We are looking for a Solutions Architect who is the technical lead in our customer conversations: designing how fits a given environment, running evaluations and proof-of-value engagements, and making customer teams genuinely capable at operating an
AI SOC.
You will work directly with detection engineers, threat hunters, SOC leads and CISOs. Expect deep technical discussions on telemetry design, analytic strategy, MITRE coverage and prioritisation logic, and expect to be the person who turns "here is our setting and here is what we need to prioritize" into a working architecture. This is a hands-on individual contributor role.
Responsibilities
- Lead technical discovery: map available telemetry, retention, existing detection coverage and blind spots across a customer's estate.
- Design the analytic approach for each environment — which signals matter, what runs as a real-time detection, and what runs as a hypothesis-driven hunt.
- Own technical evaluations and POVs end to end: agree success criteria, build the environment, run the scenarios, present the results.
- Run detection coverage and telemetry-gap analysis mapped to MITRE ATT&CK;, and turn customer scenarios and post-incident retrospectives into concrete detection and hunt strategy.
- Configure the environment-specific context that makes analytics precise: privileged and VIP accounts, critical assets, approved regions and service principals, sanctioned tooling.
- Build SOAR and automation integrations that connect findings to the customer's response tooling, and support onboarding across connectors, data paths,
authentication and multi-tenant design.
- Run workshops and technical deep dives, and maintain the demo environments,
reference architectures and scenario walkthroughs behind them.
- Bring field evidence back to Product and Engineering to shape detection content and roadmap priorities.
Requirements
- 7+ years in security operations, detection engineering, threat hunting, incident response or security architecture, including customer-facing or consulting experience.
- Hands-on background building and tuning detection content — you have written rules, measured how they performed, and improved them in production.
- Strong working knowledge of MITRE ATT&CK;: technique mapping, coverage analysis and gap identification. Familiarity with MITRE ATLAS for AI and agent threats is a plus.
- Clear grasp of when a problem calls for deterministic detection logic and when it calls for baseline, rarity or behavioural analytics.
- Hands-on SOAR and security automation experience (XSOAR, Splunk SOAR, Tines,
Torq); you have built and maintained integrations and playbooks, not just operated them.
- Hands-on with several of: SIEM (Sentinel, Splunk, Chronicle/Google SecOps, Elastic),
EDR/XDR, identity providers and IdP audit telemetry, CSPM/CNAPP, firewall and proxy — plus cloud security grounding in AWS, Azure or GCP.
- Comfortable reading and writing detection logic in a query language (KQL, SPL,
Lucene, SQL), with Sigma or a similar portable format, and self-sufficient in Python for enrichment, scripting and API work.
- Solid networking and endpoint fundamentals across Windows and Linux.
- Excellent written and verbal communication, with the range to move between a hunt query and a broader risk conversation.
- Comfortable working in a startup environment with high ownership.
Nice to have
- Background in an MSSP or with multi-tenant, content-centric security platforms.
- Exposure to agentic AI systems, LLM-driven investigation workflows, or AI security.
- Detection-as-code experience: Git-based workflows, CI/CD, versioned and tested content.
- Certifications such as GCIA, GCTI, GCFA, CISSP or a cloud security specialty.
Do you fit? then DM your resume to
[email protected]
📌 Solution Architect - Presales - Cyber Security Startup - CTC INR 50 L (Pune)
🏢 CareerXperts Consulting
📍 Pune