JOB SUMMARY:The Senior Solutions Architect, Security Operations will be responsible for providing architect-level thought leadership and expertise across modern security operations including endpoint detection and response, SIEM/SOAR, agentic SOC, and AI-assisted detection engineering, and AI-ready threat, exposure, and vulnerability management, including continuous threat exposure management (CTEM), threat-informed prioritization, attack surface and attack path analysis, and closed-loop remediation validation. Under the direction of Security Operations leadership, the Senior Solutions Architect will lead Trace3's most complex client architecture engagements across these domains and translate that work into the reference architectures, offerings, and enablement that allow Trace3's regional technical teams to sell and deliver Security Operations solutions consistently and at scale. This is a client-facing, presales role in a practice built to lead where AI is rebuilding both how organizations detect and respond to threats and how they find, prioritize, and eliminate exposure.
SUMMARY OF ESSENTIAL JOB FUNCTIONS:- Lead client engagements as the senior architect for target-state SOC architecture, SIEM/SOAR modernization and consolidation, agentic SOC and AI-assisted detection design, and CTEM and vulnerability operations redesign, from discovery through executive readout.
- Assess client current state and deliver strategic, tactical, and operational recommendations that translate detection, response, and exposure capabilities into business risk, investment, and operating-model terms for CISO- and board-level audiences.
- Design target-state threat and exposure management architectures that unify vulnerability management, attack surface management (EASM/CAASM), cloud and container posture, identity exposure, and attack path analysis into a single prioritized view of risk.
- Define defensible risk scoring, remediation SLAs, and accountability models, combining threat intelligence, exploitability evidence (EPSS, KEV), asset criticality, and compensating controls, that client IT, cloud, and application owners will accept and execute.
- Architect the AI layer of security operations and exposure management, including agentic enrichment and deduplication of findings, automated remediation routing, natural-language executive reporting, and closed-loop validation through breach and attack simulation, penetration testing, and purple-team findings.
- Converge detection and exposure operations so exposure context informs detection and response prioritization, and detection, incident, and threat-hunting findings feed back into exposure prioritization, one threat-informed loop, not two disconnected programs.
- Govern the data foundation that agentic SOC and exposure workflows depend on: asset inventory and ownership fidelity, findings normalization across scanners and platforms, and security data pipeline and platform decisions.
- Author and maintain the practice's reference architectures, assessment frameworks, and packaged offerings, including SOC maturity and AI-readiness assessment, SIEM/SOAR migration, agentic SOC readiness, and exposure management program design, each with defined scope and a delivery playbook.
- Collaborate with Security Solutions practices, Regional teams, Managed Services, and Service Delivery to scope, design, and hand off engagements that can be delivered repeatably without the architect's continued involvement.
- Develop and deliver enablement and certification content for regional architects and sellers, including delivery playbooks for standardized work (EDR migration, SIEM onboarding, detection content standards) and opportunity qualification guidance.
- Serve as the practice's senior technical counterpart to priority Security Operations partners (such as Palo Alto Networks, CrowdStrike, Microsoft, and Google), influencing roadmaps, shaping joint offerings, and securing co-funded enablement and lab capacity.
- Support account teams on qualified opportunities with solution design, competitive positioning, proposal and SOW creation, and technical validation.
- Provide subject matter expertise on AI in security operations, AI-assisted triage, LLM-based detection engineering, agentic workflows, and agent governance, and stay current on the threat landscape, standards, and frameworks.
- Advocate for Trace3 through speaking engagements, publications, field briefings, and industry events.
- Mentor solutions architects, early-career practitioners, and interns across regions, transferring judgment as well as knowledge.
REQUIRED SKILLS AND EXPERIENCE:- Bachelor's degree in computer science, Cybersecurity or equivalent information security, engineering, or like discipline from an accredited college or university, or measurable knowledge / experience from proven industry, military, defense, or government operations.
- 8+ years' experience in security operations, exposure management, or both, including hands-on ownership of detection engineering, SIEM/SOAR content and automation, SOC operations, or enterprise vulnerability and exposure operations, beyond product implementation alone.
- Experience in a customer-facing presales, solutions architecture, or technology consulting role within a VAR, systems integrator, consultancy, or technology vendor.
- Deep expertise in at least two of the following: SIEM/SOAR platforms (e.g., Palo Alto Networks Cortex XSIAM, Microsoft Sentinel, Google SecOps, Splunk); endpoint/EDR/XDR (e.g., CrowdStrike Falcon, Microsoft Defender, SentinelOne); threat, exposure, and vulnerability management, including CTEM and attack surface management (e.g., Tenable, Qualys, Rapid7, Wiz, Axonius, XM Cyber, Cymulate); identity and cloud telemetry integration.
- Demonstrated ability to design target-state security operations architectures, including platform consolidation and migration strategy, detection-as-code, exposure-as-code, and SOC and exposure operating models.
- Demonstrated experience designing or operating a risk-based vulnerability management or CTEM program at enterprise scale, including asset inventory and ownership, findings normalization across multiple scanners and platforms, threat-informed prioritization, remediation SLAs, and executive-level exposure reporting.
- Working knowledge of exposure prioritization inputs and standards, including CVSS, EPSS, CISA KEV, and SSVC, and of threat intelligence enrichment, with a defensible point of view on where each is useful and where each misleads.
- Familiarity with attack path analysis, breach and attack simulation, and adversarial validation, and how each should inform remediation priority and measure program effectiveness.
- Practical experience building, evaluating, or operating AI-assisted security operations and exposure management capabilities, with an informed point of view on what works, what does not yet, and how such capabilities should be governed.
- Working knowledge of Cybersecurity Principles, Frameworks and Standards including NIST CSF, MITRE ATT&CK, MITRE D3FEND, ISO 27001, and CTEM-aligned exposure frameworks; familiarity with OWASP AI, the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework is a plus.
- Working knowledge and experience with at least one (preferably multiple) major cloud service providers (AWS, GCP, Azure) and their native security telemetry.
- Certifications such as GIAC (GCIA, GCDA, GCFA, GDAT), CISSP, or vendor architecture certifications on the platforms above are highly preferred.
- Experience in incident response, threat hunting, or purple-team detection validation is highly preferred.
- Prior experience packaging offerings, writing reference architectures, or running technical enablement or certification programs is highly preferred.
- Ability to conduct workshops, assessments, and executive briefings and to develop clear, concise reporting and recommendations.
- Knowledge and experience creating and maintaining technical documentation, presentations, plans, roadmaps, etc.
- Strong executive communication skills, including the ability to make complex security operations problems understandable to executives and to defend a recommendation under challenge.
- Strong interpersonal and communication skills are required.
- Strong customer presentation skills are required.
- Motivated self-starter who loves to solve challenging problems and feels comfortable working directly with customers.
- Highly organized, detail-oriented, excellent time management skills and able to effectively prioritize tasks in a fast-paced, high-volume, and evolving work environment.
- Comfortable managing multiple and changing priorities, and meeting deadlines in an entrepreneurial environment.
- Ability to travel when needed (approximately 25-35%); holds a valid driver's license
Actual salary will be based on a variety of factors, including location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that is not included in the base salary.
Estimated Pay Range
$175,000-$200,000 USD
The Perks- Comprehensive medical, dental and vision plans for you and your dependents
- 401(k) Retirement Plan with Employer Match, 529 College Savings Plan, Health Savings Account, Life Insurance, and Long-Term Disability
- Competitive Compensation
- Training and development programs
- Major offices stocked with snacks and beverages
- Collaborative and cool culture
- Work-life balance and generous paid time off