M365 Security Architect
Openkyber
Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.
Years Required/Preferred Experience 8 Required Progressive SOC / security operations experience, including 2+ years functioning at a Tier 3 / senior analyst or detection engineering level.
8 Required Hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
8 Required Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred)
8 Required Practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with clear understanding of data sanitization and safe-use boundaries in a regulated environment.
8 Required Working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
8 Required Strong scripting/automation ability (PowerShell, Python, or Falcon Query Language-based automation) for building custom detections and integrations.
8 Required Excellent written communication skills for incident reporting, runbook authorship, and cross-divisional coordination.
8 Required Experience documenting investigations, creating hunt reports, and communicating technical findings to diverse audiences.
8 Required Strong analytical, problem-solving, and critical-thinking skills
8 Required Ability to work independently while collaborating effectively within cross-functional cybersecurity teams.
8 Required Ability to resolve complex security issues in diverse and decentralized environments; learn, communicate, teach new security technologies; and communicate effectively.
8 Required Conduct forensic investigations on cyberattacks to determine how they occurred and can be prevented in the future.
8 Required Experience creating/reviewing/updating security policies and standards for the public/private/hybrid cloud contexts.
4 Required Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience.
1 Preferred GIAC certifications (GCIH, GCIA, GCFA) or equivalent.
1 Preferred CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.
1 Preferred Torq certification or demonstrated portfolio of built automation workflows
1 Preferred Experience designing AI-assisted playbooks or analyst copilots for SOC use cases while maintaining strict data-handling guardrails.
1 Preferred Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.
1 Preferred Experience in government, legal, or law-enforcement-adjacent security environments
- Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
- Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).
- Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.
- Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.
- Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.
- Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
- Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
- Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
- Participate in an on-call rotation for critical incident escalations.
The above job description and requirements are general in nature and may be subject to change based on the specific needs and requirements of the organization and project.
For applications and inquiries, contact:View email address on us.fitly.work
- ...Job title OT Security Architect Work location - Bedford, Indiana--Hybrid Contract duration 6 months No CPT,OPT,H1B Mandatory skills - The role focuses on Rockwell PLC (ControlLogix/CompactLogix) systems, Ignition SCADA, and compliance with EU Cyber Resilience Act (...SuggestedContract workWork experience placementH1b
- ...Job Title: Sr. Security Consultant Location: Columbus, OH (Hybrid 3 Days Onsite) Preference: Local to Ohio or EST Time Zone Candidates Preferred Job Summary We are looking for a highly experienced Senior Security Consultant to lead the design and implementation of enterprise...SuggestedLocal area
$250k - $350k
...leading AI cybersecurity firm is seeking a Staff AI Solutions Architect. This role is crucial for designing and implementing AI-driven... ...degree in a relevant field and a passion for solving real-world security challenges. This position offers a hybrid work model and a...Suggested$122.6k
...Job Description CDM Smith is seeking a Senior Enterprise Architect to join our Corporate Business Technology team. This role is responsible... ...patterns that connect business capabilities with scalable, secure, and integrated technology solutions. This individual will...SuggestedWork experience placementH1bRemote work$150.16k
.... Job Description CDM Smith is seeking a Lead Enterprise Architect to join our Corporate Business Technology team. In this role, you... ...with business and technology stakeholders to deliver scalable, secure, and integrated solutions across the enterprise application...SuggestedWork experience placementH1bRemote work- ...assets and maintaining the integrity of cybersecurity infrastructure within the organization. It involves developing and implementing security strategies, tools, and technologies to defend against cyber threats and vulnerabilities. The role is distinguished by its focus on...Full timeTemporary workPart timeWork experience placementLocal areaFlexible hours
- ...Security Engineer TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response...
- ...Job Description Job Description Foresite is seeking a highly motivated and passionate Security Engineer with a specialized focus on Google Security Operations (SecOps) to join our growing team. In this client-facing role, you will be instrumental in helping our...Temporary work
- ...Details Stefanini Group is hiring! Stefanini is looking for a Security Engineer -Remote For quick Apply, please reach out t o Vaibhav Srivastava: (***) ***-****/ ***email_hidden*** W2 candidates only! Responsibilities This Engineer uses technology to improve...Temporary workWork experience placementWork at officeLocal areaRemote workNight shift
$195k
...delivering trusted trading, exchange, and market technology solutions across derivatives, foreign exchange, digital assets, and securities. The organisation operates critical infrastructure across global offices and data centres, with a strong focus on security, reliability...Full time$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you’ll collaborate...Work at officeRemote work- ...play a critical role in designing, implementing and safeguarding our clients' IT networks and systems by delivering industry-leading security solutions tailored to their unique needs. You will work in a fast-paced environment where you'll design, implement, manage and...Extra incomePart timeWork at officeLocal area
- ...We are looking for a a Cyber Security Engineer to join our Information Security Team in Kasas City. The work involves SIEM/SOC operations, endpoint protection, network security, and privileged access management. We are looking for hands-on experience with modern security...Work experience placementRemote work
- ...Cyber Security Engineer Location: Bellevue WA, Overland Park KS, Frisco TX, Ravinia GA, or Herndon VA Onsite position Duration: 12 months JD: Cyber Security: 10+ Years Java, frameworks, Python, Nodejs: 5+ Years Threat Modelling like STRIDE, PASTA, TRIKE...
- ...Corrective Action opportunities as needed. Define and maintain application & technology roadmaps which ensure deployed solutions are secure, resilient, scalable, and aligned with vendor lifecycles & the overall BV portfolio strategy. Partner with business, technical, and...Full timePart timeWork experience placementRelocationVisa sponsorshipFlexible hours
- ...Job Description Job Description Foresite is looking for a highly technical, results-oriented Cloud Security Engineer to serve as the technical lead for onboarding customers to GCP Security Command Center (SCC) and Wiz. In this role, you will be the driving force...Temporary work
- Tenex.AI is seeking a Lead Cloud Security Engineer to own cloud security health checks and remediation guidance across AWS, GCP, and Azure. You will work with SOC to improve detection, runbooks, and incident response, while advising customers on posture improvements and...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to M365 Security Architect. Be the first to apply!


