M365 Security Architect
Openkyber
Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.
Years Required/Preferred Experience 8 Required Progressive SOC / security operations experience, including 2+ years functioning at a Tier 3 / senior analyst or detection engineering level.
8 Required Hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
8 Required Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred)
8 Required Practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with clear understanding of data sanitization and safe-use boundaries in a regulated environment.
8 Required Working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
8 Required Strong scripting/automation ability (PowerShell, Python, or Falcon Query Language-based automation) for building custom detections and integrations.
8 Required Excellent written communication skills for incident reporting, runbook authorship, and cross-divisional coordination.
8 Required Experience documenting investigations, creating hunt reports, and communicating technical findings to diverse audiences.
8 Required Strong analytical, problem-solving, and critical-thinking skills
8 Required Ability to work independently while collaborating effectively within cross-functional cybersecurity teams.
8 Required Ability to resolve complex security issues in diverse and decentralized environments; learn, communicate, teach new security technologies; and communicate effectively.
8 Required Conduct forensic investigations on cyberattacks to determine how they occurred and can be prevented in the future.
8 Required Experience creating/reviewing/updating security policies and standards for the public/private/hybrid cloud contexts.
4 Required Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience.
1 Preferred GIAC certifications (GCIH, GCIA, GCFA) or equivalent.
1 Preferred CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.
1 Preferred Torq certification or demonstrated portfolio of built automation workflows
1 Preferred Experience designing AI-assisted playbooks or analyst copilots for SOC use cases while maintaining strict data-handling guardrails.
1 Preferred Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.
1 Preferred Experience in government, legal, or law-enforcement-adjacent security environments
- Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
- Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).
- Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.
- Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.
- Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.
- Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
- Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
- Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
- Participate in an on-call rotation for critical incident escalations.
The above job description and requirements are general in nature and may be subject to change based on the specific needs and requirements of the organization and project.
For applications and inquiries, contact:View email address on us.fitly.work
- ...Enterprise Architecture role shall have one of the following certifications or an applicable equivalent: Certified Information Systems Security Officer (CISSO), Certified Information Systems Security Professional (CISSP), GIAC Certified Intrusion Analyst (GCIA), GIAC Cloud...SuggestedFull timeFor contractors
$182.75k - $247.25k
...is a Combatant Command responsible for strategic deterrence, nuclear operations, and enterprise IT services essential to national security. It oversees Nuclear Command, Control, and Communications (NC3), Joint Electromagnetic Spectrum Operations (JEMSO), Global Strike,...SuggestedFull timeTemporary workImmediate startRemote workWorldwideRelocationFlexible hours- ...Solutions Engineers are part problem solvers and part architect. They operate in close partnership with our sales, solutions strategy... ...whether you’re an engineer, developer, products guru, systems and security expert, sales and consulting executive, or an intern looking...SuggestedInternshipLocal areaRemote work
- ...Engineer I (Data Manager)Job Description Seeking a motivated and out-going individual for a Data Manager position within an Information Security Services team. A Data Manager works jointly with Data Custodians and systems support personnel to facilitate the collection,...SuggestedWorldwideFlexible hoursNight shift
- ...connect financial institutions, corporations, merchants and consumers to one another millions of times a day - quickly, reliably, and securely. Any time you swipe your credit card, pay through a mobile app, or withdraw money from the bank, we're involved. If you want to...SuggestedFull timeTemporary workH1bWork at officeMonday to Friday
$135k - $150k
...our focus on creativity and innovative solutions empowers our customer communities to thrive.We are seeking a Senior Application Security Engineer to lead hands-on application security testing, secure code review, and secure SDLC enablement across moder application environments...Full timeTemporary workWork at officeLocal areaRemote work3 days per week- A major financial services firm is seeking an entry-level Application Security Analyst in Omaha, Nebraska. In this role, you will build security controls into software, support dynamic application security testing, and collaborate with developers to address vulnerabilities...
- ...your professional development on one of the most ambitious engineering ventures of the century. In this role you will: Design security solutions Conduct vulnerability assessments Support accreditation and compliance Embed security through lifecycle...Full timeWork at officeWork from homeFlexible hours
- ...Description Job Description Role: Senior Principal Cyber Engineer Architect III REQUIRED: Minimum Active Clearance: Active TS/SCI... ...U.S. federal government require our employees to be granted security clearances. Constellation West strives to provide fully...For contractorsWork experience placementFor subcontractorWorldwideRelocation package
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to M365 Security Architect. Be the first to apply!


