3 months ago
Kansas City, MO, USA or Scottsdale, AZ, USAMid Level
Responsibilities
- Author, tune, and maintain detection rules, correlation logic, and threat content across Google SecOps and Microsoft Sentinel.
- Build and validate log parsers for new customer data sources.
- Develop and maintain SOAR playbooks, automation workflows, and dashboards.
- Build Cloud Run functions, scripts, and API integrations when native connectors or content are unavailable.
- Collaborate with Deployment Engineers to prepare content for customer go-lives.
- Identify detection coverage gaps and develop content to address them.
- Apply threat intelligence and adversary TTPs using MITRE ATT&CK in detection logic.
- Train customers on detection content, dashboards, and platform capabilities at an advanced technical level.
- Document content with metadata, use cases, and tuning notes.
- Support AI-assisted content generation workflows with human review as the quality gate.
Requirements
- At least 3 years of experience in detection engineering, content engineering, or security operations.
- Strong proficiency in SIEM detection rule development using YARA-L, KQL, or similar technologies.
- Experience building and maintaining SOAR playbooks and automation workflows.
- Proficiency developing log parsers for diverse data sources.
- Knowledge of MITRE ATT&CK and its application to detection content.
- Experience with Python, Cloud Run functions, and API integrations.
- Experience building security dashboards for operational use cases.
- Understanding of threat intelligence and translating adversary TTPs into actionable detection logic.
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
- Relevant certifications such as CISSP, CISM, GIAC certifications, Google Cloud Professional, Microsoft SC-200/AZ-500, or AWS Certified Solutions Architect are preferred.
- Strong problem-solving, troubleshooting, customer-facing communication, and collaboration skills are required.
About TENEX.AI
TENEX is the first AI-native, human-led MDR powered by AI SOC. Backed by 24/7 U.S.based expert analysts with 8+ years avg. experience. Our human-led, AI-driven platform delivers 10x faster detection, <1-minute MTTX, and 95% fewer false positives, transforming security operations economics while dramatically improving outcomes. AI handles 100% of alerts at machine speed, allowing our experts to focus on complex threats demanding human judgment. We scale through AI, not headcount, delivering premium outcomes without enterprise-level costs.
