Cyber Security Lead Architect
Location: McKinney, TX; Buffalo, NY; Golden Valley, MN
Department: Service Delivery
About the role
The Cyber Security Lead Architect – SOC & Incident Response is the senior technical authority responsible for architecting, governing, and continuously improving security detection, response, and incident handling capabilities within a Managed Security Services Provider (MSSP) environment. This role bridges security architecture and frontline SOC execution, ensuring tools, detections, workflows, and response processes are designed for scale, speed, and consistency across multiple clients. The Lead Architect serves as the highest escalation point for complex incidents and ensures SOC operations remain defensible, repeatable, and mature.
What you'll do
SOC Architecture & Operational Leadership
· Define SOC architecture standards across SIEM, SOAR, EDR, XDR, and vulnerability platforms
· Architect SOC workflows supporting 24x7 monitoring, triage, and escalation
· Partner with SOC leadership to reduce alert noise and increase analyst effectiveness
· Ensure SOC tooling scales across diverse client environments
Incident Response Architecture & Escalation
· Act as senior escalation point for high-severity incidents
· Design and maintain incident response playbooks and runbooks
· Provide architectural guidance during active incidents
· Ensure incident handling aligns with SLAs and regulatory obligations
Detection Engineering & Threat Enablement
· Architect and govern SIEM and EDR detection strategies
· Oversee detection lifecycle management
· Ensure detection logic reflects real-world attacker behavior
Leadership & Collaboration
· Act as regional team lead / manager for SOC team members
· Mentor SOC leads, senior analysts, and engineers
· Serve as trusted advisor to leadership and clients
· Collaborate with Cyber Platform Engineering, vCISO, and Compliance teams
Qualifications
Required:
- 8+ years practical experience in cybersecurity with SOC or MSSP focus, including threat detection, incident response, and vulnerability management.
- Proficiency with SIEM tools (Stellarcyber, LevelBlue, Splunk, QRadar, etc.) and vulnerability scanners (Tenable, Qualys etc.).
- Strong understanding of network protocols, operating systems (Windows/Linux), firewalls, IDS/IPS, VPN’s, cloud security platforms (AWS, Azure) and endpoint security solutions.
- Familiarity with security frameworks like MITRE, NIST, ISO 27001, or CIS benchmarks.
- Experience with incident response processes and malware analysis.
- Excellent analytical skills, attention to detail, and ability to work under pressure.
- Strong communication skills to effectively collaborate with technical and non-technical teams
- Having experience in a client-facing role is beneficial for offering insights into the client's security posture
Preferred:
- Bachelor’s degree in Cybersecurity, Computer Science, or a related field.
- Relevant certifications are a plus, such as CISSP-ISSEP, CISSP-ISSAP, CEH (Certified Ethical Hacker), CompTIA CySA+, CompTIA CASP+ or equivalent.
About the Company
About Netrio
At Netrio, our people are at the heart of everything we do. Guided by our core values—Empathy, Partnership, Integrity, Accountability, and Innovation—we foster a culture where collaboration and trust drive real impact. We believe in listening first, delivering on our promises, and pushing the boundaries of what’s possible with technology. If you’re passionate about making a difference and want to be part of a team that grows together and leads with purpose, we invite you to explore our open opportunities and join us on our mission.
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say
