Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
ES

Threat Management Architect

Epsilon Solutions LTD
๐ŸŒ Worldwide
Remote
Staff / Principal
2 months ago
  • Threat Intelligence
  • SIEM
  • triage
  • EDR
  • SoCs
  • GCIA
  • GCIH
  • OSCP
  • CISSP
  • Storyline
  • Fabric
  • Splunk
  • Microsoft Sentinel
  • ServiceNow
  • Jira
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV
Title: Threat Management Architect
Preferred Locations: Kansas City, MO, Houston, TX, Austin, TX (Remote is also an option - Anywhere in USA or Canada)
Duration: 6-12 Months Contract

Position Summary
The Threat Management Architect owns the design, standardization, and continuous evolution of detection and response capability across clients global managed services portfolio. This role operates above individual client engagements, setting the architectural blueprint that SOC L1/L2/L3 teams, detection engineering, and threat intelligence operate within across regions and time zones. The Architect translates the evolving threat landscape and platform capabilities (SentinelOne, Meridian, SIEM/XDR, SOAR) into a coherent, repeatable detection and response architecture, and acts as the technical authority bridging client-facing teams, service delivery, and product/engineering.
Key Responsibilities
1. Detection & Response Architecture
  • Define the reference architecture for threat detection, triage, and response spanning EDR/XDR (e.g., SentinelOne), SIEM, identity/entity intelligence and SOAR across all managed service tiers.
  • Establish global standards for alert severity models, escalation matrices, and SLA-aligned response workflows that scale consistently across regional SOCs.
  • Own the technical roadmap for closing detection coverage gaps against the current threat landscape and MITRE Telecommunication&CK framework.
2. Global Playbook & Runbook Standardization
  • Design a master playbook framework used as the baseline across all regions, ensuring L1โ€“L3 analysts and automation follow consistent, auditable decision logic regardless of geography.
  • Govern the lifecycle of playbooks: creation, regional localization, version control, retirement, and post-incident revision based on lessons learned.
  • Partner with detection engineering and SOAR teams to convert playbooks into automated response workflows, prioritizing high-volume/low-complexity alert types for automation first.
3. Cross-Regional Program Consistency
  • Act as the architectural authority across follow-the-sun SOC operations, ensuring handoffs between regions preserve context, investigative continuity, and case fidelity.
  • Audit regional SOC practices against the global architecture and drive remediation where drift occurs.
  • Support onboarding of new managed services regions/teams with a consistent technical foundation.
4. Platform & Tooling Strategy
  • Serve as the technical lead in platform evaluation, integration design, and lifecycle decisions for core managed services tooling (EDR, SIEM, SOAR, identity/entity intelligence).
  • Define integration architecture between SentinelOne and identity/entity context layers (e.g., Meridian) to enrich investigations with blast-radius and identity risk context.
  • Own technical relationships with key platform vendors' architecture/engineering counterparts.
5. Threat Intelligence Integration
  • Establish the process by which threat intelligence (emerging TTPs, campaign activity, sector-specific threats) is operationalized into detection content and playbooks globally.
  • Lead architecture-level response to major/emerging threats (e.g., Client ransomware TTPs, supply-chain compromises), coordinating rapid playbook and detection updates across regions.
6. Advisory & Enablement
  • Serve as a senior technical advisor in client escalations, executive briefings, and strategic account reviews requiring architecture-level explanation of detection/response capability.
  • Mentor SOC leads, detection engineers, and L2/L3 analysts on architectural principles behind playbooks and tooling decisions.
  • Partner with sales engineering and Field CTO functions to represent managed services architecture in pre-sales and competitive positioning contexts.
Required Qualifications
  • 8+ years in security operations, with 3+ years in an architecture, engineering lead, or technical program lead capacity within a managed services/MSSP environment.
  • Deep hands-on expertise with EDR/XDR platforms (SentinelOne strongly preferred), SIEM, and SOAR/orchestration tooling.
  • Demonstrated experience designing and governing detection/response playbooks at scale across multiple teams or client environments.
  • Strong grasp of global/follow-the-sun SOC operating models and the architectural challenges of cross-regional consistency.
  • Working knowledge of identity-centric attack paths and entity/behavioral risk concepts (e.g., blast radius, lateral movement, privilege escalation).
  • Excellent written and verbal communication skills; comfortable operating at both engineering depth and executive/advisory altitude.
Preferred Qualifications
  • Prior experience architecting managed detection and response (MDR) service offerings for an MSSP or MSP.
  • SentinelOne certification(s), plus SOAR platform experience (e.g., Palo Alto XSOAR, Swimlane, Tines).
  • Exposure to identity/entity intelligence platforms (e.g., Axonius) and how they integrate with EDR/SIEM architectures.
  • Advanced certifications: GSE, GCIA, GCIH, OSCP, CISSP, or equivalent.
  • Experience supporting global, multi-region client bases spanning varied regulatory and data residency requirements.
Core Tools & Technologies :
Category Tools
EDR / XDR SentinelOne Singularity Platform (Console, Deep Visibility, Storyline, RemoteOps, Ranger)
Identity / Entity Intelligence Entity fabric / identity risk platforms
SIEM Splunk, Microsoft Sentinel, or equivalent
Orchestration / SOAR Palo Alto XSOAR, Swimlane, Tines, or equivalent
Case Management ServiceNow, Jira, or client-provided systems, standardized across regions
Threat Intelligence Commercial/open-source TI feeds integrated into detection and playbook pipelines

Threat Management Architect ยท Epsilon Solutions LTD

Auto apply with Likeremote