Tenex
SOC Engineer
Kansas City, MO SOC
Sponsorship not specifiedDetected 35 days ago
PythonAWSGCPAzureKubernetesTerraformLLMsCybersecuritySIEM
About the role
- TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider.
- We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection.
- Our team is composed of industry experts with deep experience in cybersecurity, automation, and AI-driven solutions.
Responsibilities
- Contribute to response automation quality. Work closely with the SOAR team to review enrichment logic, containment playbooks, and automation design - bringing an incident responder's perspective to what works under pressure and what doesn't.
- Support technical needs across the organization.
- Improve SOC tooling and operational workflows. Identify friction in how analysts triage, investigate, and respond. Partner on tooling improvements, process changes, and reference content that raise consistency and quality across the team.
- Experience building or evaluating AI-assisted security tooling, agentic workflows, or LLM-augmented investigation and response.
Requirements
- 5+ years in security operations, incident response, or detection engineering with demonstrated depth across multiple domains.
- Working knowledge of cloud security architecture in at least one major cloud (AWS, Azure, or GCP), including native log sources and their value for investigation.
- Scripting proficiency in Python or PowerShell for automation support, and integration work.
- Experience with IaC (Terraform, CloudFormation) and DevSecOps practices.
- Bachelor's degree in Computer Science, Information Security, or a related field, OR equivalent work experience.
- Strong fluency in logging and telemetry - able to evaluate an environment's coverage posture, identify deficiencies, and articulate what's needed for effective detection and investigation.
- Hands-on experience with SIEM platforms (Google Chronicle, Microsoft Sentinel, and/or Splunk a plus) - enough to understand data modeling, rule architecture, and parser quality, and recognize when a deployment falls short of what our MDR SOC requires.
- Solid understanding of response automation - enrichment pipelines, SOAR playbook structure, containment logic - and the judgment to evaluate whether automation is working as intended.
- Clear, confident communicator across technical and non-technical audiences - customers, engineers, and analysts alike.
- Multi-cloud breadth across AWS, Azure, and GCP security tooling and telemetry.
- Familiarity authoring detection runbooks, investigation guides, or SOC operating procedures.
- Splunk Enterprise Security depth - ES notable events, risk-based alerting, correlation search architecture.
- Container and Kubernetes security monitoring exposure.
Nice to have
- Familiarity applying AI or LLM-based tooling to security workflows - investigation assistance, alert triage, log analysis, or automation - is a strong plus.
- Relevant certifications - CISSP, GCIH, GCFE, GCDA, GREM, AWS/GCP security, or SIEM platform certifications - are a plus.
Benefits
- Assess and improve telemetry and logging coverage.
Company info
- Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the MDR landscape.
- As an early employee, you'll play a meaningful role in defining and building our culture.
- The role carries direct engagement across internal engineering teams and customers, and no shortage of hard problems to solve.
- Serve as a knowledgeable resource for forward-deployed engineers, onboarding teams, and customers on questions spanning telemetry, investigation, platform behavior, and response - representing the SOC's technical depth across functions.
- Specify what's needed for effective detection and investigation, and work with customers and internal teams to close the gaps.
This listing is sourced directly from Tenex's careers page and normalized into a canonical job model.