West Monroe
Senior Cybersecurity Architect, Agentic SOC Modernization & AI-Enabled Security Operations
Chicago · Los Angeles · New York · San Francisco
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Senior
- Stated salary
- $193,500 – $261,900 per year
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 3 Oct 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Are you ready to make an impact?
West Monroe is seeking a Senior Cybers ecurity Architect, Agentic SOC Modernization & AI-Enabled Security Operations to join our Cybersecurity & Enterprise Technology practice. This role is focused on helping clients modernize security operations by designing next-generation SOC capabilities that leverage automation, AI-enabled workflows, agentic security operations, advanced analytics, SIEM/SOAR platforms, threat intelligence, and scalable detection and response processes.
You will help clients move beyond traditional, manually intensive SOC models toward more intelligent, automated, and resilient security operations. This includes assessing current-state SOC capabilities, rationalizing fragmented tooling, designing future-state operating models, defining agent-assisted workflows, improving detection engineering, automating investigation and response processes, and enabling measurable improvements in analyst productivity, detection coverage, and response effectiveness.
You will serve as a trusted advisor to CIOs, CISOs, security operations leaders, technology executives, and cyber defense teams as they transform fragmented security operations into scalable, intelligence-driven, AI-enabled, and human-governed SOC capabilities.
While this role will support clients across industries, there is a strong preference for candidates with experience modernizing SOC capabilities for Energy & Utilities clients , including electric, gas, water, and other critical infrastructure environments. Experience supporting Financial Services, Healthcare, Private Equity, and other highly regulated sectors is also valuable where security operations, regulatory requirements, operational resilience, and risk reduction are critical.
Experience with Google Security Operations / Google SecOps is a plus, but this role is intended to be broader than any single platform. The ideal candidate understands how to design modern SOC capabilities across people, process, data, governance, automation, AI, and technology.
What You’ll Do
Lead Agentic SOC Modernization Strategy
Assess current-state security operations capabilities across people, process, technology, data, governance, automation, and operating model dimensions.
Define future-state SOC operating models that incorporate AI-assisted investigation, agentic workflows, automated enrichment, response orchestration, human-in-the-loop decisioning, and continuous improvement.
Develop SOC modernization roadmaps aligned to business risk, cyber maturity, regulatory obligations, operational resilience goals, staffing models, and technology investments.
Identify opportunities to reduce alert fatigue, improve analyst efficiency, accelerate investigation and response, increase detection coverage, and improve the quality of security outcomes.
Evaluate where AI agents, automation, analytics, and orchestration can improve SOC workflows without introducing unacceptable operational, privacy, security, or governance risk.
Facilitate executive workshops and working sessions with security leadership, infrastructure, cloud, data, application, compliance, risk, and operations stakeholders.
Design AI-Enabled and Agentic SOC Capabilities
Architect AI-enabled SOC capabilities that support alert triage, evidence gathering, enrichment, summarization, detection authoring, threat hunting, response recommendation, case management, and executive reporting.
Define agentic SOC use cases that improve security operations outcomes, including autonomous or semi-autonomous investigation support, alert correlation, threat intelligence enrichment, detection tuning, playbook execution, and analyst decision support.
Design human-in-the-loop controls, escalation points, approval gates, logging, monitoring, and quality assurance processes for agentic security operations.
Develop operating models for how analysts, engineers, incident responders, threat hunters, SOC managers, and AI-enabled tools work together across the detection and response lifecycle.
Advise clients on responsible and secure use of AI in security operations, including access control, data protection, model governance, prompt security, output validation, auditability, and operational risk management.
Help clients define practical AI-enabled SOC use cases that improve detection, response, analyst productivity, cyber resilience, and executive visibility.
Modernize SIEM, SOAR & Detection Engineering
Architect and improve SIEM, SOAR, security analytics, and case management capabilities across platforms such as Splunk, Microsoft Sentinel, Google SecOps, Palo Alto Cortex, ServiceNow SecOps, CrowdStrike, and similar technologies.
Build detection engineering strategies aligned to MITRE ATT&CK, threat intelligence, business-critical assets, regulatory priorities, OT/ICS risk scenarios, and client-specific threat models.
Design alert triage, enrichment, escalation, case management, automated response, and incident workflow capabilities.
Define threat hunting, detection lifecycle management, detection-as-code, tuning, content governance, and use-case performance measurement practices.
Establish SOC metrics and KPIs, including mean time to detect, mean time to respond, alert quality, false positive reduction, automation rates, detection coverage, analyst productivity, and operational resilience.
Develop implementation roadmaps that sequence telemetry onboarding, detection use cases, automation opportunities, workflow changes, analyst enablement, and operational adoption.
Rationalize Security Tooling, Telemetry & Data Sources
Evaluate security tool portfolios to identify overlapping capabilities, integration gaps, consolidation opportunities, and replace/retain decisions.
Assess SIEM, SOAR, XDR, EDR, threat intelligence, vulnerability management, cloud security, identity, ticketing, and workflow platforms to determine how they support future-state SOC capabilities.
Define ingestion strategies for enterprise telemetry, cloud logs, endpoint data, identity data, network data, SaaS platforms, vulnerability data, application logs, OT/ICS data, and third-party security sources.
Design normalized data models, parsing strategies, correlation logic, enrichment pipelines, analytics workflows, reporting capabilities, and evidence collection processes.
Develop cost, capability, integration, and operational impact analyses to support security tool modernization decisions.
Partner with technology, procurement, finance, security, and risk stakeholders to build actionable tooling roadmaps aligned to renewal windows, architecture dependencies, budget constraints, and business priorities.
Integrate enterprise and OT telemetry into unified SOC monitoring and response environments where applicable.
Strengthen SOC Governance, Risk & Compliance Alignment
Align SOC modernization efforts to frameworks and regulatory requirements such as NIST CSF, NIST 800-53, ISO 27001, NERC CIP, IEC 62443, HIPAA, GLBA, PCI DSS, and other industry-specific obligations.
Design control validation, audit readiness, evidence collection, logging, monitoring, and reporting capabilities within security operations workflows.
Ensure security monitoring, detection, response, and logging strategies support compliance, resilience, cyber risk management, and executive reporting objectives.
Define governance models for detection content ownership, playbook approval, automation changes, AI-enabled workflows, exception management, escalation paths, and continuous improvement.
Translate complex technical recommendations into executive-level narratives focused on business risk, operational resilience, investment priorities, and measurable outcomes.
Support Google SecOps and Other Modern SOC Platforms
Support clients evaluating, designing, or implementing modern SOC platforms, including Google Security Operations /
Similar jobs
- Senior Cybersecurity ArchitectLeidos · Lorton, VAFirst seen 5d ago
- Cybersecurity Architect AdvisorFiserv · 5 LocationsFirst seen today
- Cybersecurity ArchitectFiserv · Columbus, OhioFirst seen today
- IT Cybersecurity ArchitectDollartree · VA-ChesapeakeFirst seen today
- Director of Cybersecurity ArchitectureBlueorigin · 2 LocationsFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job