17 Sep
|
CareerXperts Consulting
|
Pune
17 Sep
CareerXperts Consulting
Pune
We are looking for a Solutions Architect who is the technical lead in our customer
conversations: designing how fits a given environment, running evaluations and
proof-of-value engagements, and making customer teams genuinely capable at operating an
AI SOC.
You will work directly with detection engineers, threat hunters, SOC leads and CISOs. Expect
deep technical discussions on telemetry design, analytic strategy, MITRE coverage and
prioritisation logic, and expect to be the person who turns here is our environment and
here is what we need to prioritize into a working architecture. This is a hands-on individual
contributor role.
Responsibilities
• Lead technical discovery: map available telemetry, retention, existing detection
coverage and blind spots across a customer's estate.
• Design the analytic approach for each environment — which signals matter, what
runs as a real-time detection, and what runs as a hypothesis-driven hunt.
• Own technical evaluations and POVs end to end: agree success criteria, build the
environment, run the scenarios, present the results.
• Run detection coverage and telemetry-gap analysis mapped to MITRE ATT&CK;, and
turn customer scenarios and post-incident retrospectives into concrete detection and
hunt strategy.
• Configure the environment-specific context that makes analytics precise: privileged
and VIP accounts, critical assets, approved regions and service principals, sanctioned
tooling.
• Build SOAR and automation integrations that connect findings to the
customer's response tooling, and support onboarding across connectors, data paths,
authentication and multi-tenant design.
• Run workshops and technical deep dives, and maintain the demo environments,
reference architectures and scenario walkthroughs behind them.
• Bring field evidence back to Product and Engineering to shape detection content and
roadmap priorities.
Requirements
• 7+ years in security operations, detection engineering, threat hunting, incident
response or security architecture, including customer-facing or consulting
experience.
• Hands-on background building and tuning detection content — you have written
rules, measured how they performed, and improved them in production.
• Strong working knowledge of MITRE ATT&CK;: technique mapping, coverage analysis
and gap identification. Familiarity with MITRE ATLAS for AI and agent threats is a plus.
• Clear grasp of when a problem calls for deterministic detection logic and when it calls
for baseline, rarity or behavioural analytics.
• Hands-on SOAR and security automation experience (XSOAR, Splunk SOAR, Tines,
Torq); you have built and maintained integrations and playbooks, not just operated
them.
• Hands-on with several of: SIEM (Sentinel, Splunk, Chronicle/Google SecOps, Elastic),
EDR/XDR, identity providers and IdP audit telemetry, CSPM/CNAPP, firewall and
proxy — plus cloud security grounding in AWS, Azure or GCP.
• Comfortable reading and writing detection logic in a query language (KQL, SPL,
Lucene, SQL), with Sigma or a similar portable format, and self-sufficient in Python
for enrichment, scripting and API work.
• Solid networking and endpoint fundamentals across Windows and Linux.
• Excellent written and verbal communication, with the range to move between a hunt
query and a broader risk conversation.
• Comfortable working in a startup setting with high ownership.
Nice to have
• Background in an MSSP or with multi-tenant, content-centric security platforms.
• Exposure to agentic AI systems, LLM-driven investigation workflows, or AI security.
• Detection-as-code experience: Git-based workflows, CI/CD, versioned and tested
content.
• Certifications such as GCIA, GCTI, GCFA, CISSP or a cloud security specialty.
Do you fit then DM your resume to [HIDDEN TEXT]
📌 Solution Architect - Presales - Cyber Security Startup - CTC INR 50 L (Pune)
🏢 CareerXperts Consulting
📍 Pune