RefolkCandidates
Open nowEngineeringSecurity Operations

Threat Detection Engineer

TENEX.AI · Sarasota , Florida

Location
Sarasota , Florida, United States
Workplace
Hybrid
Employment
Full time
Level
Mid level
Posted
6 months ago

About this role

About Tenex: TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in cybersecurity, automation and AI-driven solutions. Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the AI-Native MDR landscape.

We’re a fast growing startup backed by industry experts and top tier investors led by Crosspoint Capital Partners and also backed by Shield Capital, DTCP (formerly Deutsche Telekom Capital Partners), Deepwork Capital, and the Florida Opportunity Fund. Seed round led by Andreessen Horowitz (a16z). As an early employee, you’ll play a meaningful role in defining and building our culture. Get in on the ground floor. We’re a small but well-funded team that just raised a substantial round - joining now comes with limited risk and unlimited upside

About the Role: Tenex is seeking a highly motivated and skilled Threat Detection Engineer to join our growing Security Operations team. In this critical role, you will be responsible for proactively identifying and mitigating security threats by developing and implementing advanced detection rules (YARA-L). You will work with our Security Operations team and leverage your deep understanding of attack methodologies, security vulnerabilities, and log analysis to enhance security posture and protect assets.

Culture is one of the most important things at TENEX.AI - dive into our culture deck at culture.tenex.ai to see how we live it every day, with a deep emphasis on the collaboration and community that only in-person work delivers.

Responsibilities:

  • Design, develop, implement, and maintain custom detection rules, correlation searches, and alerts within Google Security Operations (SecOps) to identify malicious activity, security incidents, and policy violations.

  • Utilize your expertise in the SecOps detection engine and YARA-L syntax to create efficient and effective detection logic.

  • Analyze large datasets of security logs and events from various sources (e.g., cloud platforms, endpoint detection and response (EDR), network devices, applications) to identify patterns and anomalies indicative of threats.

  • Stay up-to-date with the latest threat intelligence, attack techniques, and security trends to proactively develop new detection strategies.

  • Collaborate closely with Security Analysts to tune detections logic based on incident analysis and threat landscape changes.

  • Contribute to the development and maintenance of security documentation, including YARA-L rules, response strategies, playbooks, and operational procedures.

  • Participate in the evaluation and integration of new security tools and technologies.

  • Automate detection creation, threat intelligence gathering, and rule deployment.

  • Provide mentorship, training, and guidance to junior team members.

Qualifications:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent practical experience).

  • Minimum of 5 years of experience in a security operations role, with a strong focus on threat detection and analysis.

  • Proven experience developing and implementing YARA-L rules within Google Security Operations (SecOps) is essential.

  • Experience with threat intelligence and its integration into detection strategies.

  • Deep understanding of security principles, common attack vectors, and threat actor tactics, techniques, and procedures (TTPs).

  • Strong analytical and problem-solving skills with the ability to analyze complex security logs and identify meaningful patterns.

  • Proficiency in scripting languages such as Python or similar for automation and analysis.

  • Experience working with various security technologies and data sources, including but not limited to:

    • Cloud security platforms (e.g., GCP, AWS, Azure)

    • Endpoint Detection and Response (EDR) solutions

    • Security Information and Event Management (SIEM) systems

    • Network security devices (firewalls, intrusion detection/prevention systems)

    • Identity and Access Management (IAM) systems

  • The ability to effectively communicate technical information to both technical and non-technical audiences.

  • Ability to work independently and as part of a team in a fast-paced environment.

  • Preferred Qualifications:

    • Relevant security certifications such as Security+, CySA+, GCIH, GCIA, or similar.

    • Familiarity with MITRE ATT&CK framework and its application in developing detection rules.

    • Experience with SOAR (Security Orchestration, Automation and Response) platforms.

    • Knowledge of data science and machine learning concepts as applied to security analytics.

    Why Join Us?

    • Opportunity to work with cutting-edge AI-driven cybersecurity technologies and Google SecOps solutions.

    • Collaborate with a talented and innovative team focused on continuously improving security operations.

    • Competitive salary and benefits package.

    • A culture of growth and development, with opportunities to expand your knowledge in AI, cybersecurity, and emerging technologies.

    If you're passionate about combining cybersecurity expertise with artificial intelligence and have experience with Google SecOps and Chronicle, we encourage you to apply!

    As published by TENEX.AI. Applications are handled on their site.

    Skills this posting mentions

    OrchestrationComputer SecurityLog Analysis

    About TENEX.AI

    TENEX is a cybersecurity company leveraging advanced artificial intelligence and human expertise to transform enterprise security. Backed by Andreessen Horowitz (a16z) and Shield Capital, TENEX’s flagship offering is a next-generation Managed Detection and Response (MDR) service, transforming how organizations detect and respond to threats. With deep expertise in Google and Microsoft security ecosystems and state-of-the-art AI capabilities, TENEX empowers enterprises to enhance threat detection, agility, and resilience while maximizing the value of their security investments.

    All 61 openings at TENEX.AI

    One click, then it is written

    Apply to TENEX.AI with a resume written for this role.

    Queue Threat Detection Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in TENEX.AI’s form for you.

    1. 01Drop your resume

      A PDF or a LinkedIn URL. About a minute, once.

    2. 02I rank the openings

      Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

    3. 03Each one is written up

      Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

    • 25 sent a week, free
    • No card
    • Nothing sent until you say so

    More roles at TENEX.AI

    See all

    Similar roles elsewhere

    See more

    Put this to work

    Paste your career in once. Every application after that is written for you.

    Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

    1. 01Drop your resume

      A PDF or a LinkedIn URL. About a minute, once.

    2. 02I rank the openings

      Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

    3. 03Each one is written up

      Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

    • New matches ranked and written before you are up.
    • Every bullet stays inside what your history supports. Nothing invented.
    • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

    500 free credits on sign-up. No card. Nothing is sent until you say so.

    Listed from the job board TENEX.AI publishes. Refolk is not the employer and does not handle their hiring. Applications go to TENEX.AI directly.