MSSP and security staffing
Staffing for MSSPs and in-house security teams
Staffing for MSSPs starts with the shift you cannot cover. We recruit internationally and place dedicated security analysts and engineers with US security practices and in-house teams. The contractor works your account only, on the hours you scope, at a rate that reaches a pool your local budget does not.
Analyst coverage on the hours you actually need
The staffing problem in a security practice is not at 10am. It is at 2am, on weekends, and in the hours when the person watching the console has already worked a full day. Hiring for those hours locally means paying a premium for a shift nobody wants, and then replacing that person when they burn out.
We recruit in the Philippines and Southeast Asia, Latin America, Eastern Europe and South Africa. Scope a seat against the hours you need and those hours can fall in the contractor's own working day rather than their night. Follow the sun coverage stops being a scheduling problem and becomes a question of where you place each seat.
Where the contractor works, and on what machine
Remote security work fails on the endpoint, not the resume. Our fifth screening gate is workspace and security posture, and it exists because an analyst with your console open on a shared home machine is a risk you inherited without knowing. We check the physical workspace, the network, the device and how the person handles credentials before you ever meet them.
For teams that want more than a screening check, there is one optional add-on: a secure remote workstation, priced separately from the seat. It puts the contractor inside a US hosted virtual desktop, so your data stays on US infrastructure instead of a personal machine abroad. Access is controlled centrally and revoked the day an engagement ends.
The same package includes productivity and activity monitoring, disclosed to the contractor and written into their agreement, plus managed endpoint security: protection, patching, threat detection and response. It is one package, bought once. If you would rather run the seat on your own VDI and your own tooling, that works too.
MSSP staffing rates and the analyst pool they reach
A senior or Tier 3 security seat is $3,500 to $4,500 a month, all in. That is the whole number you pay us: the contractor, the contracting and compliance work in their country, and the management around the seat. We earn on that monthly rate, not on making the introduction, so a seat that stops working is our problem too.
The US analyst market is the tightest part of your cost base, and everyone bidding for those people is bidding against the same shortlist. Internationally the picture is different. Security work is a well paid, sought after career in the markets we recruit from, and this band sits at the strong end of it, which means you are choosing from people with real console time rather than whoever answered your ad.
We also sit inside a group that delivers managed security, so the people scoping your seat know what an analyst shift actually involves. That shapes what we test for in the skills gate: alert triage under volume, escalation judgment, and whether someone can write an incident note another human can act on.
Where this model does not fit a security team
If your contracts require US citizens or cleared personnel to touch client data, stop here. We place international contractors, and no amount of tooling changes that. The same goes for work that needs someone physically on site for forensics or hardware, and for a surge you want staffed for three weeks around an incident.
We are also slower at the front than firms that send resumes the same week. The intake is heavy on purpose: scope the seat, recruit against it, then five gates before anyone reaches your interview. If you need a warm body watching a queue by Friday, we will lose that race and you should let us.
Where the model does fit, the entry is small. A $500 deposit opens the search and comes straight back off your first month's invoice when the analyst starts. From there you are committed to 90 days of fees, and nothing longer. The model is built for seats you expect to keep filled a year or more, but you are not asked to sign for that. Decide inside those 90 days that the fit is wrong and we run the search again with the deposit waived.
What you get
Included in every engagement
Identity and work history
We confirm the person is who they say they are and that the roles on their record happened, before anyone spends time on a technical screen.
Language proficiency
Spoken and written English tested against the job, because an analyst who cannot explain an escalation clearly at 3am is a risk regardless of technical skill.
Role specific skills testing
Practical testing against the seat you scoped, not a generic quiz. Triage judgment, tooling familiarity and how they write up what they found.
Reference checks
We speak to people who managed the work, not a list of friendly names, and we ask about the parts of the job your seat depends on.
Workspace and security posture
The gate that matters most for security work. Where they sit, what they work on, how the network is set up and how credentials are handled.
Screening
Five gates before you see a shortlist
- Identity & work history
- Language proficiency
- Role-specific skills testing
- Reference checks
- Workspace & security posture
Questions
Frequently asked
Can one contractor give us 24/7 coverage?
No. One seat is one person working one set of hours, and any firm telling you otherwise is selling you a pooled resource with a dedicated label. Round the clock coverage comes from how you scope seats, and where they sit. Because we recruit across several regions, the hours you struggle to fill locally can be ordinary daytime hours for the person covering them.
How long does it take to get an analyst in the seat?
We do not publish a timeframe and we will not invent one on a call. It depends on the tooling, the clearance the seat needs into your environment and how narrow the skill set is. Any number we gave you now would be a number to apologize for later. We will tell you what stage the search is at and what is slowing it down.
Who does the analyst report to?
Your managers. The contractor sits in your reporting line, takes work from your SOC lead or security manager, and follows your escalation and handover process like anyone else on the team. The contract sits with us, so we handle the compliance obligations in their country and pay the contractor. You get one monthly invoice and a person who answers to you.
Can we hire the analyst directly later on?
For Tier 3 technical and management seats, yes. Contract to hire and direct placement are both available at that level, and both end with the person on your payroll. Below Tier 3 we do not offer conversion at all. Those seats stay engaged through us on the monthly model, which also means the seat staying filled remains our responsibility rather than yours.
Who we staff
Other teams we staff
Scope the shift you cannot cover
Tell us the role, the hours you need covered, and what good looks like in ninety days. We will come back with a plan and a shortlist.