SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Torq is hiring an AI SOC Solutions Architect to join its Professional Services organization. You'll design and deliver AI-driven security operations automation for enterprise customers, translating their existing SOC processes into agent-assisted, automated workflows that reduce analyst workload and mean time to respond.
In this role, you'll own technical delivery end-to-end for strategic accounts: architecture, build, validation, and handoff. You'll design agentic workflows and AI agents that triage, enrich, investigate, and respond to security alerts. You'll map customers' Tier 1/2 triage, investigation, and incident response runbooks into automated workflows on the Torq platform, engineer integrations across their security stack (SIEM, EDR/XDR, IdP, ticketing, threat intel) via REST APIs, and design, tune, and evaluate AI agent behavior through prompt engineering and guardrail definition.
You'll serve as a trusted technical advisor to SOC leaders and analysts, running working sessions, resolving blockers, and driving adoption. You'll also feed field learnings back into product to help shape new Professional Services offerings as the AI SOC category evolves.
Torq is the AI SOC platform transforming enterprise security operations. The company closed a $140M Series D at $1.2B valuation in January 2026, achieved ~300% revenue growth in 2025, and was named Gartner's "Company to Beat" in AI SOC Agents for Threat Investigation. The team is scaling rapidly with a culture recognized by Forbes as one of the Best Startup Employers in America.
You'll need 4–6+ years in a technical security role (SOC analyst, detection/automation engineer, incident response, or technical Professional Services/Solutions Architect in cybersecurity). You must have hands-on SOC operational understanding—alert triage, investigation, escalation, and the incident response lifecycle. Direct experience with core detection tooling is required: at least one SIEM (Sentinel, Splunk, Chronicle) and one EDR/XDR (CrowdStrike, Defender, SentinelOne). Familiarity with REST APIs, workflow automation, and prompt engineering is expected. This is a builder's role at the leading edge of the AI SOC category.