- Job type
- Not listed
- Work mode
- Not listed
- Level
- Not listed
- Department
- Information Technology
- Experience
- 4+ years experience
- Posted
- Aug 12, 2026
About the role
The Role:
We're looking for an AI SOC Solutions Architect to join our growing Professional Services organization, reporting to the Director of Professional Services.
In this role you'll design and deliver AI-driven SOC automation for enterprise customers, turning existing security operations into agent-assisted, automated workflows that reduce analyst workload and mean time to respond. You'll balance customer-facing collaboration with hands-on technical work across a diverse global customer base.
You'll work directly with SOC leaders and analysts, engineer solutions on the Torq platform, and help customers see results within weeks of deployment.
What You'll Do:
- Design and implement AI-driven SOC automation by building agentic workflows and AI agents that triage, enrich, investigate, and respond to security alerts.
- Translate customer SOC processes into automation by mapping Tier 1/2 triage, investigation, and incident response runbooks into automated and agent-assisted workflows on Torq.
- Own technical delivery for strategic accounts end to end, including architecture, build, validation, and handoff.
- Engineer integrations across SIEM, EDR/XDR, IdP, ticketing, and threat intelligence systems via REST APIs.
- Design, tune, and evaluate AI agent behavior through prompt engineering, guardrails, and human-in-the-loop checkpoints.
- Serve as a trusted technical advisor to SOC leaders and analysts, run working sessions, resolve blockers, and drive adoption.
- Shape the offering by feeding field learnings back into product and helping build new Professional Services offerings.
Must-Haves:
- 4–6+ years in a technical security role such as SOC analyst, detection or automation engineer, incident response, or technical Professional Services / Solutions Architect in cybersecurity.
- Hands-on SOC operational understanding, including alert triage, investigation, escalation, and the incident response lifecycle.
- Direct experience with at least one SIEM, such as Sentinel, Splunk, or Chronicle, and one EDR/XDR platform, such as CrowdStrike, Defender, or SentinelOne.
- Proficiency in at least one of Python, Bash, or Go, plus fluency with REST APIs, JSON, and webhooks.
- Working knowledge of applied AI, including LLMs, agentic AI, prompt engineering, agent evaluation, failure modes, and guardrails.
- Ability to explain complex technical and AI concepts to analysts and CISOs and own an account relationship.
- Strong organizational skills and ability to manage multiple concurrent enterprise engagements.
Nice-to-Haves:
- SOAR platform experience, especially migrations off legacy platforms.
- Detection engineering and query languages such as KQL, SPL, Sigma, and YARA.
- Familiarity with agentic AI infrastructure such as MCP, tool/function calling, RAG, and vector stores.
- MSSP or multi-tenant deployment experience.
- Cloud security fundamentals, including AWS, Azure, or GCP IAM, logging, and API models.
- Relevant security, incident response, AI, or cloud certifications such as CISSP, GCIH, GCIA, or GCFA.
If your experience is close but doesn’t fulfill all requirements, please apply. Torq is focused on hiring people with different backgrounds, perspectives, and experiences.