2 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄
AI SOC Solutions Architect (Cybersecurity)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Π’Π΅ΠΊΡΡ:
TL;DR
AI SOC Solutions Architect (Cybersecurity) (AI-driven SOC automation): Designing and delivering agent-assisted security workflows for enterprise customers with an accent on alert triage, threat investigation, incident response, and integrations across SIEM and EDR/XDR platforms. Focus on engineering trustworthy AI agent behavior, building REST API integrations, and reducing analyst workload and mean time to respond.
Location: Remote, based out of Costa Rica
Company
develops an AI SOC platform that combines hyperautomation and agentic AI to automate enterprise security operations.
What you will do
- Design and implement AI-driven SOC automation, including agentic workflows and AI agents for alert triage, enrichment, investigation, and response.
- Translate Tier 1/2 SOC triage, investigation, and incident response runbooks into automated workflows on the platform.
- Own technical delivery for strategic accounts from architecture and implementation through validation and handoff.
- Build integrations with SIEM, EDR/XDR, identity provider, ticketing, and threat intelligence systems using REST APIs.
- Design, tune, and evaluate AI agent behavior, including prompts, guardrails, and human-in-the-loop checkpoints.
- Advise SOC leaders and analysts, resolve technical blockers, support adoption, and contribute field learnings to new Professional Services offerings.
Requirements
- 4β6+ years of experience in a technical security, SOC, incident response, cybersecurity Professional Services, or Solutions Architect role.
- Hands-on knowledge of alert triage, investigation, escalation, and the incident response lifecycle.
- Experience with at least one SIEM, such as Sentinel, Splunk, or Chronicle, and one EDR/XDR platform, such as CrowdStrike, Defender, or SentinelOne.
- Proficiency in Python, Bash, or Go, plus REST APIs, JSON, and webhooks.
- Practical experience with LLMs and agentic AI, including prompt engineering, agent evaluation, and mitigation of hallucination and over-automation risks.
- Ability to explain technical and AI concepts to analysts and CISOs, manage customer relationships, and coordinate multiple enterprise engagements.
Nice to have
- SOAR platform experience, particularly , XSOAR, Splunk SOAR/Phantom, or Chronicle SOAR.
- Detection engineering and query languages such as KQL, SPL, Sigma, or YARA.
- Experience with MCP, tool/function calling, RAG, vector stores, MSSP deployments, or cloud security fundamentals.
- Security, incident response, AI, or cloud certifications such as CISSP, GCIH, GCIA, GCFA, or an AI/cloud certification.
Culture & Benefits
- Work remotely from Costa Rica as part of a global Professional Services organization.
- Work on an AI-native autonomous SecOps platform for enterprise security teams.
- Collaborate in a fast-growing startup environment focused on security automation and applied AI.
- is an equal opportunity employer committed to diversity and inclusion.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β