Exposure to pre-sales solutioning and SOW development, Designs and engineers secure network and cloud architectures across AWS, GCP, Azure, and physical data centers. Responsibilities include threat modeling, network segmentation, monitoring, alerting, automation, attack-surface reduction, and secure connection patterns. The role drives strategic security improvements, partners with product and infrastructure teams, communicates architectural decisions, and mentors engineers. Candidates need deep hybrid networking and cloud security expertise, protocol knowledge, scripting ability, independent problem-solving skills, and strong communication. Top Skills: AIApplied CryptographyAWSAzureCi/CdDnsGCPGoHttp/SHybrid Cloud NetworkingPrivate EndpointsPythonService MeshesShell ScriptingTcp/IpTlsTransit GatewaysVpcsZero Trust Architecture ## Description Bespin Global US delivers managed security services to organizations that need enterprise-grade detection and response without building it themselves - endpoint detection and response (EDR), 24x7 SOC services, SIEM and SOAR management, security assessments, and cloud security posture management (CSPM). This role sits at the center of that practice with a dual mandate. You will engineer the platform our services run on - the SIEM/SOAR pipelines, EDR deployments, detection content, and integrations that our analysts depend on - and you will be the senior technical voice with customers, scoping new engagements, leading onboarding, and advising security leaders on how to mature their programs. This is not a shift-based SOC seat. You are the person who decides how the service works, then makes it work for each customer. What You'll Do Platform & Detection Engineering * Own the architecture and build-out of the multi-tenant SIEM and SOAR environments underpinning our managed detection services - primarily Google SecOps, with Elastic and Coralogix supporting customer-specific and log analytics use cases * Design and deploy EDR tooling across customer estates using SentinelOne and CrowdStrike; standardize policies, exclusions, and response actions * Build and maintain detection content - correlation rules, analytics, and use cases mapped to MITRE ATT&CK - and tune continuously to reduce false positives * Develop SOAR playbooks that automate triage, enrichment, containment, and notification workflows * Engineer log ingestion and normalization pipelines with BindPlane across cloud, endpoint, identity, and network sources; manage data volume, routing, and ingest cost * Stand up and maintain Wiz for cloud security posture management across AWS, Google Cloud, and Azure; define policy baselines, risk prioritization, and remediation guidance * Design and maintain secure connectivity into customer environments using Tailscale, keeping collector and management access least-privilege and auditable * Automate deployment and configuration through infrastructure-as-code and scripting rather than manual, per-customer work * Evaluate new security tooling and make build-vs-buy recommendations for the practice Customer-Facing Delivery & Advisory * Lead technical discovery and scoping for prospective customers; translate their environment and risk profile into a service design * Own the technical execution of customer onboarding - from log source integration through first tuned detections and validated response workflows * Serve as the escalation point and trusted advisor for the customer's security stakeholders after go-live * Conduct security assessments and cloud posture reviews; present findings and prioritized remediation roadmaps to technical and executive audiences * Partner with sales on solution design, technical proposals, and statements of work * Produce reference architectures, runbooks, and documentation that let the SOC and delivery teams operate what you build, * First 90 days: fluent in our service stack and delivery model; leading onboarding for at least one new customer; first detection content improvements shipped * First 6 months: owning the technical design of the SIEM/SOAR platform; measurable reduction in false-positive volume; recognized as the escalation point across the delivery team * First year: onboarding is faster and more repeatable than when you arrived; detection coverage is measurably broader; customers name you as a reason they stay Why Bespin You will have real ownership over how a growing managed security practice is built - not a narrow slice of someone else's platform. The work spans engineering depth and customer impact, and you will see the results of both across every account we run. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof](https://www.wearedevelopers.com/videos/1792-developer-time-is-valuable-use-the-right-tools-kilian-valkhof) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Building a Compiler with C#](https://www.wearedevelopers.com/videos/116-building-a-compiler-with-c) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)