AI SOC Solutions Architect - Professional Services
About Torq
Torq is the AI SOC platform transforming how enterprises run security operations. By combining a battle-tested hyperautomation engine with agentic AI, Torq lets security teams triage, investigate, and respond to threats at machine speed — moving beyond the limits of legacy SOAR and SIEM. Torq's AI agents act as digital analysts that work 24/7 to triage alerts, investigate threats, and remediate autonomously, freeing human analysts to focus on higher-value strategic work.
Torq is defining and leading the AI SOC category, backed by significant market recognition:
- Unicorn status — closed a $140M Series D at a $1.2 billion valuation in January 2026, bringing total funding to $332M.
- Named the "Company to Beat" in AI SOC Agents for Threat Investigation by Gartner (May 2026).
- Recognized as a Leader across all four AI SOC categories (Overall, Product, Innovation, and Market) by KuppingerCole (April 2026).
- 4.8/5 rating on Gartner Peer Insights.
- ~300% revenue growth in 2025, with a global team scaling rapidly.
Torq is a dynamic, highly motivated team propelling customers and partners to new heights through AI-driven security operations. This role sits at the forefront of the fastest-moving category in cybersecurity.
About the Role
We're looking for an AI SOC Solutions Architect to join our growing Professional Services organization, reporting to the Director of Professional Services. In this role, you'll design and deliver AI-driven SOC automation for enterprise customers, transforming their security operations into agent-assisted, automated workflows that measurably reduce analyst workload and mean time to respond (MTTR).
You'll balance customer-facing collaboration with deep, hands-on technical work, driving both engagement and execution across a diverse global customer base. This is a builder's role at the leading edge of the AI SOC category, where you'll work directly with SOC leaders and analysts to engineer real solutions on the Torq platform, delivering tangible results within weeks of deployment.
Responsibilities
- Design and implement AI-driven SOC automation — build agentic workflows and AI agents that triage, enrich, investigate, and respond to security alerts, measurably reducing analyst workload and MTTR.
- Translate SOC processes into automation — map a customer's existing Tier 1/2 triage, investigation, and incident response runbooks into automated and agent-assisted workflows on Torq.
- Own technical delivery for strategic accounts end-to-end — architecture, build, validation, and handoff — ensuring customers see measurable outcomes within weeks.
- Engineer integrations across the customer's security stack — SIEM, EDR/XDR, IdP, ticketing, and threat intel — via REST APIs.
- Design, tune, and evaluate AI agent behavior — prompt engineering, defining guardrails, and setting human-in-the-loop checkpoints to ensure automation is trustworthy in production.
- Serve as a trusted technical advisor to SOC leaders and analysts — run working sessions, resolve blockers, and drive adoption across the account.
- Shape the offering — feed field learnings back into product and help build new Professional Services offerings as the AI SOC category evolves.
Requirements
- 4–6+ years in a technical security role — SOC analyst, detection/automation engineer, incident response, or a technical Professional Services/Solutions Architect role in cybersecurity.
- Hands-on SOC operational understanding — alert triage, investigation, escalation, and the incident response lifecycle. You know what a Tier 1/2 analyst actually does day-to-day.
- Direct experience with core detection tooling — at least one SIEM (Sentinel, Splunk, Chronicle) and one EDR/XDR (CrowdStrike, Defender, SentinelOne).
- Automation and integration skills — proficiency in at least one of Python, Bash, or Go, plus fluency with REST APIs, JSON, and webhooks. (Comfort with jq or data transformation is a strong signal.)
- Working knowledge of applied AI — practical experience using LLMs and agentic AI to solve real problems: prompt engineering, designing and evaluating agent behavior, and a clear grasp of failure modes (hallucination, over-automation) and how to guardrail against them.
- Customer-facing excellence — able to explain complex technical and AI concepts to both analysts and CISOs, and to own an account relationship.
- Strong organizational skills — comfortable juggling multiple concurrent enterprise engagements under shifting priorities.
Nice-to-Haves
- SOAR platform experience (Torq, XSOAR, Splunk SOAR/Phantom, Chronicle SOAR), especially migrations off legacy platforms.
- Detection engineering and query languages — KQL, SPL, Sigma, YARA.
- Familiarity with agentic AI infrastructure — MCP, tool/function calling, RAG, or vector stores.
- MSSP / multi-tenant deployment experience.
- Cloud security fundamentals — AWS/Azure/GCP IAM, logging, and API models.
- Relevant certifications — security and IR certs (CISSP, GCIH, GCIA, GCFA) or an AI/cloud certification.