- Location
- Overland Park, KS, United States
- Workplace
- Hybrid
- Employment
- Full time
- Level
- Mid level
- Posted
- 3 months ago
About this role
Company Overview:
TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in cybersecurity, automation and AI-driven solutions. Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the AI-Native MDR landscape.
We’re a fast growing startup backed by industry experts and top tier investors led by Crosspoint Capital Partners and also backed by Shield Capital, DTCP (formerly Deutsche Telekom Capital Partners), Deepwork Capital, and the Florida Opportunity Fund. Seed round led by Andreessen Horowitz (a16z). As an early employee, you’ll play a meaningful role in defining and building our culture. Get in on the ground floor. We’re a small but well-funded team that just raised a substantial round - joining now comes with limited risk and unlimited upside.
Culture is one of the most important things at TENEX.AI - explore our culture deck at culture.tenex.ai to witness how we embody it, prioritizing the irreplaceable collaboration and community of in-person work.
About the Role
As a Forward Deployed Data Engineer - SIEM/SOAR, you build the content that powers TENEX's MDR delivery. From detection rules and log parsers to SOAR playbooks, dashboards, and custom API integrations, your work is what makes the platform intelligent. You are also a technical trainer - helping customers understand the content they're running and the platform they're operating.
Job Responsibilities
Author, tune, and maintain detection rules, correlation logic, and threat content across Google SecOps and Microsoft Sentinel
Build and validate log parsers for new data sources integrated into customer environments
Develop and maintain SOAR playbooks, automation workflows, and dashboards for common alert types and operational use cases
Build cloud run functions, scripts, and API integrations where native connectors or content do not exist
Collaborate with Deployment Engineers to ensure content is ready for new customer go-lives
Monitor detection coverage gaps and proactively develop content to address them
Incorporate threat intelligence and adversary TTPs (MITRE ATT&CK) into detection logic
Serve as an advanced enablement resource for customers - training them on detection content, dashboards, and platform capabilities at a deeper technical level
Document all content with clear metadata, use cases, and tuning notes
Support AI-assisted content generation workflows with human review as the quality gate
Required Skills & Qualifications
Technical & Industry Expertise
3+ years in detection engineering, content engineering, or security operations
Strong proficiency in SIEM detection rule development - YARA-L for Google SecOps, KQL for Sentinel, or similar
Experience building and maintaining SOAR playbooks and automation workflows
Proficiency with log parser development for diverse data source types
Knowledge of MITRE ATT&CK framework and its application to detection content
Experience with Python, cloud run functions, and REST API integrations
Experience building security dashboards for operational use cases
Understanding of threat intelligence and how TTPs translate into actionable detection logic
Soft Skills
Strong problem-solving and troubleshooting skills with a bias toward action
Excellent customer-facing communication and collaboration abilities
Ability to thrive in a fast-paced, high-performance startup environment
Passion for cybersecurity, automation, and continuous improvement
Education & Certifications
Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field (or equivalent practical experience)
Relevant certifications such as CISSP, CISM, GIAC certifications, Google Cloud Professional, Microsoft SC-200/AZ-500, or AWS Certified Solutions Architect are a plus
Why Join Us?
Opportunity to work with cutting-edge AI-driven cybersecurity technologies and next-generation security platforms
Collaborate with a talented and innovative team focused on continuously improving security operations
Competitive salary and benefits package
A culture of growth and development, with opportunities to expand your expertise in AI, cybersecurity, and engineering
Be part of building something new - TENEX's Forward Deployed Engineering organization is a greenfield opportunity to define how enterprise security is delivered at scale
As published by TENEX.AI. Applications are handled on their site.
Skills this posting mentions
About TENEX.AI
TENEX is a cybersecurity company leveraging advanced artificial intelligence and human expertise to transform enterprise security. Backed by Andreessen Horowitz (a16z) and Shield Capital, TENEX’s flagship offering is a next-generation Managed Detection and Response (MDR) service, transforming how organizations detect and respond to threats. With deep expertise in Google and Microsoft security ecosystems and state-of-the-art AI capabilities, TENEX empowers enterprises to enhance threat detection, agility, and resilience while maximizing the value of their security investments.
All 61 openings at TENEX.AIOne click, then it is written
Apply to TENEX.AI with a resume written for this role.
Queue Forward Deployed Data Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in TENEX.AI’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at TENEX.AI
See all- 6 weeks ago
- 7 weeks ago
- 7 weeks ago
- 8 weeks ago
- 8 weeks ago
- 8 weeks ago
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board TENEX.AI publishes. Refolk is not the employer and does not handle their hiring. Applications go to TENEX.AI directly.